How to transfer microsoft authenticator accounts to new phone

Two-factor authentication is a safe way to keep your personal information on your account safe. This type of authentication can be performed either via SMS or by using special authenticators, such as Microsoft Authenticator.

Very often when using any services for which you’ve created an account, you link the accounts to your phone. Eventually, one way or another, you’ll buy or otherwise get a new phone, because all electronic devices tend to malfunction after a long period of use.

Accordingly, in such cases, you’ll need to transfer your accounts to the new device. However, when it comes to transferring accounts with Microsoft Authenticator, things can be quite difficult.

How to explain Microsoft authenticator

Before you get to the method of transferring accounts with dual authentication, which includes Microsoft Authenticator, you need to understand what Microsoft Authenticator is all about:

Microsoft Authenticator is a two-factor authentication program. This program provides extra security for your online accounts in the form of an app.

You can see Microsoft Authenticator when you use Microsoft products or any sites and apps that use two-factor authentication with a one-time code based on time. The implication is TOTP or OTP.

How to export all your dual authentication accounts to new phone

There’s really no way to export all your dual authentication accounts and then import them onto a new phone. If it’s not Microsoft Authenticator, but for example Google Authenticator, you have to create all the accounts again, manually.

If you’re talking about Microsoft Authenticator, fortunately, this program provides a backup and recovery option.

Note that 2FA is designed in a way that makes it extremely difficult to access an account if you don’t have a 2FA code. That said, most accounts provide backup codes that can be used if your phone is lost or damaged.

If you want to switch devices, make sure you have a copy of the backup codes for each account first. This will surely come in handy if there are problems when you try to restore the accounts.

How to make backup of your 2FA accounts with Microsoft Authenticator

In order to restore the accounts on your new phone later, you need to turn on the backup option on your old phone. Only use Microsoft Authenticator. To do this:

  1. Open the Microsoft Authenticator app on your phone.
  2. Once the app loads, tap the three dots on the screen.
  3. From the options that appear after you tap on the three dots, select “Settings”.
  4. In the settings menu, find the “Backup” section.
  5. Under “Backup”, turn on “Cloud Backup” on your Android phone or “iCloud Backup” on your iPhone.

When you do this, if you have a stable internet connection, your accounts will immediately be saved to the Microsoft account you used when you first set up Microsoft Authenticator. The iPhone also requires an iCloud account.

How Microsoft Authenticator is working

This way you can save your account and user names. The saved information will also include the validation code and various metadata, such as backup time, will be included.

It all works in the following way:

  1. First, Authenticator creates an encrypted JSON Web Encryption blob JWE file, also using AES-256.
  2. After that, it hashes the data using SHA-512.
  3. Then it adds it to the JWE, and then saves the whole file and the key identifier in your account.

How to recover your 2FA accounts on new phone with Microsoft authenticator

After you’re done with the backup, install Microsoft Authenticator on the new device. You can download it from Google Play for Android or the Apple App Store for iPhone.

Remember, don’t create any accounts using Microsoft Authenticator after downloading. Don’t do this until you use the recovery tool, as it’ll overwrite the matching site accounts.

As an example, consider the following situation: let’s say you set up 2FA on your Gmail account in Authenticator on your new phone. However, the Authenticator on the old phone contains the Gmail account .

The recovery tool will overwrite the account you added to Authenticator on the new phone with the account that exists in your backup.

To use the recovery tool, do the following

  1. First, open Microsoft Authenticator on the new phone.
  2. As soon as you open the app, click “Start recovery”.

Next, you’ll see a prompt to sign in to the Microsoft account you used to back up your old phone. Your accounts will then be automatically added to Microsoft Authenticator on the new phone. It may happen that some accounts will need to be re-validated.

You may need to re-login to those accounts or scan the QR code. Microsoft Authenticator will display a message telling you to do this. This is essentially the same process you went through when you originally set up the account. So, it’s better not to use it that way before recovery.

How do I transfer Microsoft authenticator to a new phone?

How to move Microsoft Authenticator to a new phone.
Open the Microsoft Authenticator app on your old phone..
Tap on the three-dotted icon located at the top right and go to Settings..
Toggle-on Cloud backup for Android or iCloud backup for iPhone..
Install Microsoft Authenticator on your new phone..
Add a recovery account..

What happens to Microsoft Authenticator if I lose my phone?

In the case of a lost or stolen phone, recovering Microsoft Authenticator will be immediate, provided that there is access to the same Apple ID (in the case of iOS devices) or Microsoft Account.

How do I change my authenticator app to a new phone without my old phone?

If you've deleted the Google Authenticator app on your old phone without first moving the accounts to the new phone, you have two options. Retrieve via backup codes you were given when you created your google authenticator account or you'll have to add each of your accounts manually to your new phone.