Forum Discussion
Microsoft Authenticator & Microsoft Work Accounts
- Aug 06, 2026
Work accounts cannot normally be transferred to a new phone as fully working Authenticator registrations. A cloud backup may restore the account names, but the security keys are tied to the old device. Each work account must usually be registered again with a new QR code.
Try the following:
- Keep at least one existing phone or tablet available. Do not remove its Authenticator registration until the new phone is working.
- Open the My Sign-Ins security information page in a private browser window and sign in with the exact work account. Make sure you are not using the security page for a personal Microsoft account.
- Select Add sign-in method > Microsoft Authenticator or Authenticator app. Continue until the QR code appears.
- On the new Android phone, open Authenticator and select Add account > Work or school account > Scan a QR code. Repeat this process separately for every work account.
If Authenticator is still missing from the list, check whether that account already has several Authenticator devices registered. Keep one working method and remove only an old or unused device, then try adding the new phone again.
If the option remains unavailable, this is controlled by the organization rather than the phone. An Entra administrator must check Entra admin center > Protection > Authentication methods > Policies > Microsoft Authenticator and confirm that the method is enabled for the user or a group containing the user. The administrator may also need to issue a Temporary Access Pass or require the user to register MFA again.
The fact that Authenticator still works on existing tablets does not prove that new registrations are allowed. Existing registrations can continue working even when the organization has disabled Microsoft Authenticator for new setups.
I'm not sure why you marked this as solved as it's is not solved. It's a fudge workaround.
Microsoft developers need to understand the user frustration with migrating to a new phone with the authenticator app
Major Bugs still an issue in 2026
1. Backup requires a personal account. Can't backup to work/school M365 account
2. Backup limit of 102 accounts. Once you go over that limit you can't backup
3. Backup is useless for M365 Business accounts as only a stub of the account restores and you have to go through your M365 business accounts one by one with the old phone to do the approval and manually set it up again. Lost your old phone? SOL. They should add an option on the AdminAuthMethodsBlade section in the azure admin portal to allow the Authenticator App backup the keys (like the option they added to allow passkeys transfer to a new phone)
4. Then when you manually add your 2nd phone, the MFA phones listed in the M365 personal account page don't have any option to add "friendly name". Just the model number is listed. If you have a glitchy iphone 16 and just got another phone of the same model and used it to manually add MFA on your M365 Business account? Good luck identifying which one to delete as the are both listed as iPhone 15.