Recover Microsoft Authenticator on a new phone
Microsoft Authenticator can generate rotating codes, approve sign-ins, and hold work or school account registrations. A restored account name does not always mean the corresponding approval method is ready to use. Start by checking what was backed up and which platform the old phone used.
For the general recovery decision tree, see lost authenticator or phone. This page covers your own Microsoft Authenticator setup. Recover a personal Microsoft account through Microsoft account recovery; an employer or school's administrator controls the recovery of its managed identity.
1. Check the backup and platform requirements
Microsoft's Authenticator restore article says backups can be restored only to the same device type. An iOS backup cannot simply be restored on Android. Follow the tab matching the old and replacement devices rather than assuming any phone backup contains the same authentication data.
For iOS, the current instructions include the required iCloud services and restoration steps. Microsoft's separate Authenticator backup guide explains which account and backup settings your platform uses. For Android, use Microsoft's Android instructions and the account associated with its backup. If that backup account is inaccessible, recover it through its own official provider first.
Preserve an old phone that still works. A cracked screen, missing SIM, or lack of cellular service does not necessarily mean every authenticator function is unusable. Check it through normal authorized access before erasing it or removing the app.
2. Restore, then inspect each account's status
Follow Microsoft's restoration sequence in the official app. Review the returned account list and read any Sign in to restore your account message. Microsoft distinguishes entries that can immediately generate one-time codes from entries needing another sign-in.
For a personal Microsoft account using passwordless sign-in, the backup can contain only the account name. Work or school accounts likewise require sign-in again. A visible entry is therefore not proof that a push approval or passwordless registration has been fully restored.
Third-party accounts that use rotating one-time codes can have a different restoration outcome. Test each important service rather than treating one successful code as confirmation that the entire migration worked. Keep a private checklist of account names without recording active codes in it.
3. Use another configured method for accounts needing verification
Microsoft's restore guidance explains that additional verification may be required. Use another method already available to the account when signing back in. A recovery email, phone, security key, or saved code can be useful only when that account actually supports and recognizes it.
For a managed work or school identity with no usable alternative, contact the organization's help desk. Explain that the old Authenticator device is unavailable and the restored entry requires registration or sign-in. The administrator can determine the supported reset; personal Microsoft recovery forms do not manage the organization's identity.
Do not approve a prompt you did not initiate merely because it arrives while you are recovering the app. Check the account and sign-in context. A legitimate recovery task should not make you accept unrelated authentication requests.
4. Re-add missing third-party accounts through their owners
If a backup is unavailable or a service entry cannot be restored, Microsoft's article points to adding accounts again. That requires access to the protected service's security settings or its own recovery route. Microsoft cannot issue another company's backup codes.
Use each service's saved recovery code or alternate factor to regain access, then register the replacement authenticator through its official settings. Keep the old method until the new registration has been tested where that is possible. Removing an entry from the app is not always the same as revoking it at the service.
Platform restrictions and account-specific reauthentication still apply. If the backup and every alternative verification route are unavailable, some accounts may remain locked. An organization administrator can help only within the accounts and policies it controls.
If the old phone was stolen
Use the device platform's lost-phone controls and review the affected accounts from a trusted device. After establishing another working method, remove the lost registration through each account's security settings or its administrator. Restoring the app on a new phone does not by itself establish that all old access has been revoked.
After you regain access
Confirm the backup setup, test important accounts, and maintain an alternate verification method outside the same phone. Login.com's Microsoft Authenticator guide helps with everyday setup after recovery. Label personal, work, and third-party entries clearly, and keep the organization's help route available without requiring the very authenticator that could be lost.
Instructions checked against vendor guidance on 25 September 2026.