Authenticator apps: which one to use and how not to get locked out

Password & accounts. Updated 2026-09-13. About 4 minutes to read.

Choose an authenticator app with an encrypted backup you control, save every account's recovery codes, and move your codes before you wipe or trade in your old phone.

Authenticator apps create the six-digit codes that change every 30 seconds when you sign in. They are far safer than text message codes because nobody can steal them by moving your phone number to another SIM. They can still be phished, and they cause lockouts when people lose or replace a phone without a plan.

The code itself works the same in every app. What separates the apps is backup, recovery and how easily you can leave. This guide compares the main options, then shows how to set one up and move it to a new phone safely.

How authenticator codes work, and their weak spot

When you scan the QR code on a website's security page, the site and your app share a secret. From then on, both combine that secret with the current time to produce the same short code. It works offline and never travels by text message.

The weak spot is you typing the code into the wrong place. In 2025 Microsoft described criminals using fake login pages to capture multi-factor codes and then log straight in to victims' email and HR accounts. A code is only as safe as the page you type it into.

Never read an authenticator code to anyone who calls or messages you, even if they say they are from your bank, IT team or the service itself. Real staff never need it.

The main apps and their trade-offs

  • Google Authenticator: free. Since April 2023 it can sync codes to your Google Account, so they survive a lost phone. The trade-off is that anyone who takes over that Google account may get your codes, so protect it with a passkey.
  • Microsoft Authenticator: codes for any site, plus push approvals with number matching for Microsoft accounts. Its cloud backup is tied to a personal Microsoft account.
  • Apple Passwords app: on recent iPhone, iPad and Mac versions it stores verification codes beside your passwords, fills them in automatically and syncs through iCloud Keychain. Convenient, but both factors sit in one place.
  • Password managers such as 1Password and Bitwarden: the same convenience and the same trade-off. Protect the vault with a strong master password and a passkey or security key.
  • Aegis for Android: free and open source, with an encrypted vault and encrypted export files, but no cloud sync, so you manage backups yourself.
  • 2FAS and Ente Auth: free apps for iPhone and Android. 2FAS can back up to your own cloud storage, and Ente Auth offers end-to-end encrypted sync across devices.
  • Twilio Authy: in July 2024 Twilio said attackers had identified data, including phone numbers, linked to Authy accounts through an unauthenticated endpoint. It asked users to update the app and be alert to phishing texts.

Choose using four questions

  • If my phone is lost tomorrow, how do I get my codes back?
  • Is the backup end-to-end encrypted, and who could reset access to it?
  • Can I export all my codes if I want to switch apps later?
  • Can I lock the app with my face, fingerprint or a PIN?

Set up an authenticator app on an account

  1. Open the account's security settings and look for authenticator app, 2-step verification or two-factor authentication.
  2. Choose the authenticator app option and scan the QR code shown on screen.
  3. Type the current code from the app to confirm the link.
  4. Save the backup or recovery codes the site gives you, on paper or in your password manager.
  5. Sign out and sign back in to test the code works.
  6. Once the app works, remove text message codes as a sign-in method if the site allows it.

Move your codes to a new phone without getting locked out

  1. Keep the old phone working until the very last step.
  2. Google Authenticator: on the old phone use Transfer accounts to export, then scan the export QR code with the new phone, or sign in with the same Google Account if sync is on.
  3. Microsoft Authenticator: confirm backup is on in the old phone's settings, install the app on the new phone, sign in with the same personal Microsoft account and tap Begin recovery. Some work accounts will ask you to verify again.
  4. Aegis, 2FAS and other apps: create an encrypted export or backup on the old phone and import it on the new one.
  5. Test codes on your email, password manager and bank from the new phone.
  6. Only then remove the app and wipe the old phone.

Push approvals and prompt bombing

Some apps let you approve sign-ins with a tap instead of typing a code. Criminals who already have your password can send prompt after prompt, hoping you approve one to make them stop. Number matching, where you type the number shown on the sign-in screen, blocks most of this. Never approve a prompt you did not start, and change your password immediately if prompts appear out of nowhere.

Frequently asked questions

Is an authenticator app safer than SMS codes?

Yes. App codes cannot be taken by a SIM swap or intercepted on the phone network. Both can still be phished, which is why passkeys and security keys are stronger again.

I lost my phone and had no backup. What now?

Use each account's saved recovery codes. If you do not have them, start the account recovery process for your email first, since password resets for everything else go through it. Recovery can take days, so start straight away.

Should I keep codes in my password manager?

It is convenient and fine for most accounts if the vault itself is protected with a passkey or security key. For your email and the password manager itself, use a separate authenticator or key.

Is cloud backup of my codes safe?

Backup that is end-to-end encrypted, or protected by a strong account with a passkey, is safer than no backup. Lockouts from lost phones are far more common than attacks on well-protected backups.

Tools that help

Related guides

Sources