A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
There are two separate issues here: restoring the Authenticator backup itself, and regaining access to the accounts that depend on it.
- Confirm device type and backup type
- Authenticator backups can only be restored on the same device type (iOS → iOS, Android → Android). Accounts backed up on iOS cannot be restored on Android, and vice versa.
- On iOS, backups are stored via iCloud (Drive/Keychain/Backup).
- On Android, backups are stored via the Microsoft personal account used as the recovery account.
- Fix a bad or non-functional backup restore If the app is restoring from a bad or partial backup created during setup, use the platform-specific recovery steps.
iOS
- Make sure on the new phone:
- iCloud Drive is enabled.
- iCloud Keychain is enabled.
- iCloud Backup is enabled.
- Ensure Authenticator is updated to version 6.8.33 or later.
- Uninstall and reinstall the Authenticator app.
- Open Authenticator; the backup should now appear. Sign in to each account as prompted to complete the restore.
Android
- Open Authenticator and select Restore from backup (or Begin recovery) before signing in. If already signed in, sign out first, then try again.
- When prompted, sign in with the same personal Microsoft account that was used as the recovery account when the backup was created.
- If Restore from backup or Begin recovery does not appear, remove or sign out of all accounts in Authenticator, then reopen the app and try restore again.
- Understand what actually gets restored Even with a good backup, not all methods are fully usable immediately after restore:
- Microsoft personal accounts
- If configured only with a 30‑second one-time password (OTP) code, those codes are available once restored.
- If configured with passwordless sign-in, only the account name is restored; sign-in must be completed again.
- Work or school accounts
- Only the account name is restored; sign-in is required again.
- 3rd party accounts (Amazon, Facebook, Gmail, etc.)
- OTP codes are restored and usable.
- If the backup cannot be restored at all If the backup itself is inaccessible or corrupted, recovery depends on the account type:
- Microsoft personal account (consumer)
- Use the Microsoft account sign-in helper to regain access to the backup account and then try restore again: Sign-in helper.
- If still unable to restore, remove and add the accounts again in Authenticator following the normal “add account” flow.
- iOS-specific issue accessing iCloud backup
- If the problem is access to the iCloud account or iCloud services, contact Apple Support using the link in the documentation.
- When recovery is not possible If access to the backup account (iCloud for iOS, or the Microsoft recovery account for Android) is permanently lost, support cannot recover Authenticator’s stored credentials. In that case, each account must be recovered individually using its own recovery options (email, phone, support process) and then re-added to Authenticator.
In summary: ensure the correct platform backup prerequisites are met, reinstall Authenticator and use Restore from backup with the original recovery account. If that backup cannot be accessed or is invalid, the only supported path is to recover each account via its own recovery mechanisms and then re-add them to Authenticator.
References:
- Restore account credentials from Microsoft Authenticator
- Back up account credentials in Microsoft Authenticator
- Back up your accounts in Microsoft Authenticator
- Recover user authentication methods using Microsoft Entra Backup and Recovery (Preview)
- Backup and restore scenarios for iOS/iPadOS
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Authenticator locked and cannot access at all after replacing phone - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A