A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
If the phone was not backed up to the cloud and there is no Authenticator backup, the original app data (including most codes) cannot be recovered. Recovery options depend on the type of accounts and what was backed up, if anything:
- If Microsoft Authenticator cloud backup was enabled (iOS or Android)
Authenticator can restore saved account credentials to a new device of the same platform type only:- iOS backup → can only be restored on iOS.
- Android backup → can only be restored on Android.
- A personal Microsoft account as the recovery account.
- Being signed in to iCloud, with iCloud Drive, iCloud Keychain, and iCloud Backup enabled.
- In Authenticator: Settings → Backup → iCloud backup turned on.
- Enable iCloud Drive, iCloud Keychain, and iCloud Backup on the new device.
- Install Microsoft Authenticator.
- Sign in with the same personal Microsoft account used for backup.
- Authenticator will restore the saved credentials; then sign in to each account as required.
- Microsoft personal accounts
- If using only a 30‑second one‑time password (OTP): the OTP configuration is restored and codes work again.
- If using passwordless sign‑in: only the account name is restored; sign in again to re‑enable passwordless.
- Work or school accounts: only the account name is restored; sign in again.
- 3rd‑party accounts (Amazon, Facebook, Gmail, etc.): OTP configurations are restored and codes work again.
- If no Authenticator/cloud backup exists or it was on a different platform
If the phone was never backed up (or the backup is inaccessible) and Authenticator’s own cloud backup was not enabled, the OTP secrets stored on the old device are lost. In that case:- Authenticator cannot reconstruct old codes.
- Each account must be recovered and re‑added manually using that service’s recovery process.
- Use the account’s “Can’t access your account?” or recovery form.
- Prove identity using email, SMS, backup codes, or support.
- Once signed in, go to that service’s security/MFA settings and remove the old Authenticator registration.
- Set up Microsoft Authenticator again by scanning the new QR code or following the service’s MFA setup instructions.
- If locked out of Microsoft accounts because of lost Authenticator
- Work or school account: follow the guidance in “I’ve lost access to my security info” to replace security info and wait out any enforced period if required.
- Personal Microsoft account (Outlook/Hotmail, etc.): use the Microsoft account recovery form and follow the prompts to regain access, then re‑add Authenticator.
Going forward, enable Authenticator cloud backup (and, on iOS, iCloud services) so future device changes do not cause loss of codes.
References:
- Back up your accounts in Microsoft Authenticator
- Back up account credentials in Microsoft Authenticator
- Restore account credentials from Microsoft Authenticator
- Common problems with two-step verification for a work or school account
- Recover user authentication methods using Microsoft Entra Backup and Recovery (Preview)
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- Authenticator locked and cannot access at all after replacing phone - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Can't sign in to my email - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A