Skip to content

How to Use the Microsoft Authenticator App

Applies toMicrosoft 365iOSAndroid
4 min fix Updated 23 Aug 2026
Quick Answer

Install the Microsoft Authenticator app from your phone's app store. On your computer, go to mysignins.microsoft.com/security-info, select Add sign-in method, choose Microsoft Authenticator, and scan the QR code it shows with your phone.

Checked against Microsoft Learn - end of support and retirement, Microsoft 365 Roadmap and between 5 Aug 2026 and 12 Sep 2026. Nothing published in that period has been linked to this guide.

Summary

The Microsoft Authenticator app is used to approve multi-factor authentication (MFA) prompts and can enable passwordless sign-in for your Microsoft 365 account. This article covers installing the app, approving sign-in requests, and setting up passwordless access.

Before You Start

  • A smartphone (iOS or Android).
  • A Microsoft 365 account with MFA enabled by your organization.

Instructions

1. Install the App and Register It Against Your Account

Registration starts on your computer, not on your phone — the phone scans a code that your account's security page puts on screen.

  1. On your phone, open the App Store (iOS) or Google Play Store (Android).
  2. Search for Microsoft Authenticator and install the official app by Microsoft Corporation.
  3. On your computer, go to mysignins.microsoft.com/security-info and sign in with your work account.
  4. Select Add sign-in method, choose Microsoft Authenticator, and select Add.
  5. Select Next until the page displays a QR code, and leave it on screen.
  6. On your phone, open Authenticator, tap the plus icon, and tap Add account.
  7. Tap Work or school account, then tap Scan a QR code, and point the camera at the code on your computer.
  8. If the camera will not read it, select Can't scan the image on your computer and tap Enter code manually on your phone.
  9. Finish the prompts on your computer. The account appears in the app's list, and the security page now lists Microsoft Authenticator among your sign-in methods.

2. Approve a Sign-In Request

Respond to push notifications when signing in.

  1. Sign in to a Microsoft 365 service (Outlook, Teams, etc.) with your email and password.
  2. A notification appears on your phone: "Approve sign-in?"
  3. Open the notification. You may see a number matching prompt — a two-digit number on your computer screen that you type into the app to prove the sign-in is yours.
  4. Type that number into the app, or tap Approve when no number is shown. If a request arrives when you are not signing in to anything, deny it — see How to Stop Unwanted MFA Prompts (Push Bombing and MFA Fatigue).
  5. You are signed in on your computer.

Tip: If you do not have cellular service, the Authenticator app can still generate time-based one-time passcodes (TOTP). Tap your account in the app to see a 6-digit code that refreshes every 30 seconds. Enter this code when prompted instead of using the push notification.

3. Set Up Passwordless Sign-In

Skip your password entirely and use the app to sign in.

  1. Open the Authenticator app on your phone.
  2. Tap your work account.
  3. Tap Set up Passwordless sign-in requests.
  4. Follow the prompts in the app to finish registering the account.
  5. The next time you sign in to Microsoft 365:
    • Enter your email address (no password).
    • If the password box appears anyway, select Other ways to sign in, then Approve a request on my Authenticator app.
    • A number appears on screen. Enter that number in the Authenticator app, tap Approve, and confirm with your fingerprint, face, or PIN.
  6. You are signed in without typing a password.

4. View and Manage Accounts

Check or remove accounts from the app.

  1. Open the Authenticator app.
  2. Your accounts are listed on the main screen. Tap an account to see:
    • The current one-time passcode (refreshes every 30 seconds).
    • Account details and settings.
  3. To remove an account, tap the account > tap the gear icon or three-dot menu > Remove account.

Troubleshooting

DANGER

If you lose your phone or get a new one, you will need to re-register the Authenticator app. See the related article below for transferring MFA to a new device. Without a registered device, contact your IT helpdesk for a temporary bypass. If the phone is already lost or broken, see How to Recover Microsoft Authenticator After Losing Your Phone — it covers the backup sign-in methods you can use before raising a ticket.

Symptom / ErrorPotential CauseSolution
Not receiving push notificationsNotifications blocked on phoneCheck your phone's notification settings and ensure Authenticator notifications are allowed.
Number matching prompt not appearingApp or OS out of dateUpdate the Authenticator app and your phone's operating system to the latest version.
"Account already exists" errorDuplicate registrationRemove the existing account from the app, then re-add it by scanning a new QR code from your security settings.

Last updated:

Frequently asked questions

Why does the app show a two-digit number instead of just an Approve button?
This is 'Number Matching', a security feature designed to prevent MFA fatigue attacks. You must type the number shown on your computer screen into your phone to prove you are actually the person trying to log in.
What happens if I get a new phone?
You must set up the Authenticator app again on the new phone. Before getting rid of your old phone, register a backup method (like a phone number for SMS) at mysignins.microsoft.com, or ask IT to reset your MFA.