Appearance
Summary
The Microsoft Authenticator app is used to approve multi-factor authentication (MFA) prompts and can enable passwordless sign-in for your Microsoft 365 account. This article covers installing the app, approving sign-in requests, and setting up passwordless access.
Before You Start
- A smartphone (iOS or Android).
- A Microsoft 365 account with MFA enabled by your organization.
Instructions
1. Install the App and Register It Against Your Account
Registration starts on your computer, not on your phone — the phone scans a code that your account's security page puts on screen.
- On your phone, open the App Store (iOS) or Google Play Store (Android).
- Search for Microsoft Authenticator and install the official app by Microsoft Corporation.
- On your computer, go to
mysignins.microsoft.com/security-infoand sign in with your work account. - Select Add sign-in method, choose Microsoft Authenticator, and select Add.
- Select Next until the page displays a QR code, and leave it on screen.
- On your phone, open Authenticator, tap the plus icon, and tap Add account.
- Tap Work or school account, then tap Scan a QR code, and point the camera at the code on your computer.
- If the camera will not read it, select Can't scan the image on your computer and tap Enter code manually on your phone.
- Finish the prompts on your computer. The account appears in the app's list, and the security page now lists Microsoft Authenticator among your sign-in methods.
2. Approve a Sign-In Request
Respond to push notifications when signing in.
- Sign in to a Microsoft 365 service (Outlook, Teams, etc.) with your email and password.
- A notification appears on your phone: "Approve sign-in?"
- Open the notification. You may see a number matching prompt — a two-digit number on your computer screen that you type into the app to prove the sign-in is yours.
- Type that number into the app, or tap Approve when no number is shown. If a request arrives when you are not signing in to anything, deny it — see How to Stop Unwanted MFA Prompts (Push Bombing and MFA Fatigue).
- You are signed in on your computer.
Tip: If you do not have cellular service, the Authenticator app can still generate time-based one-time passcodes (TOTP). Tap your account in the app to see a 6-digit code that refreshes every 30 seconds. Enter this code when prompted instead of using the push notification.
3. Set Up Passwordless Sign-In
Skip your password entirely and use the app to sign in.
- Open the Authenticator app on your phone.
- Tap your work account.
- Tap Set up Passwordless sign-in requests.
- Follow the prompts in the app to finish registering the account.
- The next time you sign in to Microsoft 365:
- Enter your email address (no password).
- If the password box appears anyway, select Other ways to sign in, then Approve a request on my Authenticator app.
- A number appears on screen. Enter that number in the Authenticator app, tap Approve, and confirm with your fingerprint, face, or PIN.
- You are signed in without typing a password.
4. View and Manage Accounts
Check or remove accounts from the app.
- Open the Authenticator app.
- Your accounts are listed on the main screen. Tap an account to see:
- The current one-time passcode (refreshes every 30 seconds).
- Account details and settings.
- To remove an account, tap the account > tap the gear icon or three-dot menu > Remove account.
Troubleshooting
DANGER
If you lose your phone or get a new one, you will need to re-register the Authenticator app. See the related article below for transferring MFA to a new device. Without a registered device, contact your IT helpdesk for a temporary bypass. If the phone is already lost or broken, see How to Recover Microsoft Authenticator After Losing Your Phone — it covers the backup sign-in methods you can use before raising a ticket.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Not receiving push notifications | Notifications blocked on phone | Check your phone's notification settings and ensure Authenticator notifications are allowed. |
| Number matching prompt not appearing | App or OS out of date | Update the Authenticator app and your phone's operating system to the latest version. |
| "Account already exists" error | Duplicate registration | Remove the existing account from the app, then re-add it by scanning a new QR code from your security settings. |