A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Treat this like moving Authenticator to a new device. Before flashing the OS, keep the current setup working until the new registration is confirmed.
- On the current phone, enable Authenticator backup.
- In Microsoft Authenticator, open Settings.
- On Android, turn on Cloud Backup.
- Select the Microsoft personal account where the backup will be stored.
- Do not erase or reflash yet until sign-in recovery is confirmed.
- For work or school accounts, only the account name is restored after backup/restore.
- The work account must be opened in Authenticator and signed in again to complete setup.
- After flashing the OS, reinstall Microsoft Authenticator and restore from backup.
- Use the same recovery account that was used for the backup.
- If restore is not available, verify backup was enabled on the old setup, the same recovery account is being used, and the restore is to the same device type.
- Re-register the work account in Authenticator.
- After restore, seeing "Sign in to add your account." is expected for work or school accounts.
- Open the restored work account entry and sign in again to complete setup.
- If the account uses passkeys, set up a new passkey before removing the old one.
- Go to Security info at https://aka.ms/mysecurityinfo.
- Select Add sign-in method.
- Choose Passkey or Passkey in Microsoft Authenticator.
- Follow the prompts, test the new passkey, then remove old passkeys or devices only after the new one works.
- If self-service re-registration is blocked, contact the IT admin or help desk.
- If passkey setup is not allowed, admin assistance is required.
- If the old phone state is no longer usable and sign-in cannot be completed, the admin may need to reset MFA or require re-registration.
Important limitations for this scenario:
- Backup/restore does not fully transfer a work or school Authenticator registration.
- It restores the account name so the account can be recognized, but sign-in is still required again after restore.
- Keep the current phone state available until the new Authenticator registration or passkey is tested successfully.