A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To move Microsoft Authenticator data to a new phone, use the built-in backup and recovery features. Backup and restore must be done on the same device type (iOS → iOS or Android → Android); iOS backups cannot be restored on Android and vice versa.
For iOS (iPhone):
- On the old iPhone, prepare iCloud and backup:
- Enable iCloud Drive on the device.
- Enable iCloud Keychain.
- Enable iCloud Backup, then in the Saved to iCloud list, find Authenticator and turn its toggle on.
- Ensure Microsoft Authenticator is updated to version 6.8.33 or later.
- Open Authenticator at least once after enabling backup so the backup is created.
- On the new iPhone:
- Install Microsoft Authenticator from the App Store if it is not already installed.
- Open Authenticator.
- Use Begin recovery (or similar option) and sign in with the same personal Microsoft account used as the recovery account.
- The app will restore backed-up credentials and settings that are allowed to be restored.
What gets backed up and restored (iOS):
- Microsoft personal accounts:
- If using only one-time password (OTP) codes, the OTPs are restored.
- If using passwordless sign-in, only the account name is backed up; sign-in must be re-done on the new device.
- Work or school accounts:
- Only the account name is backed up; sign-in must be re-done on the new device.
- Third-party accounts (e.g., Amazon, Facebook, Gmail):
- OTP codes are backed up and restored.
If the backup does not appear on the new iPhone:
- On the old device, re-check that iCloud Drive, iCloud Keychain, and iCloud Backup are all enabled and that Authenticator is toggled on in Saved to iCloud.
- Confirm Authenticator is at least version 6.8.33 and has been opened once after enabling backup.
- On the new device, uninstall and reinstall Authenticator, then open it again; the backup should appear.
For work accounts on a new iPhone (Intune/Company Portal scenario):
- Set up the new iPhone and sign in with the same Apple ID so apps (including Authenticator) can restore from iCloud if desired.
- Install Microsoft Authenticator if it did not restore automatically.
- Sign in to a work app (like Microsoft Teams) with the work account; complete MFA using the old phone if still available.
- Enroll the new device with Intune Company Portal as required by the organization.
- In Authenticator on the new device, tap Begin recovery, sign in with the personal Microsoft account used for backup, and restore allowed MFA credentials.
- For work accounts, select the work account entry and complete setup (2-step verification/phone sign-in) again to register the new device.
For Android:
- Enable Cloud Backup in Authenticator settings on the old Android device using a personal Microsoft account.
- On the new Android device, install Authenticator, open it, choose Begin recovery, and sign in with the same personal Microsoft account to restore.
Important notes:
- Only one of each account type (one Microsoft personal, one work/school, one non-Microsoft) can be backed up per recovery account.
- No emails, files, or other data are stored in the Authenticator backup; only credentials and related app settings (like account order) are backed up.
References: