How to Transfer Your Authenticator to a New Phone

Affiliate disclosure: This article contains affiliate links. If you click a link and make a purchase, we may earn a commission at no extra cost to you. Our editorial recommendations are never influenced by commissions — read our full disclosure policy.
The Half Hour That Decides Whether the New Phone Works
New phone day has a trap in it. Your photos move. Your messages move. Your contacts move. Your two-factor codes very often do not, because the thing that generates them is not a file on the phone — it is a secret that was handed to your authenticator app once, at setup, and never again.
Transferring your number to a new SIM does nothing for it. Restoring an iPhone or Android backup does not reliably carry it either. And the moment you discover this is usually the worst possible moment: old phone wiped, new phone in hand, and every account you protected properly now asking for a code that no device on earth can produce.
This is the sequence that avoids that. It takes about half an hour and the order matters more than any individual step.
Do This Before You Wipe the Old Phone
The single most useful sentence on this subject is Microsoft's own, from its Authenticator transfer page: "Keep your old phone until you confirm that you can sign in to the accounts and resources you use most often from the new phone." That is the whole discipline. The old phone is your rollback. Do not trade it in, do not factory reset it, and do not hand it to a family member until the new one has actually logged you in somewhere that matters.
Before you touch the new phone at all:
- Open your authenticator and photograph or list every account entry in it. You need to know what you are checking against later.
- Turn on whatever backup the app offers, on the old phone, and confirm it says it completed.
- Find your recovery codes for your email and your bank. If you do not have them, generate them now, on the old phone, while it still works.
- Check that the recovery email and phone number on your most important accounts are current.
The Three Ways Codes Actually Move
There are only three mechanisms, and knowing which one your app uses tells you what will break.
| Mechanism | What moves | What it needs | Where it fails |
|---|---|---|---|
| Cloud backup or account sync | The account entries, restored on the new device | The same provider account you backed up to | Wrong recovery account, or a different device type |
| Direct export by QR code | The secrets themselves, scanned across | Both phones working at the same time | Old phone already wiped |
| Re-enrolment per account | Nothing, you set each one up again | Working sign-in to each service | Any account you cannot get into |
Everything else is a variation. Hardware keys are a fourth case and they are the easy one: a security key is not tied to the phone at all, so a new handset changes nothing for the accounts protected by it.
Walking It Through, App by App
Google Authenticator. Google's own help page describes both routes. If you sign in to your Google Account inside the app, "your codes are automatically synced to this device" when you sign in on the new phone. If you would rather move them directly, the app has Transfer accounts: choose Export accounts on the old phone, select what to move, and it produces one or more QR codes; on the new phone choose Transfer accounts then Import accounts and scan them. More than a handful of accounts and it will generate several codes, so do not stop after the first.
Microsoft Authenticator. Backup is set up per platform. On iOS it depends on iCloud Drive, iCloud Keychain and iCloud Backup being on, plus the Authenticator toggle under your Apple Account's iCloud settings. On Android you turn on Cloud Backup in the app's settings and choose a personal Microsoft account to store it in. Two details from Microsoft's page are worth reading twice. First, restore requires "the same recovery account" and "the same device type" — a backup made on one platform is not a general-purpose archive. Second, for work or school accounts "only the account name is restored"; you sign in again on the new phone to finish setup, and seeing red text reading "Sign in to add your account" is the expected behaviour, not a fault.
Password-manager vaults. If your codes live in a manager such as NordPass or Proton Pass, migration is simply installing the app and unlocking the vault. That convenience is the whole argument for the approach, and it comes with a real trade-off that deserves its own read: should both factors live in one vault.
Passkeys. These are not authenticator entries and are not covered by an authenticator backup. Microsoft states plainly that "passkeys are handled separately from Authenticator account backup" — if one was saved only to the old phone, you create a new one on the new phone. If it was saved to a synced credential manager it may already be there. Check before the old device goes. The wider difference between the two is covered in passkeys versus 2FA.
The Fallback That Always Works
If the migration path has already failed — old phone gone, no backup, no export — there is still a route, and it is unglamorous: go account by account, sign in with your password plus a recovery code, disable 2FA, re-enable it, and scan the new QR code with the new phone. Save the fresh recovery codes as you go.
It is slow. Budget two to three minutes per account. But it needs nothing except a working password and a recovery code, which is exactly why the preparation step above insists you find those first.
What to Check Before the Old Phone Leaves Your Hands
Work down this list on the new phone, with the old one still switched on beside you:
- Sign in to your primary email. This is the account every other reset flows through.
- Sign in to your bank or payment app.
- Sign in to your password manager.
- Open one work account, if you have one, and confirm it is fully set up rather than just showing a name.
- Confirm the number of entries in the new authenticator matches the list you made at the start.
Where This Goes Wrong
The two failures worth naming. The first is trusting a phone-to-phone transfer tool. Moving a whole device to new hardware is a solved problem for files, and the same instinct applies to codes; our EaseUS Todo PCTrans review covers that class of tool honestly for a PC move. Authenticator secrets are deliberately outside that scope, because a secret a migration tool can copy is a secret malware can copy.
The second is doing this in a hurry at an airport. Every step above assumes you can receive an email, answer a security question, or wait out a recovery delay. Do it at home, on a weekday, with both devices charged.
The Honest Limits
Nothing here removes the underlying fragility: 2FA deliberately ties access to something you physically hold, and that is exactly why losing it hurts. The mitigations are unexciting and they work — a second enrolled device, printed recovery codes stored away from the phone, and a hardware key for the two or three accounts you genuinely cannot afford to lose.
If you are choosing which app to land on while you are here anyway, the comparison is in best 2FA apps 2026, and the setup order for a fresh start is in how to set up two-factor authentication.
Covered in this guide
Reviewed by NorwegianSpark Editorial — written with AI assistance and reviewed by the NorwegianSpark SA editorial team · Last updated: 6 September 2026




