How to transfer Microsoft Authenticator to the same phone after flashing a new OS?

lmace 0 Reputation points
2026-09-10T20:30:26.7566667+00:00

Hello,

I use Microsoft Authenticator solely for work and my personal phone is connected as the default MFA method. I am looking to install GrapheneOS on the same phone I currently use and have a sandboxed environment for Google Play services and Micosoft Authenticator. When transferring I will need to approve from my phone but that will not be possible with a new OS. What steps do I need to take to transfer my authenticator app to the same phone on a different OS?

Microsoft Security | Microsoft Authenticator
0 comments No comments

3 answers

Sort by: Newest
  1. Rob Koch 26,075 Reputation points Volunteer Moderator
    2026-09-11T18:38:18.79+00:00

    Though the specific details aren't clear to me, it appears that the use of a rooted device or otherwise modified Android operating system might be detected by the Microsoft Authenticator and/or cause problems with Entra accounts, since the integrity of the phone operating system itself would be something that Microsofrt would consider a security risk.

    Here's the DuckDuckGo search I did to find the articles discussing this which might provide some aid in understanding the issues more deeply.

    GrapheneOS compatibility with Microsoft Authenticator

    Unfortunately, the issue of personal privacy and security you're running into are really different sides of the same coin and as such have both overlapping as well as separate concerns, which when using private devices within work environments are even more likely to collide with business best practices, vs personal privacy preferences.

    As a past security professional working in corporate and education environments, with my own preferences for highly private use of my devices, I ran into these collisions many times during my career and even since, so finding a happy balance is even more difficult for us than the typical consumer who's often oblivious to these concerns.

    IOW, I see what you're trying to do but am betting it's an overly complex combination at best and nearly impossible to resolve question at worst. For those reasons I personally wouldn't even try this combination, but that's my take having typically been more concerned with the security of both the organization(s) I was working for and more importantly the employees I was trying to protect.

    Rob

    Was this answer helpful?

    0 comments No comments

  2. lmace 0 Reputation points
    2026-09-10T20:34:46.7433333+00:00

    When attempting to backup Microsoft authenticator, it says that my onmicrosoft account doesn't exist.

    Was this answer helpful?

    0 comments No comments

  3. AI answer

    2026-09-10T20:30:42.4033333+00:00

    Treat this like moving Authenticator to a new device. Before flashing the OS, keep the current setup working until the new registration is confirmed.

    1. On the current phone, enable Authenticator backup.
      • In Microsoft Authenticator, open Settings.
      • On Android, turn on Cloud Backup.
      • Select the Microsoft personal account where the backup will be stored.
    2. Do not erase or reflash yet until sign-in recovery is confirmed.
      • For work or school accounts, only the account name is restored after backup/restore.
      • The work account must be opened in Authenticator and signed in again to complete setup.
    3. After flashing the OS, reinstall Microsoft Authenticator and restore from backup.
      • Use the same recovery account that was used for the backup.
      • If restore is not available, verify backup was enabled on the old setup, the same recovery account is being used, and the restore is to the same device type.
    4. Re-register the work account in Authenticator.
      • After restore, seeing "Sign in to add your account." is expected for work or school accounts.
      • Open the restored work account entry and sign in again to complete setup.
    5. If the account uses passkeys, set up a new passkey before removing the old one.
      • Go to Security info at https://aka.ms/mysecurityinfo.
      • Select Add sign-in method.
      • Choose Passkey or Passkey in Microsoft Authenticator.
      • Follow the prompts, test the new passkey, then remove old passkeys or devices only after the new one works.
    6. If self-service re-registration is blocked, contact the IT admin or help desk.
      • If passkey setup is not allowed, admin assistance is required.
      • If the old phone state is no longer usable and sign-in cannot be completed, the admin may need to reset MFA or require re-registration.

    Important limitations for this scenario:

    • Backup/restore does not fully transfer a work or school Authenticator registration.
    • It restores the account name so the account can be recognized, but sign-in is still required again after restore.
    • Keep the current phone state available until the new Authenticator registration or passkey is tested successfully.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.