Getting a new phone is exciting, but if you use the Microsoft Authenticator app to sign in to your Microsoft 365 account (multi-factor authentication, or MFA), there is one job you must do before you wipe or get rid of the old handset: move your authenticator to the new phone.
⚠️ Do this first. Keep the old phone switched on, charged, and connected to the internet until the new phone is fully set up and working. If you dispose of the old phone first, you may be locked out of your account and will need help from IT to regain access.
Make sure you set up the new phone while the old phone still works, then dispose of the old one only once you have confirmed everything works.
You don’t need to add the account on the new phone just yet — we’ll do that from the web, which links the account to the new device cleanly.
When you sign in, Microsoft will ask you to prove it’s really you. Use the old phone to approve this request — open the Authenticator app on the old phone and tap Approve, or enter the code shown on screen.
You should now see the new phone listed as a sign-in method alongside the old one.
You can have a limited number of authentication methods, so it’s good practice to tidy up.
If you’re not confident, leave the old entry in place for a few days and remove it once you’ve successfully signed in with the new phone a couple of times.
Only now should you wipe, sell, or dispose of the old phone. If you can, leave it switched off but charged for a week or so before you factory reset it — just in case you need to fall back to it.
While you’re on the Security info page, it’s worth adding a second method as a backup — for example a phone number for text or call verification, or even better, a passkey. That way, if you ever lose a phone or it’s damaged, you can still get in.
If you have already replaced your phone without setting up the new one first, see Gaining access to your Office 365 account if you have replaced your phone and have MFA enabled.
| Step | Action |
|---|---|
| 1 | Install Microsoft Authenticator on the new phone |
| 2 | Go to aka.ms/mfasetup and sign in |
| 3 | Approve the sign-in request using the old phone |
| 4 | Add the new phone and scan the QR code |
| 5 | Delete the old phone’s entry once the new one works |
| 6 | Test signing in, then dispose of the old phone |