Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An authenticator app can add a second check when you sign in, usually by generating a short-lived code or sending an approval prompt. To turn it on, open the account’s security settings, choose its multi-factor authentication (MFA) or two-step verification option, select an authenticator app if available, and follow that service’s enrollment steps. Save the account’s recovery options before you rely on the app.

What an authenticator app does

An authenticator app helps prove that a sign-in is coming from someone with an enrolled device or credential. Depending on the app and the account, it may generate a rotating one-time password (OTP), display a notification to approve or deny, or support passkey-based sign-in. These are different methods, not interchangeable features: the account service determines which options it accepts. Microsoft, for example, documents OTP codes, notifications, and passwordless sign-in as distinct Authenticator functions (Microsoft Authenticator overview; Microsoft Entra Authenticator documentation).

MFA means using more than one kind of proof to sign in. A password plus a code from an enrolled device is one common combination. MFA adds a check beyond the password; it does not make every sign-in method equally resistant to scams.

How to turn on authenticator-app MFA

Account providers use different labels and enrollment screens, so follow the instructions shown by the service you are protecting. A typical setup looks like this:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open the account’s security settings. Sign in to the account and look for Security, Sign-in, or Account protection settings.
  2. Find the MFA option. It may be called multi-factor authentication, two-factor authentication, or two-step verification.
  3. Choose an authenticator app if the account offers it. Do not assume every account accepts every app or supports both codes and approval notifications.
  4. Follow the enrollment prompt. The service may display a QR code to scan with the app, provide setup information to enter manually, or give other account-specific directions. Keep the setup secret private; do not send it to anyone or enter it on an untrusted page.
  5. Complete the service’s verification step. This commonly means entering a generated code or approving a prompt so the account can confirm enrollment.
  6. Save recovery options. If the service provides recovery codes, store them somewhere separate from the phone and follow the service’s instructions for other recovery methods.
  7. Test sign-in before ending your existing session. Use a second browser session or device to confirm that the new factor works, and verify that you can reach a recovery method.

CISA recommends enabling MFA and aiming for a phishing-resistant method where feasible (CISA: Turn On MFA; CISA: Require Multifactor Authentication).

What authenticator codes protect against—and what they do not

A code adds a possession check: a person who has only your password may still be stopped if they cannot provide the enrolled factor. But a manually entered OTP code is not phishing-resistant. If you type it into a convincing fake sign-in page, an attacker may relay it in real time to the real service. NIST states that OTP authentication is not phishing-resistant because manual entry does not bind the code to the intended sign-in session (NIST SP 800-63B).

Passkeys and security keys using WebAuthn/FIDO2 can bind authentication to the verifier’s identity, so a response intended for the legitimate domain cannot simply be reused at a phishing site. Protection depends on the service’s implementation and support, and account recovery still matters. A physical FIDO2 security key is an option for compatible accounts; verify compatibility and register a backup key before relying on one. CISA lists physical security keys among MFA options and advises organizations to aim for phishing-resistant MFA (CISA MFA guidance).

Push approvals may be more convenient than typing a code, but the protection depends on the account’s specific flow. Follow its guidance, including any number-matching step it offers. Do not assume that every app notification has the same security properties as a passkey or security key.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose among the methods an account supports

When an account offers more than one sign-in factor, compare the actual options it supports rather than choosing by the word “authenticator” alone.

Method Phishing resistance What to check
Manually entered OTP code Not phishing-resistant; a code can be relayed from a fake page to the real service. Whether the account supports it, and how you will recover access if the phone is unavailable.
Push approval Depends on the account’s implementation; do not treat every approval flow as equivalent. Whether the service provides number matching or other instructions, plus device availability and recovery.
Passkey or FIDO2/WebAuthn security key Can provide phishing resistance through verifier binding. Whether the service supports the method, which devices or keys are compatible, and how to recover or register a backup.

The best practical choice is limited by what the account supports and what you can recover if a device is lost. For current method-specific requirements, use the account provider’s own instructions; NIST describes the distinctions between OTP and verifier-bound authentication in SP 800-63B.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Prepare for a lost or replaced phone

Do not wait until a phone is missing to find out whether your accounts can be restored. Keep recovery codes or other service-approved recovery methods accessible without depending on the same phone. An app backup may not include every credential or restore every account in a usable state.

Before changing phones

  • Check the authenticator app’s current backup and transfer instructions.
  • Confirm that you can use each important account’s recovery method if the old phone stops working.
  • Where possible, enroll the authenticator on the new device while the old device is still available.
  • Test sign-in to the protected accounts from the new device before removing the old authenticator.

If the phone is lost

  1. Use the account’s recovery codes, another enrolled factor, or its official account-recovery process.
  2. After regaining access, enroll a new authenticator or another supported factor.
  3. Remove or invalidate the lost device’s authenticator when the service allows it.
  4. Review account security settings for unfamiliar devices or sign-in methods.

NIST recommends binding the OTP app on the new device and invalidating the old one; a compatible sync facility may be an alternative if it meets the applicable requirements (NIST SP 800-63B).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand backup limits before relying on sync

Backup behavior varies by app, device, account type, and service. Microsoft’s current Authenticator guidance says backups can be restored only on the same device type, so an iOS backup cannot be restored on Android. For third-party OTP accounts, codes are available after restore; for work or school accounts, only account names are backed up, and users must sign in again. Microsoft also says that starting in January 2027, Android backup will use Microsoft Authenticator in Google One rather than a Microsoft personal account. These are Microsoft-specific details, not general rules for other authenticator apps (Microsoft Authenticator backup guidance).

Before switching platforms or trusting a backup, check the current instructions for your specific app and confirm the recovery path for each account it protects. A successful restore of an app does not necessarily mean every account credential has been restored.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.