I got a new phone and now all my keys are gone

Tyler Fulmino 0 Reputation points
2026-07-08T21:43:38.66+00:00

I recently got a new phone and transferred the data from my old one to this one… my old phones data got wiped and now I have no way to get my keys onto this phone. Please help.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-07-08T21:44:35.9233333+00:00

    When getting a new phone, Microsoft Authenticator entries and passkeys do not automatically transfer unless backup and restore were set up on the old device. What can be done now depends on the type of accounts and keys that were lost.

    1. Check if an Authenticator backup is available

    If the old phone was an iPhone and you had backup enabled:

    1. On the new iPhone, uninstall Microsoft Authenticator.
    2. Reinstall Microsoft Authenticator from the App Store.
    3. Open the app; if an iCloud backup exists, the backup option should appear and allow restore.

    For iOS, backup requires that on the old phone (before it was wiped):

    • iCloud Drive, iCloud Keychain, and iCloud Backup were enabled.
    • Authenticator was turned on in Apple Account > iCloud > Saved to iCloud.

    If those were not enabled before the wipe, the Authenticator backup is not available and entries must be re-added manually.

    For Android, backup requires that on the old phone:

    • In Authenticator Settings, Cloud Backup was turned on and linked to a Microsoft personal account.

    If backup was enabled to a Microsoft account, install Authenticator on the new Android phone, sign in with that same Microsoft personal account, and restore from backup.

    If restore from backup is not available, verify:

    • Backup was enabled on the old phone.
    • The same recovery account is being used.
    • Restore is being done to the same device type (iOS→iOS or Android→Android).

    2. Understand what is restored

    Even when backup works, not everything comes back fully configured:

    • Work or school accounts (Entra ID): Only the account name is restored. Each account must be opened and signed in again to complete setup. The app may show “Sign in to add your account” until this is done.
    • Personal Microsoft accounts:
      • If using only time-based one-time codes, those entries are restored.
      • If using passwordless sign-in, only the account name is restored; sign-in is required again to complete setup.
    • Third-party accounts (Amazon, Facebook, Gmail, etc.): The one-time password entries are restored if backup exists; otherwise they must be reconfigured using each service’s security settings.

    3. Handling lost passkeys after a new phone

    Passkeys are separate from Authenticator backup:

    • If a passkey was stored only on the old phone and that phone was wiped, a new passkey must be created for the new phone.
    • If passkeys were saved in a synced credential manager (such as Microsoft Password Manager, Google Password Manager, or Apple iCloud Keychain), they may still be available after signing into that manager on the new phone.

    If a passkey no longer works or was deleted:

    1. Set up a new passkey for each affected account.
    2. After the new passkey works, remove obsolete passkeys or devices from the account.

    For work or school accounts where passkeys are enforced:

    1. Sign in using any remaining working method (old device, another device, or alternative MFA).
    2. Go to Security info at https://aka.ms/mysecurityinfo.
    3. Select Add sign-in method and choose Passkey or Passkey in Microsoft Authenticator.
    4. Follow prompts to create and save the new passkey, then test sign-in.

    If self-service passkey setup is not allowed, contact the organization’s IT admin or help desk for the approved recovery process.

    4. If completely locked out

    If there is no backup and no remaining sign-in method (no SMS, email, or other MFA), recovery depends on the account type:

    • Personal Microsoft accounts: Use the account security page from a signed-in browser session (if still accessible) to adjust security info, add new sign-in methods, or temporarily disable 2FA as needed to regain access, then reconfigure Authenticator and passkeys.
    • Work or school accounts: If locked out and no other admin exists, the organization’s global admin must work with Microsoft support/data protection to regain access.

    Going forward, ensure:

    • Authenticator backup is enabled (iCloud on iOS, Cloud Backup on Android).
    • At least one alternative MFA method (SMS, email, hardware key) is configured for each important account.
    • Passkeys are stored in a synced credential manager when possible.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.