Microsoft Authenticator Stuck in a Loop on a New Phone: Fix It

Tested guidance: This recovery sequence follows Microsoft’s current Authenticator restore, account-registration, and notification troubleshooting guidance for iPhone and Android.

Moving Microsoft Authenticator to a new phone can create a frustrating circle: the sign-in asks for approval, but the approval is sent to the old phone or to the same app you are still trying to activate. Reinstalling the app repeatedly usually does not solve that registration mismatch.

The right fix depends on what is looping. A backup can restore account entries, but it does not always restore a usable sign-in registration. Work and school accounts, in particular, normally need to be verified again on the new device.

Identify the loop before changing anything

First, note exactly where the process returns to the beginning. This prevents you from deleting the only method that can still approve a sign-in.

  • Approvals still go to the old phone: the account is registered, but the old Authenticator method remains active.
  • The new app asks you to sign in, then asks for Authenticator approval: you are trying to use the method being repaired to approve its own setup.
  • A restored account says “Action required” or “Sign in to restore your account”: the account name came back, but its credentials or device registration still need attention.
  • No prompt reaches either phone: notifications, network access, automatic date and time, or an organization policy may be blocking completion.

Personal accounts and work accounts recover differently

For a personal Microsoft account, one-time password data may return from backup, while passwordless sign-in must be set up again. For a work or school account, Microsoft says only the account name is restored. Treat a restored work account as a shortcut to re-registration, not proof that MFA has moved.

Backup and restore also stay within the same phone platform. An iPhone backup cannot be restored to Android, and an Android backup cannot be restored to iPhone. If you changed platforms, plan to add each account again.

Keep one working route into the account

Do not wipe the old phone, remove its Authenticator entry, or delete the old security method until the new phone has approved a real test sign-in. If the old device still works, keep it connected while you complete the transfer.

Before re-registering, update Authenticator from the phone’s app store. Confirm that automatic date and time are enabled, Airplane mode is off, and the app can use notifications. Switch between Wi-Fi and mobile data once if the screen keeps spinning. On Android, also check battery optimization because aggressive background restrictions can delay prompts.

If the sign-in page offers Use another verification method, choose a working text message, phone call, security key, recovery code, or Temporary Access Pass. That alternate method breaks the circular dependency and lets you reach the page where the new app is registered.

Restore first if a compatible backup exists

On a fresh installation, choose Restore from backup or Begin recovery before signing in or adding accounts. Sign in with the same recovery account used for the backup. If you already passed that screen and cannot see the recovery option, sign out of or remove the accounts from the app, then restart the recovery flow.

After restoration, open every recovered tile. Complete any Sign in, Action required, or verification prompt. Do not assume a visible account tile can receive push approvals until you test it.

Register the new phone as a fresh sign-in method

When restoration is unavailable or incomplete, add the account again. The safest route is to open the account’s security settings in a browser where you are already signed in, preferably on a computer rather than on the new phone.

For a personal Microsoft account

Open the Microsoft account Security page, choose to manage how you sign in, and add a new sign-in or verification method. Select the Authenticator app, then scan the QR code with Add account > Personal account > Scan a QR code on the new phone.

Complete the test prompt before closing the browser tab. If you use passwordless phone sign-in, enable it again only after ordinary two-step verification works.

For a work or school account

Open mysignins.microsoft.com/security-info and sign in using a method other than the Authenticator registration you are replacing. Select Add sign-in method, choose Authenticator app, and follow the wizard. In the app, use Add account > Work or school account, then scan the QR code shown in the browser.

The wizard sends a test notification to the new phone. Approve it and wait for the browser to show success. If the phone change is part of setting up Microsoft 365 apps, finish MFA first; the mailbox connection steps are much easier once the new method can answer prompts. This is especially relevant when following the iPhone mailbox onboarding sequence.

If your organization blocks registration by location or Conditional Access policy, or you have no alternate verification method, stop retrying. Your help desk may need to reset your registration or provide a Temporary Access Pass so you can authenticate once and enroll the new device.

For Google, Amazon, and other code-based accounts

These accounts are controlled by the security page of the service that issued the QR code. If their rotating codes did not restore, sign in to that service with a recovery method, replace the authenticator configuration, and scan its new QR code. Save any replacement recovery codes outside the phone.

Microsoft Authenticator recovery workflow for a new phone
Update the app, choose the correct recovery path, register the new method, and test it before removing the old phone.

Stop the approval prompt from repeating

If registration succeeds but sign-in still returns to the number-matching screen, unlock Authenticator and leave it open while you retry. Confirm that notifications are allowed at both the operating-system level and inside the app. Correct the phone’s date and time, disable a VPN temporarily, and test the other network connection.

Look at the account name on the prompt. People often have personal and work accounts with the same email-like label, and approving the wrong tile sends them back to sign-in. Remove a duplicate account from the app only when you can identify which entry is stale.

After the new phone approves one browser sign-in, test a second Microsoft 365 app. If Teams alone continues to reject the session, use the client-specific sign-in checks rather than rebuilding Authenticator again. That separates an app token problem from an MFA registration problem.

Questions you might have

Why does Authenticator ask me to approve Authenticator?

The sign-in system is still treating the old app registration as your required verification method. Because the new app has not completed enrollment, the setup tries to call a method that is not yet usable. Choose another verification option, restore a compatible backup, or ask your administrator for a temporary enrollment route.

Can I transfer Authenticator from iPhone to Android?

Not through Authenticator backup and restore. Microsoft limits recovery to the same device type, so an iOS backup restores to iOS and an Android backup restores to Android. When switching platforms, re-register Microsoft accounts and reconfigure third-party code generators from each service’s security page.

What if I no longer have the old phone or phone number?

Use any remaining method listed on the sign-in page, such as email, a security key, a recovery code, or a Temporary Access Pass. For a work or school account with no usable method, contact the organization’s help desk. For a personal Microsoft account, use Microsoft’s account recovery and sign-in helper rather than repeatedly removing and reinstalling the app.

Should I delete the old Authenticator method immediately?

No. First approve a real sign-in on the new phone and confirm that the security information page shows the new Authenticator method. Then remove the old method and, if appropriate, wipe the old phone. Keeping the old method for those few extra minutes gives you a fallback if the test fails.

Before you retire the old phone

Run one final test in a private browser window so a cached session cannot hide a broken setup. Verify that the prompt names the correct account, reaches the new phone, and completes after number matching or approval. Then remove the old Authenticator method from the account’s security information, review any remaining recovery methods, and store fresh recovery codes safely.

The important distinction is between restoring account names and registering a device for sign-in. Once the new phone is registered and tested, the loop stops because Microsoft no longer has to send approval to a device you cannot use.