Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Authenticator can verify a Microsoft account with a push notification, generate six-digit time-based codes, or approve passwordless sign-ins. Those are different features: adding an account to the app does not automatically enable every one of them.

Install the latest version of Microsoft Authenticator from the official app-store link before starting. Microsoft does not support Authenticator versions more than 12 months old.

Before you start

  • Install Microsoft Authenticator on your Android phone or iPhone.
  • Update it from Settings in the app by enabling App updates.
  • Keep the account password, recovery email, phone, or another verification method available.
  • For a work or school account, your organization may require administrator approval, device registration, a PIN, or biometric protection.
  • Do not remove your old authenticator device until the new one has successfully approved a test sign-in.

Authenticator is used in three main ways:

Use What happens at sign-in
Push approval A notification appears in Authenticator. For Microsoft Entra accounts, you enter the number shown on the sign-in screen.
TOTP verification Authenticator displays a six-digit code that changes every 30 seconds.
Passwordless sign-in You enter your Microsoft account name, then approve a sign-in request in Authenticator instead of entering a password.

Set up a personal Microsoft account

Use this route for an account ending in an address such as Outlook.com, Hotmail.com, Live.com, or another personal Microsoft account.

Add Authenticator as a verification method

  1. Open account.microsoft.com/security and sign in.
  2. Select Manage how I sign in.
  3. Select Add a new way to sign in or verify.
  4. Choose Use an app.
  5. If the app is not installed, select Get it now. If it is already installed, choose Set up a different Authenticator app, then select Next.
  6. Leave the QR code visible on the computer.
  7. Open Authenticator on the phone, tap the + icon, choose Personal account, and select Scan a QR Code.
  8. Point the phone camera at the QR code and complete Microsoft’s test verification.

If the camera cannot read the code, select I can’t scan the bar code on the computer. Choose Enter code manually on the phone and enter the displayed code and URL or secret when requested.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Turn on two-step verification

Adding the account to Authenticator and enabling two-step verification are separate actions.

  1. Return to account.microsoft.com/security.
  2. Select Manage how I sign in.
  3. Scroll to Two-step verification.
  4. Select Turn on.
  5. Follow the prompts and scan the QR code Microsoft displays.

After this is enabled, Microsoft can request an Authenticator approval or a code in addition to your password, depending on the sign-in flow.

Make the account passwordless

Passwordless sign-in removes the normal password step, but it is not the same as merely registering Authenticator.

  1. Go to account.microsoft.com/security.
  2. Select Manage how I sign in.
  3. Scroll to Passwordless account.
  4. Select Turn on.
  5. Complete the verification prompts.
  6. Approve the request sent to Authenticator.

Microsoft may show the same setting under Additional security options → Passwordless account → Turn on.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set up a work or school account

For Microsoft 365, Microsoft Entra ID, and other organization-managed accounts, use your organization’s Security info page.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

QR-code setup

  1. Sign in at mysignins.microsoft.com/security-info.
  2. Select Add sign-in method.
  3. Choose Microsoft Authenticator from the dropdown.
  4. Select Add.
  5. If Authenticator is installed, select Next to display the QR code.
  6. Open Authenticator and tap +.
  7. Select Add account → Work or school account → Scan a QR Code.
  8. Scan the code and approve the test notification or complete the verification shown on screen.

If the Security info page is unavailable, use the older organization path when it is offered: select Additional security verification, tick Authenticator app, and select Configure to display the QR code.

Set up with credentials instead of a QR code

This option appears only when the organization’s administrator has enabled phone sign-in with Authenticator. Microsoft says it is unavailable to users in China.

  1. Open Authenticator and tap the + icon.
  2. Select Work or school account.
  3. Select Sign in.
  4. Enter your work or school credentials. If your administrator issued a Temporary Access Pass (TAP), you can use it when prompted.
  5. Tap the account and verify it in the full-screen account view.

For U.S. government organizations, Microsoft says phone-sign-in accounts must be added with Sign in with your credentials; the QR-code method is not supported for that scenario.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Add Amazon, Google, Facebook, or another third-party account

Authenticator can generate TOTP codes for services that offer app-based two-step verification. Enable two-step verification in that service first; Authenticator cannot turn it on from the app.

  1. Open the account’s security settings—for example, the service’s Two-factor authentication or Authenticator app page.
  2. Choose the option to use an authenticator app. The service displays a QR code or a manual setup key.
  3. Open Microsoft Authenticator and tap +.
  4. Choose the account type shown in the app, usually Other (Google, Facebook, etc.).
  5. Scan the service’s QR code, or enter its secret manually.
  6. Enter the current six-digit Authenticator code back on the service’s website to confirm setup.

Codes change every 30 seconds. Enter the code before it expires; if the service rejects it repeatedly, check that the phone’s date and time are set automatically.

Rank #3
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Understand number matching

Microsoft Entra push approvals use number matching. Instead of simply tapping “Approve,” the sign-in page displays a number and the Authenticator notification asks you to enter that number. Type the number into the notification, then approve it.

Users cannot disable number matching. It applies to Authenticator push notifications used for MFA, self-service password reset, combined registration, AD FS, and NPS. It does not alter TOTP-code verification or approvals from another authentication provider.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Number matching is not supported for push notifications on an Apple Watch or Android wearable. Approve the request on the phone instead.

Back up Authenticator before changing phones

Android

  1. Open Authenticator.
  2. Tap the More menu.
  3. Select Settings.
  4. Turn on Cloud Backup.
  5. Select the Microsoft personal account where the backup will be stored.
  6. Tap OK.

If you selected the wrong personal Microsoft account, turn off Cloud Backup, select OK to delete that backup, then turn backup on again and choose Continue or Change account.

iPhone

iOS backup requires all of the following:

  • iCloud Drive
  • iCloud Keychain
  • iCloud Backup
  • Authenticator enabled in the iCloud Saved to iCloud list

Microsoft’s current troubleshooting instructions also require Authenticator version 6.8.33 or later. Open Authenticator at least once on the old iPhone before switching to the new device.

Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Restore on the replacement phone

  1. Install Authenticator on the new phone.
  2. Before adding or signing in to accounts, choose Restore from backup or Begin recovery.
  3. Sign in with the personal Microsoft account used for the backup.
  4. For an entry marked Sign in, tap it, enter the account password, and complete the additional verification.
  5. For an entry marked Action required, open its tile and choose the sign-in and recovery option.

Restore works only between the same platform types: Android to Android or iPhone to iPhone. A work or school account restores only its account name and must be signed in again. A passwordless personal Microsoft account also requires sign-in again. Personal and third-party accounts using TOTP can have their codes restored.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If Restore from backup or Begin recovery does not appear, Microsoft says you may need to remove or sign out of all accounts in Authenticator before starting recovery. If you cannot access the Microsoft personal account holding the backup, Microsoft Support cannot restore those credentials for you.

Authenticator no longer provides the old password-manager features: autofill stopped working in July 2025, and passwords stopped being accessible in the app in August 2025.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Fix common Authenticator problems

Problem What to check
“You’ll need to go to aka.ms/mfasetup” The account does not have enough existing authentication methods to obtain a strong-authentication token. Use aka.ms/mfasetup in a browser or use another available recovery method.
“You might be signing in from a location that is restricted by your admin” Your administrator may not have enabled registration, or a Security Information Registration Conditional Access policy may be blocking it.
No push notification Check the old phone first; the request may still be going there. Also check notifications, sound, vibration, Do Not Disturb, network access, and the app’s notification channel. Remove the old device from account security settings when it is no longer needed.
Notification says it expired Set the phone’s date and time to automatic, update the clock, restart the phone, and try again.
QR scan fails Update Authenticator, improve the screen brightness and camera focus, then use I can’t scan the bar code or Can’t scan the image and enter the setup details manually.
“Google Play services are currently unavailable” On Android, enable push notifications and ensure both Google Play Services and Google Play Store are installed and enabled. A PIN or biometric, hardware encryption, and device registration may also be required.
“Sorry, only part of the set up completed successfully” Check the same Android requirements: push notifications, Google Play Services, Play Store, PIN or biometric protection, hardware encryption, device registration, and a device without rootkit or comparable malware.
“We could not complete the sign-in at this time” Check notifications and network connectivity. If those are working, remove and re-add the affected account.
“Something went wrong. [4s8qz]” Retry, open Authenticator to confirm it responds and lists the account, update the app, update Company Portal on a work device, and restart the phone.
Gray or inactive account tile It may have been created by another application for single sign-on. Microsoft says these tiles can generally be ignored.

Authenticator’s displayed sign-in location is approximate because it uses location data from the phone’s operating system. An incorrect address does not necessarily indicate that the sign-in was made from that location.

Microsoft is also introducing jailbreak and root detection for work or school Microsoft Entra credentials beginning in February 2026. Those credentials will not function in Authenticator on a jailbroken or rooted device.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Symantec VIP Hardware Authenticator - K10S - Two Factor Authentication Security Key - Fits USB-A - FIDO U2F Certified
  • Standard OATH compliant HOTP (event-based). The HOTP function is to be used with Symantec VIP Access.
  • Generates a 6-digit HOTP code with one tap of the touch button
  • FIDO U2F support with Symantec VIP attestation certificate
  • Zero footprint: no need for the end user to install any software
  • Micro-sized, secure, sturdy, and long-life hardware design

FAQ

Does adding Microsoft Authenticator automatically enable two-factor authentication?

No. Adding the app is a registration step. For a personal Microsoft account, separately open Security, select Manage how I sign in, scroll to Two-step verification, and select Turn on. Passwordless sign-in is a separate Passwordless account setting.

Can I use Microsoft Authenticator without a Microsoft account?

Yes. Authenticator can generate TOTP codes for Amazon, Google, Facebook, Instagram, Gmail, and other services that provide a QR code or manual one-time-password secret.

Why is Authenticator asking me to enter a number?

Microsoft Entra uses number matching for Authenticator push notifications. Enter the number displayed on the sign-in screen into the notification on your phone, then approve the request. Users cannot opt out.

Can I transfer Authenticator from Android to iPhone?

No. Microsoft supports backup restoration only between the same device types. Android backups restore to Android, and iPhone backups restore to iPhone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Will restoring Authenticator fully restore my work account?

No. A work or school backup restores the account name only. You must select the account, sign in again, and complete the organization’s verification process.

What should I do if my old phone receives the approval request?

Use the old phone if you still have it, then remove that device from the account’s security settings after the replacement phone works. If available, choose another verification method while registering the new device.

The Bottom Line

For a personal Microsoft account, register Authenticator at account.microsoft.com/security; for a work or school account, use mysignins.microsoft.com/security-info. Scan the QR code with the matching account type in Authenticator, then test the sign-in before removing the old phone. Enable backup before replacing a device, but expect work/school and passwordless accounts to require sign-in again after restoration.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.