Sign In to Microsoft Authenticator on a New Phone
How Microsoft Authenticator Sign-In Works
Microsoft Authenticator does not have one universal app sign-in that unlocks every account. Opening the app, adding an account, and signing in to that account are separate actions.
When you open Authenticator, you may use your phone’s screen lock or biometric check. Adding an account connects the app to a personal Microsoft account, a work or school account, or another service. Approving a request confirms a sign-in that you started elsewhere. Signing in to a Microsoft account means entering that account’s credentials on a Microsoft sign-in screen and then completing any requested verification.
Therefore, the answer to “how to sign into Microsoft Authenticator app” depends on your goal. If the account already appears, open the app and select it. If it is absent, add or recover it first.
Sign In to Microsoft Authenticator
- Install the current Microsoft Authenticator app from the official Apple or Google app store. Check that Microsoft Corporation is identified as the publisher.
- Open the app and allow notifications. Allow camera access if you will scan a QR code.
- Select the plus sign or Add account, then choose Personal account, Work or school account, or Other account.
- For a personal Microsoft account, follow the sign-in option shown in the app or display a setup QR code from the security area of your Microsoft account.
- For a work or school account, open its Security info page on another device, choose Add sign-in method, and select Microsoft Authenticator. Your organization may instead permit you to enter your credentials in the app.
- Scan the QR code displayed on the other device. Do not scan a code sent by an unknown person. If scanning is unavailable, use the manual setup option when the official account page provides one.
- Complete the test approval, number match, or verification-code step shown on screen.
After setup, a Microsoft Authenticator app sign-in request may ask you to approve a notification, enter a number displayed on the sign-in screen, or type a changing code from the app.
Set Up Microsoft Authenticator on a New Phone
If the old phone still works, keep it registered until the new phone has passed a test sign-in. Turn on Authenticator backup on the old phone and confirm that it uses the recovery account you expect. Also make sure you can use another verification method for each important account.
- Install Authenticator on the new phone from its official app store.
- Use the app’s recovery option if a backup exists. Otherwise, add each account from its official security settings.
- Follow every account marked Action required or Sign in to restore. Work and school registrations commonly require another sign-in.
- Test the new phone by signing in to each account in a separate browser session.
- Only after successful tests, remove the old Authenticator registration from each account’s security information and erase the old phone if appropriate.
This is the safest way to set up Microsoft Authenticator on a new phone. A Microsoft Authenticator new phone login is not complete merely because account names appear in the app.
Restore Authenticator from a Backup
Cloud recovery works only if backup was enabled before the old phone became unavailable. Microsoft requires restoration to the same device type: an iPhone backup cannot be restored to Android, and an Android backup cannot be restored to iPhone.
On an iPhone, the required iCloud features must be available, and you must use the same iCloud and personal Microsoft recovery accounts associated with the backup. On Android, sign in with the personal Microsoft account used as the recovery account. Select Restore from backup or Begin recovery before adding other accounts. If that choice is missing, Microsoft says you may need to sign out of or remove accounts already added to the new app.
What returns varies. Time-based codes for some personal Microsoft and third-party accounts can be restored. Passwordless personal accounts may restore only the account name. Work or school accounts restore the name but require sign-in or registration again. Review every entry rather than assuming every account transferred automatically.
If the Old Phone Is Lost or Unavailable
On the account sign-in screen, select the option to use another verification method. Use a method you previously registered, such as another authentication app, security key, email, text, or recovery code, if the account offers it. This is account recovery, not a way to bypass multi-factor authentication.
For a personal Microsoft account, use the official Microsoft account sign-in helper or account-recovery process found through Microsoft Support. After access is restored, open the account’s security settings, add the new Authenticator registration, test it, and remove the unavailable phone.
For a work or school account, contact your organization’s help desk or account administrator. Ask them to help replace or reset the unavailable Authenticator method. Microsoft’s consumer support cannot change an organization’s access policy.
Fix Sign-In and Approval Problems
No prompt appears: open Authenticator manually, confirm the phone is online, allow notifications in phone settings, and check that battery-saving or focus settings are not suppressing the app. Retry the sign-in once.
The approval is unexpected: deny it. Never approve a request you did not start and never give another person a displayed code.
A changing code is rejected: set the phone’s date, time, and time zone to automatic. Wait for a fresh code and enter it before it changes.
The wrong account receives the request: compare the account name shown on the sign-in screen with the entry in Authenticator.
The new phone shows the account but cannot approve: open that entry and complete any Action required or sign-in prompt. If necessary, register it again from the account’s security settings.
A work or school setup is blocked: the organization may restrict registration or require an administrator to reset authentication methods. Contact its help desk.
Get Official Microsoft Support
For a personal account, go to Microsoft’s official Support site and search for Microsoft Authenticator, account recovery, or the Microsoft account sign-in helper. Use the Contact Support option shown there if self-service steps do not resolve the problem.
For a work or school account, start with your employer’s or school’s IT help desk because its administrator controls sign-in methods and access policies. Administrators can use Microsoft’s official business support path through their organization’s administration portal.
Avoid phone numbers and recovery services found in ads, forums, or unsolicited messages. Official support will not ask you to approve an unfamiliar sign-in or disclose a one-time verification code.