How to set up Microsoft Authenticator
Microsoft Authenticator is a free app from Microsoft that adds an extra layer of protection to your accounts.
This guide shows how to install it, connect it to your Microsoft and non-Microsoft accounts, and use it for secure sign-ins.
Whether you want to protect Outlook, Microsoft 365, GitHub, or other supported services, the setup process is straightforward once you understand the basics.
What Microsoft Authenticator does
Microsoft Authenticator supports two-factor authentication (2FA) and passwordless sign-in.
Instead of relying only on a password, you confirm your identity with a time-based code, a push notification, or biometric verification such as Face ID or fingerprint recognition.
The app is commonly used with Microsoft accounts, Azure Active Directory, Entra ID, and many third-party services that support one-time passcodes.
It helps reduce the risk of phishing, credential stuffing, and password reuse.
Before you begin
To make setup easier, have these items ready:
- A smartphone running iOS or Android
- Your Microsoft account email address, if you are setting up a Microsoft login
- Access to the account you want to protect
- A stable internet connection
If you are adding Authenticator to work or school accounts, your organization may require additional security policies, such as device registration or multi-factor authentication enrollment.
How to install Microsoft Authenticator
Start by downloading the official Microsoft Authenticator app from the Apple App Store or Google Play Store.
Look for the app published by Microsoft Corporation to avoid fake downloads.
- On iPhone: open the App Store, search for Microsoft Authenticator, and tap Get.
- On Android: open Google Play, search for Microsoft Authenticator, and tap Install.
After installation, open the app and allow any permission prompts that support notifications or camera access.
Camera access is important when you need to scan a QR code during account setup.
How to set up Microsoft Authenticator for a Microsoft account
If your goal is to secure a personal Microsoft account such as Outlook.com, Xbox, or OneDrive, sign in to your account security settings first.
Microsoft will guide you through adding the Authenticator app as a verification method.
Steps to add the account
- Sign in to your Microsoft account on a browser.
- Open Security settings and choose Advanced security options or a similar sign-in method page.
- Select Add a new way to sign in or verify.
- Choose the Authenticator app option.
- Open Microsoft Authenticator on your phone and tap the option to add an account.
- Scan the QR code shown on your screen, or follow the manual setup instructions if scanning is unavailable.
Once the account is added, Microsoft may ask you to approve a test notification or enter a verification code to confirm the setup.
How to set up Microsoft Authenticator with a work or school account
Work and school accounts often use Microsoft Entra ID, formerly known as Azure Active Directory.
Your IT administrator may require you to register the app as part of the organization’s security setup.
Typical enrollment process
- Sign in to your work or school account.
- Open the security or MFA enrollment page.
- Choose to add the Microsoft Authenticator app.
- Scan the QR code with your phone.
- Approve the registration request in the app.
Some organizations also require number matching, where you enter a number shown on your computer into the app to confirm the sign-in.
This helps prevent accidental approvals and strengthens phishing resistance.
How to add non-Microsoft accounts
Microsoft Authenticator can also store one-time passcodes for supported third-party services such as Google, Amazon, Facebook, Dropbox, GitHub, and many banking or enterprise platforms.
The setup steps vary slightly by service, but the general process is similar.
- Open the service’s security settings.
- Find the option for two-factor authentication or authenticator app setup.
- Select Authenticator app or time-based one-time password.
- Use your phone to scan the provided QR code.
- Save the backup codes offered by the service.
After setup, the app generates 6-digit codes that refresh every 30 seconds.
These codes work even without cellular service, as long as your device clock is accurate.
How to enable phone sign-in and passwordless access
One of the most useful features of Microsoft Authenticator is passwordless sign-in.
Instead of typing a password, you approve a login request on your phone using biometric authentication or a PIN.
To turn this on, open the app, select your Microsoft account, and look for the option to enable phone sign-in.
Microsoft may require you to verify the account and update your security settings before passwordless login becomes active.
This feature is especially useful for frequent Microsoft 365 users, since it can reduce password fatigue while improving security.
How to back up and restore Microsoft Authenticator
If you change phones, backup and recovery settings can save time and prevent lockouts.
Microsoft Authenticator supports cloud backup for many account types, but the restore process depends on whether you use iPhone or Android.
Helpful backup tips
- Turn on cloud backup inside the app.
- Keep recovery methods updated for each account.
- Save backup codes from each service in a secure location.
- Check that your phone number and email recovery options are current.
When moving to a new device, install the app first, sign in with the same Microsoft account used for backup, and follow the restore prompts.
Some accounts may still need to be re-verified manually.
Common setup problems and fixes
Most Microsoft Authenticator setup issues are easy to resolve.
If something goes wrong, check the following:
- QR code not scanning: clean the camera lens, increase screen brightness, or use manual entry.
- No notification received: make sure notifications are enabled for the app and that the account is correctly added.
- Code not accepted: verify your phone’s date and time are set automatically.
- Account mismatch: confirm you are signing in with the same Microsoft account you used during setup.
If you are locked out of a work account, your organization’s help desk may need to reset multi-factor authentication or issue a temporary access method.
Security best practices after setup
After learning how to set up Microsoft Authenticator, keep your accounts safer by following a few practical habits:
- Use unique passwords for each account
- Enable authentication app verification wherever available
- Review sign-in activity regularly
- Protect your phone with a secure lock screen
- Do not approve prompts you did not initiate
Microsoft recommends using the Authenticator app over SMS codes when possible because app-based authentication is less vulnerable to SIM swapping and message interception.
What to do if you change phones
Before switching devices, make sure cloud backup is enabled and account recovery methods are current.
On the new phone, install Microsoft Authenticator, sign in, and restore the backup if available.
Then test each important account to confirm that sign-in works properly.
If you use the app for workplace access, update your device enrollment and notify IT if the organization requires re-registration.
This prevents interruptions when you need to access Microsoft Teams, Outlook, SharePoint, or other business apps.