Migration guide

How to Migrate from Microsoft Authenticator to Fob in 2026

Microsoft Authenticator is a perfectly good app if you live inside the Microsoft ecosystem. Your personal Microsoft account, Xbox, a work Microsoft 365 login, a few third-party codes - it all works. The moment you want to move your codes somewhere else, the edges start to show.

This guide is the honest way out. It works whether you end up on Fob, Aegis, 2FAS, or somewhere else. The steps are the same. Who the guide is for: Microsoft Authenticator users who want a non-Microsoft option for their 2FA codes, got burned by a Microsoft account lockout, are cleaning up after leaving an employer, or simply want their authenticator independent of any one cloud identity.

Who the guide is not for: if every account in your authenticator is a Microsoft personal or Microsoft 365 work account and you are happy with how that works, you do not need to leave. The honest version of this page starts there.

Why move from Microsoft Authenticator?

Microsoft Authenticator works. It is fast, it is free, and the passwordless sign-in flow for Microsoft services is genuinely well designed. There are three reasons most of the people who end up here want out.

None of this makes Microsoft Authenticator a bad app. It is the right app for a specific profile: Microsoft-ecosystem-heavy users, comfortable with Microsoft holding the sync key, not changing phones between platforms, small account count. If that is not you, a move is worth the time.

Understand what does and does not transfer

This is the part most migration articles skip, and it is the part most likely to trip you up. Microsoft Authenticator stores three very different kinds of accounts, and they migrate differently.

The rest of this guide walks through the third-party TOTP accounts. Microsoft accounts stay where they are (or go away when you stop needing them). Work and school accounts follow your IT policy.

Why there is no one-click export

Microsoft Authenticator has no user-facing export, on any platform, on any tier. There is cloud backup, but it is not an export format. It is a restore mechanism that requires the same Microsoft account and the same phone operating system. You cannot download a JSON file. You cannot scan a batch QR code. You cannot read the seeds off the device.

A handful of rooted-Android workarounds circulated in 2023 that pulled the Authenticator database. Treat them as academic curiosity, not a migration plan: they require root, they break on updates, and the extracted secrets have to be re-entered by hand anyway.

The reliable path is the one below. It is the same manual flow that works for leaving Authy: log into each service, disable 2FA, re-enable it with a fresh QR code in your new app.

How to migrate, account by account

On a desktop computer, with the service open in one window and your new authenticator in your hand:

  1. Log into the service using your current Microsoft Authenticator code.
  2. Go to Security or Account Settings. Look for "Two-factor authentication," "2FA," "Login security," or "Multi-factor authentication."
  3. Disable 2FA. The service usually requires a current code, sometimes a password too.
  4. Immediately re-enable 2FA, choosing "Authenticator app" or "TOTP app."
  5. Scan the new QR code with your destination app (Fob, Aegis, 2FAS, whatever you picked).
  6. Test the new code before you leave the page. Enter the 6-digit code from your new app into the service's confirmation field. If it accepts, the account is migrated. If not, scan again.
  7. Save the recovery codes the service offers you. Paste them into your password manager.

Do the accounts in blast-radius order, not alphabetical order: primary email first, banking and payments second, crypto third, work identity fourth, everything else last. A 40-account migration usually takes 90 minutes to 3 hours spread across a day or two, not one sitting.

Keep Microsoft Authenticator installed until the last account is confirmed working on the new app. It is your fallback if something goes sideways. Sign out and remove it only after every account has been logged into at least once using the new codes.

If you are also moving accounts off Authy, that is a similar manual flow (Authy does not export either). The step-by-step is at /import/authy. If you are coming from Google Authenticator instead, which does export as a QR batch, see /import/google-authenticator.

What happens to your Microsoft Authenticator data

Nothing, unless you remove it.

Third-party TOTP secrets stay on the old device, inside the Authenticator app, until you delete them. Re-enrolling an account at the service issues a new secret in your new app and invalidates the old one at the service level, but the stale entry in Microsoft Authenticator lingers until you swipe it away or uninstall.

Microsoft's cloud backup, if you had it enabled, stays in your Microsoft account for the standard retention window. Signing out on the device does not purge the backup on its own. If you want the cloud copy gone, turn off cloud backup in the app's settings before signing out.

Personal Microsoft account sign-ins and Entra work accounts stay tied to Microsoft Authenticator. Leave them in place or register a different authenticator on the Microsoft side (a different phone, a security key, SMS, whatever your account supports).

After migration, what Fob does differently

The migration is the point of this page. Fob is an option, not a pitch. Here is what changes if you end up in Fob rather than in another TOTP app.

If you are moving off Authy at the same time, the step-by-step is at /import/authy. Fob is on Google Play, Android first. iOS follows; get notified from the homepage when it lands.

FAQ

Can I export accounts from Microsoft Authenticator in 2026?

No. Microsoft Authenticator does not offer a user-facing export on Android, iOS, or any tier. Cloud backup is not an export: it only restores to the same Microsoft account on the same platform. The only way to move third-party TOTP accounts out of Microsoft Authenticator is to log into each service and re-enroll it with a fresh QR code in the new app.

Will my Microsoft 365, Xbox, or personal Microsoft account sign-in still work if I switch authenticators?

Yes, but those sign-ins are not TOTP codes; they are passwordless push notifications tied to your Microsoft account. Switching your third-party 2FA to a different authenticator does not change how you sign into Microsoft services. If you want to also stop using Microsoft Authenticator for those, register a different authentication method inside your Microsoft account (a different app, a security key, an authenticator set up under a new tenant, or SMS) and then remove Microsoft Authenticator from the approved list.

What happens to my work or school account?

That depends on your employer's conditional access policy in Microsoft Entra. Some tenants allow any TOTP app, in which case re-enroll following the same manual flow above. Some tenants require Microsoft Authenticator specifically; if yours does, you cannot move the work account to a different app without IT involvement. Check your employer's documentation before you touch the work login, and keep Microsoft Authenticator on the device for that one account if needed.

Is Microsoft Authenticator going away?

No. Microsoft is actively developing the app. The password autofill feature was deprecated in 2025 and pushed users to Microsoft Edge, which caused some friction and drove some migrations, but the authenticator function itself is stable and supported. This guide is not an emergency exit. It exists for people who want their TOTP codes independent of any one cloud identity.

Can I keep Microsoft Authenticator installed during migration?

Yes, and you should. It is your fallback if a re-enrollment fails silently or a service locks you out. Keep it on the device until every account is confirmed working on the new app, then sign out and remove it. Cross-tenant work accounts in particular deserve the belt-and-suspenders approach: confirm the new code works twice before you let the old one go.


Fob is on Google Play

On Android today. iOS to follow. Tag-based filtering, end-to-end encrypted cloud backup, export anytime.

Get it on Google Play