Upgrading your phone should not mean losing access to your accounts or weakening your two-factor authentication (2FA). This guide shows you exactly how to move authenticator apps and one-time passcodes (TOTP) to a new phone without breaking your security. You will learn what to prepare, the safest migration workflows for popular apps, how to verify every account, and what to do if something goes wrong.
Why This Matters
Authenticator apps protect logins with time-based codes. If you switch phones without a plan, you can lock yourself out of email, banking, cloud storage, and social media—or accidentally leave 2FA active on a device you no longer control. A careful migration prevents both problems and keeps your identity and accounts safe.
Key Terms (Simple Definitions)
- Two-Factor Authentication (2FA): A second proof (like a code) after your password to log in.
- TOTP: Time-based one-time passwords generated by apps like Google Authenticator, Microsoft Authenticator, and others.
- Security Key (FIDO/WebAuthn): A physical key (e.g., YubiKey) used as a strong second factor.
- Recovery Codes: One-time backup codes provided by a service to regain access if you lose your 2FA device.
- Device Transfer/Backup: App features that securely copy your 2FA entries to a new phone.
Before You Start: The Safety Checklist
Complete these steps before moving any authenticator app:
- Keep your old phone powered and accessible. Do not erase, trade in, or factory reset it yet.
- Collect recovery options for each important account. Download or print recovery codes. Confirm you know your passwords and can receive account recovery emails or texts if needed.
- List your critical accounts first. Prioritize email, password manager, cloud storage, banking, crypto, work accounts, and social media tied to sign-in or recovery.
- Install all needed apps on the new phone. Install your authenticator app(s), your password manager, and a browser you use to log in.
- Update contact info. Ensure primary email and phone recovery options are current on key accounts.
- Enable screen lock and device encryption on the new phone. Use a strong passcode or passphrase.
Understand Your Authenticator’s Transfer Options
The safest method depends on your app. Here are the common ones:
- Google Authenticator
- Device-to-device QR transfer: Export on old phone, scan on new. Optionally enable cloud sync with your Google account, but understand that sync stores your TOTP secrets in your Google account; weigh convenience vs. centralizing risk.
- Microsoft Authenticator
- Cloud backup/restore: Backs up to your Microsoft account (with optional iCloud on iOS). Restore on the new device after signing in. Some enterprise accounts may require re-approval.
- Authy
- Multi-device and encrypted backup: Enable multi-device and backups (with a secure backup password). Install Authy on the new phone, authorize it, and let it sync. Turn off multi-device after migration if you prefer.
- Other TOTP apps (Aegis, 2FAS, Raivo, FreeOTP, etc.)
- Encrypted export/import: Many support password-protected exports. Import on the new phone, then delete the export file securely.
Step-by-Step: Safest General Migration Flow
- Confirm recovery access for each account. Download recovery codes and verify you can reach the recovery email/phone.
- Prepare the authenticator app on the new phone. Install and sign in, or set a strong app PIN/biometrics where available.
- Transfer your 2FA entries using your app’s supported method:
- Google Authenticator: Export QR on old phone → Import by scanning with new phone.
- Microsoft Authenticator: Sign into Microsoft account → Restore from backup on new phone.
- Authy: Enable multi-device and backups on old phone → Authorize and sync on new → Disable multi-device if desired.
- Other apps: Create encrypted export on old device → Import into new app → Delete export safely.
- Test logins for each priority account. From a desktop or another device, log out and log back in using the new phone’s codes. Confirm codes are accepted.
- Remove the old phone as a 2FA method only after testing. In each account’s security settings, remove the old device if it’s listed explicitly, then confirm that only your intended methods remain.
- Securely decommission the old phone. After confirming all accounts work on the new phone and backups exist, sign out, wipe, and reset the old phone before selling or recycling.
Provider-Specific Instructions
Google Authenticator
- On the old phone: Open Google Authenticator → Menu → Transfer accounts → Export accounts → Choose the entries to move → Show QR code.
- On the new phone: Open Google Authenticator → Get started → Import existing accounts → Scan the QR from the old phone.
- Test logins on your top accounts. If you use Google account sync within the app, review your Google Account security to ensure you’re comfortable with cloud storage of secrets.
- Keep the old phone until all tests pass. Then remove it from account security pages if listed and wipe the device.
Microsoft Authenticator
- On the old phone: Enable cloud backup in Microsoft Authenticator (Settings → Cloud Backup). Confirm it shows up-to-date.
- On the new phone: Install Microsoft Authenticator → Sign in to your Microsoft account → Restore from backup.
- Some accounts (especially work or school) may require re-approval or a new sign-in. Follow prompts from your organization’s admin if needed.
- Test logins, then remove old device entries from account security pages as appropriate.
Authy
- On the old phone: In Authy, enable Multi-device and encrypted Backups. Set a strong backup password you can remember; losing it can lock you out of your tokens.
- On the new phone: Install Authy → Verify your phone number → Approve the new device from the old phone → Sync tokens.
- After you confirm everything works, consider turning off Multi-device for tighter control.
Other TOTP Apps with Encrypted Export
- On the old phone: Create an encrypted export (with a strong password). Avoid unencrypted exports or screenshots of QR codes.
- Move the export file securely (AirDrop, local cable transfer). Avoid cloud drives for sensitive exports if possible. If you must, use end-to-end encrypted storage.
- On the new phone: Import the file → Verify entries and labels → Test logins.
- Delete the export file from both devices and any intermediary storage. Empty “recently deleted” folders.
Verifying Every Account (Don’t Skip)
Testing is what keeps you from surprises after you wipe your old phone. Use this process:
- From a separate device, sign out of the account.
- Sign back in with your password.
- When prompted for the code, use the new phone authenticator.
- Once successful, go to the account’s security settings:
- Confirm the correct 2FA method is listed.
- Remove outdated devices, phone numbers you no longer use, and old authenticator app entries.
- Regenerate and store new recovery codes if you rotated methods.
What If You Lost Your Old Phone Already?
- Try recovery codes. Many services let you log in with a one-time recovery code in place of the authenticator.
- Use backup methods you set up earlier. That could be a security key, a second authenticator device, or SMS/voice (use SMS only as a last resort).
- Contact support for account recovery. Be ready to prove identity. Expect delays for high-security services.
- Check for suspicious activity. If you lost a phone that still had access, review logins, revoke old sessions, and change passwords for your most sensitive accounts.
Security Keys as a Safer Upgrade Path
While authenticator apps are strong, hardware security keys can be even better for high-value accounts. Consider adding:
- At least two keys (a primary and a backup) registered with your most important accounts.
- Cross-platform, phishing-resistant protocols like FIDO2/WebAuthn or passkeys.
- Separate storage for your backup key (e.g., a safe at home).
Security keys reduce risks from SIM-swaps and malware stealing TOTP secrets. You can keep authenticator apps as additional options for flexibility.
Privacy and Risk Tips During Transfer
- Avoid screenshots of QR setup codes. They contain the same secret used to generate your codes.
- Prefer offline or end-to-end encrypted transfers. If your app supports local QR transfer or encrypted export, use it.
- Lock down your new phone first. Strong passcode, biometric unlock, and encrypted storage are essential.
- Label entries clearly. Use names you recognize (e.g., “Bank – Personal”) to avoid mix-ups during recovery.
- Rotate secrets if you suspect exposure. If you ever exported unencrypted, re-enroll 2FA on that account to generate a new secret.
Common Mistakes to Avoid
- Erasing or trading in the old phone too soon. Keep it until all accounts are verified on the new device.
- Relying solely on SMS. It’s better than nothing but vulnerable to SIM swapping. Keep app-based codes or security keys as primary.
- Skipping recovery codes. Without them, a lost device can lock you out for days—or permanently.
- Mixing personal and work accounts without guidance. Some organizations control 2FA policies. Follow your IT’s procedure.
- Storing exports in cloud drives unencrypted. If you must use cloud storage temporarily, encrypt the export and delete it immediately after use.
How to Re-Enroll 2FA on an Account (When Transfers Aren’t Supported)
Some sites don’t support direct transfers. In that case:
- Sign in to the website on a trusted device.
- Go to Security or Two-Factor settings.
- Disable the existing TOTP method (you may need a current code).
- Enable 2FA again. When shown the new QR code or secret, scan it with the new phone’s authenticator app.
- Save new recovery codes and test login from a separate device.
- Only then, remove old authenticator entries.
Backup and Recovery Plan You Can Trust
- Keep two second factors for your most important accounts (e.g., authenticator app plus a hardware key, or authenticator on two devices you control).
- Store recovery codes securely in a password manager or printed and locked away.
- Document your process (where codes live, which key is backup) in a secure note.
- Review twice a year to remove old devices and refresh recovery codes if needed.
When to Add Extra Monitoring
If your old phone was lost, stolen, or you notice unauthorized sign-ins, widen your protection. Review your inbox filters and forwarding rules, rotate passwords for critical accounts, and monitor your financial identity. A dedicated privacy and credit monitoring tool can alert you to unusual activity that might follow account exposure. If that level of protection would help your situation, see our resource on privacy, credit monitoring, and identity protection.
Quick Reference: Migration Order That Works
- Install and secure the authenticator app on the new phone.
- Gather recovery codes and confirm passwords for priority accounts.
- Transfer authenticator entries using your app’s safest method.
- Test logins for critical accounts from another device.
- Remove old device methods from each account.
- Securely wipe the old phone.
- Update your backup plan and store recovery codes safely.
Conclusion
Moving an authenticator to a new phone is safe and straightforward when done in stages: prepare recovery options, add the new device, test every important account, and only then retire the old phone. Choose the transfer method your app supports, keep your secrets encrypted during the move, and maintain at least one backup factor such as a hardware key or recovery codes. With a clear plan and careful testing, you can upgrade your phone without risking lockouts—or your security.
Good to Know
Move your 2FA in planned stages: add the new phone first, confirm codes work on every important account, then remove the old phone at the very end. Never factory reset or trade in your old device until you have tested logins.