Microsoft Authenticator
Mobile setup, push approvals, and recovery for Microsoft 365 accounts.
Open guideArticle
Before replacing a phone used for work sign-in, confirm a working recovery method and the enrollment steps your company allows. Keep the old device available until you have tested the new one.
Before You Get the New Phone
Open your work account security settings and test another company-approved sign-in method, such as an allowed security key or phone method. For Microsoft work accounts, a recovery email supports password reset, not MFA sign-in. Available methods depend on company policy.
The most common are Microsoft Authenticator, Duo Mobile, Okta Verify, and Google Authenticator. Make a list of which ones are on your phone now so you know what to set up on the new one.
Follow your company policy and the app vendor instructions before enabling backup. Restoring Microsoft Authenticator work accounts requires signing in again, and backups cannot be restored across iOS and Android. Duo Restore depends on platform and organization settings; Okta Verify may require transfer or re-enrollment. Test access before retiring the old device.
The Day You Switch
Keep the old phone charged and connected if you still control it. Its existing enrollment may help you add the new device. Approve only sign-ins you initiated, and confirm the prompt details. After a successful new-device test, remove the old enrollment and follow company instructions for disposal.
Install Microsoft Authenticator, Duo Mobile, Okta Verify, or whichever you use from the App Store or Google Play. Do not remove anything from the old phone yet.
For each work account, sign into the security settings page from a computer (using the old phone to approve), then add the new phone as the active method. For Microsoft Authenticator this is Add sign-in method > Authenticator app on https://mysignins.microsoft.com/security-info. For Duo, your IT can send you a fresh enrollment link. For Okta, sign into your end-user dashboard and add a new device if your company allows self-service enrollment; otherwise IT may need to reset or re-enroll Okta Verify for you.
If You Already Lost Access
Use the option to sign in another way, if offered, and select a method you previously registered and your company allows. A Microsoft work-account recovery email is not an MFA method. Contact IT if no available method works.
IT will need to confirm you are really you before resetting multi-factor sign-in, because multi-factor sign-in reset is a common attacker target. Be ready with your manager's name, employee ID, or whatever your firm uses.
After verifying your identity, IT can check whether your organization supports Microsoft Temporary Access Pass, a Duo bypass code, or another vendor-supported recovery route. Availability is policy-dependent. Treat temporary codes as credentials and never share them.
Related
Mobile setup, push approvals, and recovery for Microsoft 365 accounts.
Open guideWhat to do when a new phone breaks Duo pushes.
Open guideRe-enrolling Okta on a new phone and using FastPass.
Open guide