How to Move Microsoft Authenticator to a New Phone
If you use Microsoft Authenticator for two-factor authentication, switching to a new phone requires more than just installing an app.
This guide explains how to move Microsoft Authenticator to a new phone, what transfers automatically, and what you must reconfigure to avoid being locked out.
The process is straightforward when you prepare first, but account-specific details can create problems if you skip a step.
Knowing how backup, recovery, and cloud sync work will save time and reduce risk.
What Microsoft Authenticator stores on your device
Microsoft Authenticator can manage two main types of accounts: Microsoft accounts and other third-party accounts that use time-based one-time passwords, also called TOTP.
It may also store passwordless sign-in approvals for work, school, or personal Microsoft accounts.
- Microsoft accounts: Personal Microsoft sign-ins, such as Outlook.com or Xbox, may support cloud backup and restore.
- Work or school accounts: These often need to be re-registered, especially if your organization uses Microsoft Entra ID.
- Third-party accounts: Accounts from services like GitHub, Amazon, or Google usually must be added again with a new QR code or secret key.
The exact transfer experience depends on whether your backup is enabled, whether you use iPhone or Android, and whether the account owner supports app-based migration.
Before you change phones, do this first
Preparation is the most important part of learning how to move Microsoft Authenticator to new phone devices without trouble.
Do not wipe your old phone until you confirm the new one works and every account is restored or re-added.
Check that backup is turned on
On the old phone, open Microsoft Authenticator and confirm that backup is enabled.
On iPhone, the backup is tied to your Apple iCloud account.
On Android, it uses your Microsoft account and cloud backup features available in the app.
Confirm your sign-in methods
For each critical account, make sure you have at least one alternative recovery method:
- SMS verification
- Email recovery address
- Backup codes
- Another authenticator device, if available
This is especially important for banking, email, cryptocurrency, and business accounts, where account recovery can be slow or heavily restricted.
Keep the old phone active until setup is complete
Do not factory reset, trade in, or erase the old device until the new phone is fully tested.
If the transfer fails, the old device can still generate verification codes or approve sign-ins.
How to move Microsoft Authenticator to a new phone on iPhone
For iPhone users, Microsoft Authenticator typically restores from an iCloud backup if the same Apple ID is used on the new device.
This works best when the old phone had backup enabled before the change.
- Install Microsoft Authenticator on the new iPhone.
- Sign in with the same Apple ID used on the old phone.
- Open the app and choose the option to restore from backup.
- Follow the prompts to complete sign-in and account restoration.
- Verify each account individually before deleting the old phone data.
Some accounts may appear automatically, while others will require re-entry.
Even after restore, certain work or school accounts usually need to be re-approved by your organization.
How to move Microsoft Authenticator to a new phone on Android
On Android, the process uses Microsoft account-based backup and restore.
The app can recover stored accounts if you backed up the old device and sign in with the correct account on the new phone.
- Install Microsoft Authenticator from Google Play on the new Android phone.
- Open the app and sign in with the same Microsoft account used for backup.
- Select the restore option when prompted.
- Wait for your accounts to sync into the app.
- Check each login and reset anything that does not restore correctly.
Android transfers can be affected by differences in manufacturer settings, battery optimization, or account sync permissions.
If restore does not complete, verify that cloud backup was active on the old device and that you are signed into the correct Microsoft account.
How to re-add accounts that do not transfer
Not every authenticator entry migrates cleanly.
Third-party services and many enterprise accounts require a fresh setup on the new phone, usually by scanning a QR code or entering a manual setup key.
For personal online accounts
Log in to the service’s security settings and remove the old authenticator if needed.
Then choose the option to set up an authenticator app again and scan the new QR code with Microsoft Authenticator.
For work or school accounts
Organizations that use Microsoft Entra ID, formerly Azure Active Directory, may require re-registration.
Your administrator may ask you to:
- Sign in to the company security portal
- Approve a new authentication method
- Use a temporary access pass
- Complete multi-factor authentication enrollment again
If your company uses conditional access or passwordless sign-in, the account may not function on the new phone until the IT team confirms the device and method are trusted.
For critical services
Some services, such as banking apps, cloud storage platforms, and developer tools, may block authenticator transfer entirely.
In those cases, you must sign in to the service, disable the old method, and register Microsoft Authenticator again.
How to avoid getting locked out
The biggest risk when moving Microsoft Authenticator to a new phone is losing access before the new setup is finished.
You can reduce that risk by treating the old phone as a backup device until every account is verified.
- Export or save backup codes before making changes.
- Keep at least one recovery email and phone number current.
- Test sign-in for your most important accounts first.
- Use app lock, biometrics, or device passcode protection on the new phone.
- Do not uninstall the app from the old phone until transfer is confirmed.
If a code or approval request stops working, go directly to the account’s security settings rather than repeatedly retrying sign-in.
Repeated failures can trigger security locks or temporary account blocks.
What to do if Microsoft Authenticator will not restore
If the restore process fails, check the most common causes before troubleshooting further.
Most issues come from backup being disabled, using the wrong cloud account, or trying to restore onto a device with a different platform setup than expected.
- Confirm you are signed in with the same Microsoft account or Apple ID used for backup.
- Make sure the new phone is connected to stable Wi-Fi or mobile data.
- Update Microsoft Authenticator to the latest version.
- Check that date and time are set automatically on the new device.
- Restart the phone and try the restore again.
If you still cannot recover the app data, you may need to re-register each account manually.
For work accounts, contact your IT administrator or help desk for a new enrollment path.
Best practices after the transfer
Once the new phone is working, review your sign-in setup to ensure everything is secure and current.
This is a good time to remove stale devices, update recovery options, and confirm that you can still access account backup codes.
- Delete old device registrations from account security pages.
- Verify MFA methods for Microsoft, Google, and other critical services.
- Store recovery codes in a secure password manager or offline location.
- Enable biometric unlock on the new phone if supported.
- Keep backup options updated whenever you change a number or email address.
For users managing business or multiple personal accounts, a periodic review of authentication methods helps prevent access problems later.
It also makes the next phone upgrade much easier.