Llamaha icon

Article

Getting a new phone without losing multi-factor sign-in

Before replacing a phone used for work sign-in, confirm a working recovery method and the enrollment steps your company allows. Keep the old device available until you have tested the new one.

Before You Get the New Phone

Set yourself up to switch cleanly

Make sure you have a second sign-in method

Open your work account security settings and test another company-approved sign-in method, such as an allowed security key or phone method. For Microsoft work accounts, a recovery email supports password reset, not MFA sign-in. Available methods depend on company policy.

Find out which apps your company uses for multi-factor sign-in

The most common are Microsoft Authenticator, Duo Mobile, Okta Verify, and Google Authenticator. Make a list of which ones are on your phone now so you know what to set up on the new one.

Turn on cloud backup if your authenticator app supports it

Follow your company policy and the app vendor instructions before enabling backup. Restoring Microsoft Authenticator work accounts requires signing in again, and backups cannot be restored across iOS and Android. Duo Restore depends on platform and organization settings; Okta Verify may require transfer or re-enrollment. Test access before retiring the old device.

The Day You Switch

Keep the old phone working until the new one is set

Do not erase or factory-reset the old phone yet

Keep the old phone charged and connected if you still control it. Its existing enrollment may help you add the new device. Approve only sign-ins you initiated, and confirm the prompt details. After a successful new-device test, remove the old enrollment and follow company instructions for disposal.

Install the same authenticator apps on the new phone

Install Microsoft Authenticator, Duo Mobile, Okta Verify, or whichever you use from the App Store or Google Play. Do not remove anything from the old phone yet.

Re-add accounts one at a time

For each work account, sign into the security settings page from a computer (using the old phone to approve), then add the new phone as the active method. For Microsoft Authenticator this is Add sign-in method > Authenticator app on https://mysignins.microsoft.com/security-info. For Duo, your IT can send you a fresh enrollment link. For Okta, sign into your end-user dashboard and add a new device if your company allows self-service enrollment; otherwise IT may need to reset or re-enroll Okta Verify for you.

If You Already Lost Access

You upgraded the phone before doing any of this — now what?

Check your other sign-in methods first

Use the option to sign in another way, if offered, and select a method you previously registered and your company allows. A Microsoft work-account recovery email is not an MFA method. Contact IT if no available method works.

Contact IT and be ready to verify your identity

IT will need to confirm you are really you before resetting multi-factor sign-in, because multi-factor sign-in reset is a common attacker target. Be ready with your manager's name, employee ID, or whatever your firm uses.

Ask IT about an approved temporary recovery method

After verifying your identity, IT can check whether your organization supports Microsoft Temporary Access Pass, a Duo bypass code, or another vendor-supported recovery route. Availability is policy-dependent. Treat temporary codes as credentials and never share them.

Related

Specific app guides

Microsoft Authenticator

Mobile setup, push approvals, and recovery for Microsoft 365 accounts.

Open guide

Duo Mobile

What to do when a new phone breaks Duo pushes.

Open guide

Okta Verify

Re-enrolling Okta on a new phone and using FastPass.

Open guide