Does anyone have a phone # to contact Microsoft regarding their Authenticator app services?
Authenticator App Question
I lost my Microsoft Authenticator App & all the data contained therein. I know the name of the accounts that were lost. Is there any way to restore the previous accounts to the authenticator app?
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Authenticator
4 answers
Sort by: Most helpful
-
-
JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator
2021-08-02T17:55:54.547+00:00 @Fredrick Martin
Thank you for your post!If you enabled Cloud Backup, you can leverage our Back up and recover account credentials documentation, to use your old backup to recover your account credentials on your device. However, if you didn't create a backup you can following our FAQ to hopefully help resolve your issue.
- To remove the app from a device using a personal Microsoft account. Go to the two-step verification area of your Account Security page and choose to turn off verification for your old device.
- To remove the app from a device using a work or school Microsoft account. Go to the two-step verification area of either your MyApps page or your organization's custom portal to turn off verification for your old device.
For more info - https://learn.microsoft.com/en-us/azure/active-directory/user-help/user-help-auth-app-faq#lost-device
If you have any other questions, please let me know.
Thank you for your time and patience throughout this issue.----------
Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.
-
Thomas Lawless 1 Reputation point
2021-08-01T07:40:20.567+00:00 I very much doubt it unless you deleted the app/storage and can use a data recovery application on your device. This is probably one of the best articles to explain how to avoid this issue in the future and also point to why you would be unable to recovery those "accounts" in the Authenticator App specifically:
Overview of how the Microsoft Authenticator works
...For accounts using the OATH TOTP standard, there is a shared secret stored both in the Authenticator app and in the identity provider.
For accounts using other mechanisms, the Authenticator creates a public/private keypair in a hardware backed storage (e.g. the Keychain on iOS and Keystore on Android) and exports the public key to Microsoft’s login server. The private key never leaves the device when a user is using the backup or restore features of their Authenticator app or when using the operating system app restore features.
For OAUTH TOTP which I believe most apps/websites would use, you may be able to get the "shared secret" from the 3rd party app/website. However I doubt they give you the option due to security, and you would need to log into the account anyways which means you've probably already bypassed MFA and can turn it off.
For public/private keypairs, the private key is hardware backed which should mean that a) there isn't a way to export the private key, and b) only the application to create the private key should have access to it
The only real advice I can give is if you are locked out of accounts that required OTPs from the Authenticator App, there is usually another way to get back into the account, though you may end up needing to head to the help section of that website/service or contact customer support in some cases.
Some services like Microsoft will set you up with multiple account recovery options. So if you have MFA enabled, you may be able to select an option like "I lost my device" during login and then have the option for them to send a text or confirmation code to another device/account. Some services will also give "recovery codes" when you setup MFA, so that when you lose your device, you can use the 1 time recovery code to get back into your account. Of course it is usually up to you to manually save that recovery code somewhere so you can refer to it later.
But from here on out, Microsoft Authenticator App does offer a cloud backup for this reason (and also easily switching devices), but you have to enable it in the app settings.
-
cheong00 3,486 Reputation points Volunteer Moderator
2021-08-01T09:21:34.413+00:00 Yes if you have had enabled "Cloud backup" in your Authenticator App before (with Microsoft or iCloud account as recovery account).
When opening a cleanly installed Authenticator App, there will be 2 buttons displayed - "ADD ACCOUNT" for new users, and "BEGIN RECOVERY" if you want to restore from backup.
You'll want to try it real quick because if Cloud Backup is enabled, it will be overwritten every night with your current accounts information in the App.
See: https://learn.microsoft.com/en-us/azure/active-directory/user-help/user-help-auth-app-backup-recovery for details.
======
If not, then not ALL accounts, but you can ask Microsoft or other account providers to disable the 2FA and then set the up one by one again.
Just tell them things like the credit card number you used to buy things from that account, your phone number, address (if you added that before), etc., or your purchase records so they can confirm you're the account holder. For the other providers the requirements can be different.