Microsoft Authenticator App for Android: Backup and Account Management Questions

Shane King 86 Reputation points
2025-04-30T05:30:41.22+00:00

Recent discussions with a client raised important questions regarding the behavior of the Microsoft Authenticator app. These questions remain unanswered in public forums and official documentation, due in some part to conflicting advice. We are seeking definitive guidance from Microsoft to clarify the following scenario and concerns.

Scenario

A user has multiple logins configured in the Microsoft Authenticator app, including both Microsoft and non-Microsoft accounts, all using the app for multi-factor authentication (MFA).

Questions

  1. Backup Scope: When a user backs up their Authenticator app, are all configured accounts and logins included in the backup, including non-Microsoft accounts?
  2. Restore on Same Device: After restoring the backup on the same mobile device, will the user be able to access all accounts and log into associated resources without any errors or further configuration?
  3. Restore on New Device: When restoring the backup on a new mobile device, can the user expect a seamless experience with full access to their accounts, or will additional steps/configuration be required?
  4. Personal MSFT Account for Backup: If the Authenticator app was backed up using a personal Microsoft account, and the user later loses access to that account, how can they recover their MFA configurations — particularly if the user is an organization’s Microsoft 365 admin? Our concern is that losing access to the personal Microsoft account could prevent access to critical M365 admin capabilities.
  5. Backup Data Location: Are the backups from the Authenticator app stored in the same region/geolocation as the user?
  6. Notification: If non-MSFT accounts are not backed up in the app, why does it not declare this or prevent users from adding non-MSFT accounts to the app?
  7. Supplemental Backup Options: Are there supplemental backup options that would allow a user to back up the remaining equally critical non-MSFT MFA accounts?
  8. Exchange Online: Where an organization has subscribed to Exchange Online, what are the recommendations for Break-Glass accounts? Is the expectation that the customer purchase additional Exchange Online subscriptions to allow for an unauthenticated admin-level login?

A direct response from someone with authoritative insight at Microsoft would be appreciated, as the current documentation and community forums do not address these questions with the clarity and depth required for enterprise or government environments.

Microsoft Security | Microsoft Authenticator
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.