A new phone breaks your Microsoft Authenticator app — but recovery is straightforward if you've prepared.

1. With cloud backup enabled

If you had cloud backup on (recommended):

  1. Install Microsoft Authenticator on new phone
  2. Choose Begin recovery
  3. Sign in to your recovery account (your work account or personal Microsoft)
  4. Accounts restore from backup

You may still need to verify one work account by SMS or phone call. That's fine.

2. Without cloud backup

If you didn't enable backup:

  • Each account needs to be re-added manually
  • Sign in to each service's MFA settings page
  • Generate a new QR code
  • Scan with new phone

This is slow but works. The longest part is figuring out which accounts you had.

3. Microsoft 365 specifically

For work / school accounts in M365:

  1. Sign in to mysignins.microsoft.com/security-info from a computer
  2. May be asked for current MFA — use your backup method (SMS, alternative phone)
  3. Click Authenticator appAdd account → walk through QR scan
  4. Done

If you can't get past the initial MFA prompt:

  • Use a backup code
  • Use SMS / phone call
  • Or contact IT to reset MFA

4. Personal Microsoft

For Outlook.com / Hotmail:

  1. Sign in at account.microsoft.com
  2. Security → Advanced security options
  3. Reset MFA from there

5. Third-party services

Each service with MFA needs its own update:

  • Google: myaccount.google.com/security
  • GitHub: Settings → Security → Authentication
  • AWS: IAM → Users → Your User → Security credentials
  • Salesforce: Personal Settings → Two-factor authentication

Re-enroll each.

6. Setting up backup codes (recommended)

After getting MFA working on new phone, generate backup codes for next time:

  • Go to MFA settings → Backup codes
  • Print or save in password manager
  • Stored in a secure offline location

These are your "I lost my phone" emergency codes.

7. Enable cloud backup on new phone

Now that everything works:

  • Microsoft Authenticator → Settings → Backup → enable iCloud backup (iOS) or Microsoft account (Android)
  • Test recovery — install the app on a tablet or another device and verify accounts appear

8. Authy alternative

If you've struggled with Microsoft Authenticator:

  • Authy has cloud sync built in
  • Available on iOS, Android, desktop
  • Sign in with phone number on new device, all accounts appear

Migration: use the export-import feature in each MFA setup, switch to Authy.

9. Hardware key as backup

For extra resilience:

  • Add a YubiKey or similar to your MFA methods
  • Even without your phone, you can sign in with the key
  • Useful for travel where you can't use your phone

10. Common gotchas

  • Old phone wiped before new is enrolled → can't see codes to migrate
  • Backup codes saved on the old phone → gone with the old phone
  • Same phone number on new phone → SMS-based recovery still works

Plan ahead before wiping the old phone.

When to ticket

Raise a ticket if:

  • You've lost access to all MFA methods
  • A specific service is requiring MFA you can't satisfy
  • Backup codes aren't accepting
  • You need IT to reset MFA on your work account

Include the affected services and what verification methods you have available (SMS to old number, work email, etc.).