Forum Discussion
Microsoft Authenticator & Microsoft Work Accounts
- Aug 06, 2026
Work accounts cannot normally be transferred to a new phone as fully working Authenticator registrations. A cloud backup may restore the account names, but the security keys are tied to the old device. Each work account must usually be registered again with a new QR code.
Try the following:
- Keep at least one existing phone or tablet available. Do not remove its Authenticator registration until the new phone is working.
- Open the My Sign-Ins security information page in a private browser window and sign in with the exact work account. Make sure you are not using the security page for a personal Microsoft account.
- Select Add sign-in method > Microsoft Authenticator or Authenticator app. Continue until the QR code appears.
- On the new Android phone, open Authenticator and select Add account > Work or school account > Scan a QR code. Repeat this process separately for every work account.
If Authenticator is still missing from the list, check whether that account already has several Authenticator devices registered. Keep one working method and remove only an old or unused device, then try adding the new phone again.
If the option remains unavailable, this is controlled by the organization rather than the phone. An Entra administrator must check Entra admin center > Protection > Authentication methods > Policies > Microsoft Authenticator and confirm that the method is enabled for the user or a group containing the user. The administrator may also need to issue a Temporary Access Pass or require the user to register MFA again.
The fact that Authenticator still works on existing tablets does not prove that new registrations are allowed. Existing registrations can continue working even when the organization has disabled Microsoft Authenticator for new setups.
Moving between Android phones does not fully transfer work-account credentials in Authenticator. A restore brings back the account name; each work or school account normally must be verified again. Do not remove the working registrations from your tablets or old phone yet. On the new Android device, add Work or school account and choose Sign in, then approve registration with an existing method if offered. If Security info does not offer “Authenticator app,” that method is disabled or restricted by the organization’s authentication policy, not by the phone. Ask each tenant administrator to confirm Authenticator is enabled for your user and to require re-registration or issue a Temporary Access Pass if necessary. After the new phone approves a test sign-in, remove the old device entry from Security info. A backup made on iOS cannot be restored to Android, so the iPad copies cannot provide an Android backup.