Saturday, October 3 Lagos newsroom Newsroom online
Edition: Africa
Cybersecurity

Moving to a new phone? Transfer your authenticator codes before the old one disappears

Move authenticator codes as a separate, security-critical task—then test every important account before erasing your old phone.

The worst time to discover that your sign-in codes lived only on your old phone is after the phone has been wiped, sold or stolen. An authenticator app can protect email, banking-adjacent services, work tools and social accounts from a stolen password, but it can also become a single point of failure if there is no recovery plan.

Before changing phones, treat account access as a separate migration project. Your photos may move automatically while your verification setup does not.

First, make an account list

Open the authenticator app and list every service shown. Do not photograph QR setup codes or send screenshots through WhatsApp. Instead, record the service name, the account identifier and whether you have another recovery method. Prioritise the email account used to reset other passwords, your password manager, domain or hosting account, cloud storage, workplace administration and social pages.

For each important account, sign in through its official website or app and review its two-step verification settings. Generate fresh backup codes where the service supports them. Store those codes somewhere protected and separate from the phone—for example, in an encrypted vault or a securely stored paper copy. Google says each of its backup codes can be used once, and a new set invalidates the old set.

Do not store a password and its recovery code together in an unprotected note. Do not send codes to anyone who calls claiming to “help with migration”.

If you use Google Authenticator

Google’s current help documentation describes two approaches. Authenticator codes can sync to a signed-in Google Account, or accounts can be transferred from the old device using export and import QR codes. For a manual transfer, keep both phones with you, install the official Google Authenticator on the new device, use Transfer accounts on the old device to export, then scan the generated QR code with the new device.

That QR code contains sensitive account secrets. Scan it only on the new phone you control, in private. Do not save it as an image or let a repairer scan it. After the transfer, test several important accounts before making any change to the old phone.

If you use Microsoft Authenticator

Microsoft Authenticator supports backup and recovery, but Microsoft warns that what can be restored depends on the account type and platform. Work or school accounts may need you to sign in again after recovery, and backup does not remove the need for an organisation’s administrator or recovery policy.

Open the app’s settings on the old phone and confirm that the supported backup option is active before relying on it. Install the official app on the new phone, use the documented recovery route and follow prompts for accounts that require re-verification. If your employer controls the account, keep the IT contact and alternative sign-in process available before wiping anything.

Test before you erase

Use a private browser window or a device that is not already signed in. Enter the username and password, then confirm that the new phone generates or approves the required second step. Test the most important accounts first. Keep the old phone offline but intact until you have completed the list.

After successful testing, remove the old device from account security pages where appropriate, revoke sessions you no longer need, and only then perform the manufacturer’s proper factory reset. If the old phone is being sold, also remove device locks and ownership links through the official process. Never hand a buyer a phone that still displays authenticator codes.

If the old phone is already lost or broken

Do not panic and do not pay an unknown “account recovery agent”. Start with the official recovery method for each service: backup code, trusted device, security key, recovery email or organisation administrator. Use a previously signed-in, trusted device where possible. If the lost phone held an active SIM, contact the mobile operator through an official channel and secure number-based accounts as well.

Recovery can take time because a provider must distinguish the owner from an attacker. Anyone asking for your password, one-time code or authenticator QR secret is not completing a legitimate verification step on your behalf.

Frequently asked questions

Will phone cloning automatically move authenticator codes? Do not assume it will. Follow the authenticator provider’s documented transfer or recovery process and test the result.

Can I keep the same codes on both phones? Some transfer or sync arrangements can leave codes available temporarily, but account behaviour varies. Remove the old device securely after testing.

Should I turn off two-factor authentication before changing phones? Usually there is no need if you prepare supported recovery and transfer methods. Weakening protection creates another risk.

Continue reading on Tech Embed

Topic hub: Explore more in Cybersecurity in Nigeria.

Sources

tech2025

Share a useful experience

Be specific. Do not post account numbers, phone numbers, passwords, OTPs or other private information.