Security · 8 min read
Changing phones without losing your authenticator codes
Resetting your old phone before moving your authenticator app is the fastest way to lock yourself out. Here's how to avoid it, and what to do if it's already happened.

I had a call this week from a client whose team member had just upgraded her phone. She transferred her photos, contacts and messages across, decided the old one was surplus to requirements, and factory reset it.
Then she tried to log in to her work accounts.
A handful of them now asked for a code from an authenticator app that no longer existed on any device she owned. She was locked out.
It's a remarkably common scenario, and entirely avoidable if you know the order to do things. Here's the short, practical version I send to clients before anyone changes phones.
Why this happens
An authenticator app (Microsoft Authenticator, Google Authenticator, Authy, 2FAS and the rest) generates a rotating six-digit code from a secret key that lives only on that device. The secret is not stored in the cloud, and it is not tied to your phone number. It lives in the app.
When you factory reset the phone, or uninstall the app, or drop the phone in a canal, that secret is gone. Every account that relied on it now sees a login attempt with no valid second factor, and correctly refuses to let you in.
This is the app working as designed. It just hurts when it's your phone.
Before you touch the old phone
Do these four things while the old phone still works. This is the part most people skip, and it's the difference between a five-minute job and a multi-day recovery slog.
1. List every account that uses the authenticator
Open the app and write down every account you can see. Don't rely on memory. Microsoft Authenticator hides some entries behind a dropdown, so scroll through the full list.
Common ones people forget:
- Microsoft 365 / work email.
- Google account (personal and workspace).
- Password manager (Bitwarden, 1Password, etc.).
- Accounting or invoicing software.
- Social media accounts with MFA turned on.
- Cloud storage (Dropbox, OneDrive, Google Drive).
- Any line-of-business app your organisation uses.
If you're supporting a team, ask each person to do this before any device refresh.
2. Check whether your app can cloud-backup
Some authenticator apps can back up their codes to an account, which makes moving to a new phone trivially easy:
- Microsoft Authenticator can back up to a personal Microsoft account and restore on the new phone. Note: this does not back up codes for your work or school accounts in all configurations, check the app's backup screen.
- Google Authenticator can sync codes to your Google account.
- Authy backs up to the cloud with a backup password.
If your app supports it, turn the backup on, confirm it says it has synced, and then test the restore on the new phone before you reset the old one.
If your app does not support cloud backup (older Google Authenticator builds, some others), you will need to move each account manually, see the next step.
3. Move each account, one at a time
For each account on your list:
1. On a computer, log in to the account and go to the security or two-factor settings. 2. Choose to add a new method, or replace the existing authenticator. 3. You'll get a QR code on screen. 4. Scan it with the authenticator app on the new phone. 5. Confirm the new phone generates a working code by logging in once with it. 6. Only then, remove the old phone from that account's trusted devices.
This is tedious for 15 accounts and vital for 15 accounts. The good news: you only do it once.
4. Keep the old phone for a week
Don't reset the old phone the day you switch. Keep it charged, on the same accounts, and use the new phone for everything. If something doesn't work on the new phone, the old one is still your safety net.
After a week of clean logins on the new phone, then reset the old one.
The app I recommend: Authy
If you want to make the next phone change painless, switch to Authy (by Twilio). It's free, it works on iPhone and Android, and unlike a plain authenticator app it keeps an encrypted backup of your tokens tied to your phone number and a master backup password. Install it on the new phone, verify your number, enter your backup password, and every code you had comes straight back.
Two things worth being clear about:
- The backup is encrypted with your backup password, and Authy cannot recover it for you. Store that password in your password manager, not in your head.
- Because access is tied to your phone number, treat your mobile account as part of your security. Set a PIN or port-out lock with your network provider.
Downloading Authy
- iPhone / iPad (App Store): apps.apple.com/app/twilio-authy/id494168017
- Android (Google Play): play.google.com/store/apps/details?id=com.authy.authy
Setting Authy up properly
1. Install Authy from the store link above and open it. 2. Enter your mobile number and country, then confirm the verification code sent by text or call. 3. When prompted, turn Backups on. If it doesn't prompt, go to Settings, then Accounts, and switch on "Backups". 4. Create a backup password. Make it long, unique, and save it in your password manager immediately. This password decrypts your tokens on any future device, and nobody can reset it for you. 5. In Settings, then Devices, turn Allow Multi-device off once you have the devices you need enrolled. This stops anyone adding a new device to your Authy account without you re-enabling it. 6. Add your accounts. In each service's security settings choose "add authenticator app", then scan the QR code with Authy. 7. Test one login end to end before you remove the old authenticator method from that account.
Moving to a new phone with Authy
1. Install Authy on the new phone and verify the same phone number. 2. Approve the new device from your existing Authy install, or accept the text/call verification. 3. Enter your backup password when asked, and your tokens decrypt onto the new phone. 4. Check a couple of codes work, then remove the old device under Settings, then Devices.
That's the whole job, usually five minutes rather than an evening of QR codes.
If you're already locked out
If the old phone is already reset and you're staring at "enter the code from your authenticator", here is the recovery path for the most common platforms. Expand the system you're locked out of for the exact steps.
Contact your tenant administrator. They can reset your MFA from the Microsoft 365 admin centre in under a minute, which clears the old authenticator and prompts you to set up a new one at your next sign-in. If you're a Live IT client, that's me, give me a ring and I'll have you back in within the hour. If you don't have an IT administrator, you'll need to use Microsoft's account recovery form with identity documents, which is far slower.
Official links:
Same principle, contact your Google Workspace administrator. They can disable two-step verification for your account temporarily, let you log back in, and help you re-enrol MFA on the new phone. If you're a Live IT client, contact me and I'll handle it. For a personal Google account that isn't managed by an organisation, use the account recovery flow with your backup email or phone number.
Official links:
Xero doesn't use authenticator apps by default, it sends a six-digit code by email or text. If you're locked out, go to the Xero login screen, click "Having trouble logging in?" and follow the prompts. If you set up an authenticator app as a second factor, Xero support can disable it after verifying your identity, which can take a day or two. Your Xero subscription admin can also help by resetting two-step authentication from their own account settings.
Official links:
Intuit offers an automated recovery flow. On the login screen, when prompted for the verification code, click "Try another way" or "Get help". You'll be asked to verify your identity using the email or phone number on file. If that fails, submit a request to Intuit support with your account details and business information. Recovery typically takes 24 to 48 hours.
Official links:
If you can't access your authenticator, Stripe offers recovery through your backup codes (provided when you enabled two-factor authentication) or by contacting Stripe support from the email on your account. Stripe will verify your identity and disable 2FA so you can re-enrol. For security reasons, team administrators cannot reset 2FA for another user, recovery must go through Stripe support. Expect a day or two.
Official links:
If you're locked out of Slack, your workspace owner or admin can temporarily disable your two-factor authentication from the admin settings, allowing you to log back in and set up MFA on your new phone. If you're the workspace owner and locked out yourself, Slack support can help after verifying your identity. If you're a Live IT client, contact me and I'll reset it from the workspace admin panel.
Official links:
Most password managers have a master password recovery flow, or an emergency recovery code printed when you first set up the account. If you have neither, and the authenticator is gone, you may be locked out permanently. This is why password managers tell you to save the recovery code. If you're a Live IT client, contact me and I may be able to help depending on which manager you use.
Official links:
For each locked account, go to that provider's account recovery flow. They all have one. The process is slower the less identity verification you set up beforehand (recovery email, phone, backup codes). Expect to prove who you are, and expect it to take anywhere from minutes to a few days. If you're a Live IT client and you're stuck, get in touch and I'll talk you through it.
The 10-minute checklist before your next phone upgrade
- Open the authenticator app and list every account.
- Turn on cloud backup in the app if it's available.
- Set up each account on the new phone and test logins.
- Confirm a recovery email or phone is set on every locked account.
- Print or save any backup recovery codes the account gave you.
- Keep the old phone alive for a week before resetting it.
Here it is as a one page PDF you can print, or send round the team before a device refresh.
Phone upgrade authenticator checklist (PDF)One page, printable, tick off every step before the old phone gets reset.What to put in place for your team
If you support a small organisation, make this a documented step in your device refresh process:
- A short checklist, the one above, sent to each user before their phone changes.
- An admin account that can reset MFA for users who still get caught out.
- A record of which apps each user has enrolled, so recovery isn't a guessing game.
Most lockouts I deal with are not hacking. They're a perfectly sensible person doing things in a sensible order that happens to be the wrong one. A five-minute checklist sent a week before the upgrade would prevent almost all of them.
If your team is about to refresh phones, or someone's already locked out and you need a hand getting back in, get in touch.
Need a hand with this?
I help small organisations across the UK with exactly this kind of work. Honest advice, plain English, no pressure.
Get in touch