Disclaimer: EasyLoginHub is an independent informational platform providing practical guides and security awareness content. EasyLoginHub is not affiliated with, endorsed by, or connected to any third-party brands, app developers, or authentication service providers mentioned in this guide.
Upgrading to a new smartphone is an exciting milestone, but it often brings an unexpected hurdle: migrating your two-factor authentication (2FA) apps. While transferring photos, contacts, and mobile applications to a new device has become almost effortless, moving time-based one-time password (TOTP) authenticators requires extra caution. Making a mistake during this transition can result in locked accounts, tedious recovery processes, or permanent loss of access to critical online services.
Whether you rely on authenticator apps for banking, social media, work portals, or email accounts, careful planning is essential. At Easy Login Hub, our step-by-step login guides are designed to help you navigate digital access safely. Below is a comprehensive guide on how to securely transfer your 2FA authenticator apps to a new phone without getting locked out of your accounts.
The Golden Rule: Keep Your Old Phone Active
The single most important rule when upgrading smartphones is: Do not erase, factory reset, or trade in your old phone until you have verified every single 2FA account on your new device.
Most authenticator applications store security tokens locally on your physical device for safety. If you wipe your old phone before confirming that your 2FA tokens are active on your new device, you will destroy the unique cryptographic keys needed to generate your verification codes. Always complete the entire migration process while both phones are powered on and accessible.
Step 1: Check Your Authenticator App Type
How you transfer your 2FA codes depends largely on which authenticator app you use and how it handles encryption and account synchronization. Authenticator apps generally fall into two categories:
1. Cloud-Synced Authenticator Apps
Many modern authenticator apps allow you to back up your 2FA tokens to an encrypted cloud account associated with your Apple ID, Google Account, or vendor account. Examples include Microsoft Authenticator, Twilio Authy, and updated versions of Google Authenticator with cloud synchronization enabled.
- How it works: Your seed keys are encrypted and backed up to the cloud. When you install the app on your new device and sign in with the same master account, your 2FA entries restore automatically or via an account recovery passphrase.
- Security precaution: Ensure cloud backup features are toggled ON inside the app settings on your old device prior to starting the setup on your new phone.
2. Local / Device-Bound Authenticator Apps
Some users deliberately disable cloud sync for maximum privacy, while certain secure apps store token keys strictly within your device’s local enclave (unless exported manually).
- How it works: Accounts must be transferred manually using a batch export feature (typically generating a temporary export QR code on your old screen) or re-scanned individually for each service.
- Security precaution: Never screenshot or publish your export QR codes. They contain the raw setup keys for all your connected accounts.
Step 2: Pre-Transfer Checklist Before Switching Devices
To avoid security snags, run through this pre-migration checklist before opening your new phone:
- Locate Your Emergency Backup Codes: When you first set up 2FA on services like Google, GitHub, or financial institutions, you were likely given 8- to 10-digit backup codes. Retrieve these codes from your secure storage in case an app transfer fails.
- Verify Alternative Verification Methods: Check if your accounts have secondary backup options enabled, such as verified SMS phone numbers, backup email addresses, or hardware security keys.
- Update Connected Phone Numbers: If your new phone comes with a new phone number, update your profile settings across your accounts before relinquishing access to your old number.
Step 3: Transferring Popular Authenticator Apps
While exact menu layouts change over time, the general migration path for major authenticator tools follows these procedures:
Google Authenticator
Google Authenticator offers both cloud synchronization via a Google Account and a direct device-to-device export option.
- Cloud Sync Method: Ensure you are signed into your Google Account inside the app on your old phone. Download Google Authenticator on your new phone and sign into the identical Google Account. Your 2FA codes should populate automatically.
- Manual QR Transfer Method: If cloud sync is disabled, open the app menu on your old phone and look for the option to transfer or export accounts. Select the accounts you wish to move to generate an export QR code. On your new phone, install the app, choose the option to import existing accounts, and scan the QR code displayed on your old phone screen.
Microsoft Authenticator
Microsoft Authenticator relies on account-level cloud backups to move 2FA entries safely.
- On your old phone, open the settings menu within Microsoft Authenticator and verify that Cloud Backup (or iCloud/Android Backup) is enabled and linked to your personal Microsoft account.
- Download Microsoft Authenticator on your new phone.
- Upon opening the app on your new device, choose the option to Restore from backup rather than adding a new account immediately. Sign in with the master Microsoft account used for the backup.
- Note: Some personal or corporate accounts may require you to re-verify credentials for security reasons after a backup restore.
Twilio Authy
Authy supports multi-device synchronization linked to your mobile phone number and account password.
- On your old phone, navigate to settings and ensure Multi-Device access is turned ON. Also, verify that you know your Backup Password.
- Install Authy on your new phone and enter the phone number associated with your account.
- Approve the new device installation using a prompt sent to your old phone or an SMS/call verification.
- Enter your account Backup Password to decrypt and unlock your 2FA tokens on the new phone.
Step 4: Verify Every Account Before Wiping the Old Phone
Once you believe all 2FA tokens have migrated to your new device, perform a thorough verification test:
- Pick 3 to 5 critical accounts (e.g., primary email, financial accounts, social media).
- Open a private browsing window on a computer or secondary device and initiate a sign-in attempt.
- When prompted for a 2FA code, enter the digits generated by the authenticator app on your new phone.
- Confirm that the login succeeds.
- Only after successfully verifying all critical platforms should you erase or factory reset your old smartphone.
What to Do If You Get Locked Out
If you discover that an account did not transfer correctly and you no longer have access to your old device, don’t panic. You can still troubleshoot common login problems using established recovery procedures:
- Use One-Time Emergency Recovery Codes: Enter one of the offline backup codes generated during initial 2FA setup to gain access and register your new authenticator app.
- Fallback Verification: Look for options such as “Try another way” or “Use alternative verification” on the login screen to receive a code via email or SMS.
- Request Account Recovery: If no backup options work, seek formal account recovery assistance directly through the service provider’s official support channel. Be prepared to verify your identity using official government IDs, registered email confirmation, or account history details.
Long-Term Best Practices for 2FA Management
To ensure smooth device upgrades in the future, adopt these proactive security habits:
- Store Backup Codes Off-Device: Store printed or handwritten physical copies of recovery codes in a secure location, or place them inside an encrypted password manager.
- Consider Hardware Security Keys: Physical security keys (such as FIDO2/WebAuthn USB keys) can serve as an uncopyable secondary authentication method that operates independently of mobile apps.
- Audit Your Accounts Annually: Periodically review which services require 2FA and clean up inactive logins to streamline future device upgrades.
By following these systematic steps, transferring your authenticator apps to a new smartphone can be entirely stress-free. For more step-by-step account recovery assistance, security insights, and detailed Login Guide resources, explore the extensive library available at Easy Login Hub.









