How to Set Up an Authenticator App for Two-Factor Authentication

Text-message codes can be stolen with a SIM swap. Here is how to switch your accounts to an authenticator app, step by step, and avoid getting locked out.

A man in a dark sweater looks at his smartphone beside a stylised blue illustration of a hand holding a phone
Artwork from Microsoft’s Authenticator app page. Image: Microsoft.

An authenticator app is a free phone app that generates the one-time codes used for two-factor authentication (2FA), and setting one up takes a few minutes per account: turn on 2FA in the account’s security settings, choose “authenticator app,” scan the QR code with the app, then type in the six-digit code it shows. This guide walks through that process step by step for Google Authenticator, Microsoft Authenticator and the verification codes built into Apple’s Passwords app on iPhone, current as of September 2026.

Key facts

  • What you need: a smartphone, the account you want to protect, and (ideally) a second screen to display the QR code
  • Time: a few minutes per account
  • Cost: free — Google Authenticator and Microsoft Authenticator are free apps, and iPhone codes are built into the Passwords app
  • Why bother: the FTC says authenticator app codes are safer than text messages because they are not exposed to SIM swap attacks
  • Don’t skip: save the account’s backup codes before you finish, or you risk locking yourself out if you lose your phone

If an account supports passkeys, those are even stronger, and our guide to setting up passkeys on iPhone, Android and Windows covers them. But many banks, shops, games and work tools still rely on passwords plus a second step, and for those an authenticator app is the upgrade most people should make today.

What is an authenticator app and how does it work?

Two-factor authentication means proving who you are with two different kinds of evidence. The Federal Trade Commission’s guide to two-factor authentication groups them as something you know (a password or PIN), something you have (a code from a text, email or authenticator app, or a security key) and something you are (a fingerprint or face). An authenticator app turns your phone into the “something you have.”

Most authenticator apps use an open standard called Time-based One-Time Password, or TOTP, published by the Internet Engineering Task Force as RFC 6238. When you scan a website’s QR code, the app stores a secret key shared with that site. From then on, the app and the site each combine that secret with the current time to calculate the same short code, which the standard recommends refreshing every 30 seconds. Because the code comes from the secret and the clock, the app works without an internet connection or phone signal — something both Google and Microsoft point out in their help pages.

Because TOTP is a standard, a QR code from almost any website works in almost any authenticator app. You do not need Google Authenticator for Google or Microsoft Authenticator for Microsoft.

Authenticator app vs text message codes

Codes sent by text message are better than nothing, but they have a well-known weakness. The FTC explains that hackers can take over your phone number through a SIM card swap attack and receive your texts, including verification codes. Codes generated by an app live on your device instead, so, in the FTC’s words, the passcode “isn’t susceptible to a SIM card swap attack or to someone hacking your email.” Google makes the same point in its 2-Step Verification help page, warning that codes sent by text or call “can be vulnerable to phone number-based hacks.”

Authenticator apps are not the strongest option, however. The US Cybersecurity and Infrastructure Security Agency’s “More than a Password” MFA guidance says “any MFA is better than no MFA,” but that the only widely available phishing-resistant method is FIDO/WebAuthn — the technology behind passkeys and hardware security keys. A fake login page can still trick you into typing an authenticator code; it cannot trick a passkey.

MethodHow it worksMain weaknessVerdict
Text message or email codeCode sent to your number or inboxSIM swaps, email account takeover, phishingBetter than nothing
Authenticator app (TOTP)Code generated on your phone every 30 secondsCan still be phished if you type it into a fake siteGood — the practical default
Push approvalTap Yes/No on a notification“Prompt bombing” if you approve without checkingGood when number matching is used
Passkey or security key (FIDO)Cryptographic login tied to the real websiteNeeds support from the siteBest — phishing-resistant

Which authenticator app should you use?

For most people, the choice is between three free options. All of them generate standard TOTP codes; the differences are in backup, syncing and extra features.

Google AuthenticatorMicrosoft AuthenticatorApple Passwords (iPhone)
PlatformsAndroid (6.0 or later) and iPhoneAndroid and iPhone; not available for PC or MacBuilt into iPhone
Cloud backup / syncOptional sync to your Google AccountAccount backup and restore featuresSyncs with your Apple passwords across devices
Push sign-in approvalsNo (Google prompts come from other Google apps)Yes, for Microsoft personal and work or school accounts onlyNo
Autofills codesNoNoYes, suggested above the keyboard
Works offlineYesYes, for codesYes
App lockOptional Privacy ScreenDevice PIN or biometricsDevice passcode, Face ID or Touch ID

Several password managers can also store TOTP codes, which is convenient because the password and the code autofill together. Proton’s pricing page lists integrated 2FA for its premium Proton Pass tier, for example, and our comparison of Bitwarden, 1Password and Proton Pass goes through the options. The trade-off is that your password and second factor then live in one place, which Microsoft argues against in its FAQ when explaining why its app is phone-only: “If both factors … are on the same device, it would be easier for an attacker to compromise both.”

How to set up an authenticator app on any account: 7 steps

The wording differs from site to site, but the process is the same almost everywhere.

  1. Install the app. Download Google Authenticator or Microsoft Authenticator from the App Store or Google Play, or skip this step on iPhone if you will use the Passwords app.
  2. Open the account’s security settings on a computer or tablet. Look for “Two-factor authentication,” “2-Step Verification,” “Multi-factor authentication” or “Login verification.”
  3. Choose “Authenticator app” (sometimes “Security app,” “Verification app” or “TOTP”). The site displays a QR code.
  4. Scan the QR code from inside your authenticator app — not with the regular camera app, unless you are using the iPhone Passwords method below. If you cannot scan it, choose the option to show a setup key and type it into the app.
  5. Enter the six-digit code the app now shows for that account, before it refreshes.
  6. Save your backup or recovery codes. Most sites offer a set of one-time backup codes. Print them or store them in your password manager. Google, for instance, lets you print or download a set of 8-digit backup codes for use if you lose your phone.
  7. Test it. Sign out and back in to make sure the code works before you rely on it.

Start with the accounts that matter most. The FTC recommends beginning with your bank, credit cards, email, social media, tax filing website and payment apps. Your email account is the most important of all, because it can be used to reset nearly every other password.

How to set up Google Authenticator

Google’s official Google Authenticator help page says the app needs Android 6.0 or above on Android devices. To add it as a sign-in method for your Google Account:

  1. Go to your Google Account’s 2-Step Verification settings. If 2-Step Verification is not on yet, open your Google Account, tap Security & sign-in and turn it on first.
  2. Tap Set up authenticator (on some devices, Get Started).
  3. Follow the on-screen steps to scan the QR code and confirm a code.

Google warns that it may take up to seven days for Google Authenticator to show up as an available sign-in option, a delay designed to let you secure your account if someone else added it. Having a trusted passkey or security key may speed that up.

To add any other website, open Google Authenticator, tap the plus button and scan that site’s QR code.

Sync or no sync?

Google Authenticator can back up and sync your codes across devices by signing in to your Google Account (version 6.0 or later on Android, 4.0 or later on iOS). Google says the codes are encrypted “both in transit and at rest.” You can also tap Use without an account to keep codes only on your phone. Syncing protects you from losing everything with a lost phone; local-only means your codes are gone if the phone is. For most people, syncing plus a strong, 2FA-protected Google Account is the safer choice.

Google also recommends turning on Privacy Screen (Menu > Settings > Privacy Screen), which requires your PIN, pattern or biometrics before the app opens.

How to set up Microsoft Authenticator

Microsoft Authenticator works with Microsoft accounts, work or school accounts and non-Microsoft accounts such as Amazon, Facebook, Instagram and Google, according to Microsoft’s guide on how to add your accounts to Microsoft Authenticator.

For a personal Microsoft account

  1. Sign in to the Security page at account.microsoft.com/security.
  2. Select Manage how I sign in, then Add a new way to sign in or verify, and choose Use an app.
  3. On your phone, open Authenticator, tap the plus icon, choose Personal account and tap Scan a QR Code.
  4. If you cannot scan it, choose I can’t scan the bar code on the PC and Enter code manually on the phone.

To require a code every time you sign in, scroll to the Two-step verification section on the same page and turn it on.

For other websites

In Authenticator, tap the plus icon, choose Add account, select Other (Google, Facebook, etc.) and scan the QR code the website shows.

Two limitations are worth knowing. Microsoft’s FAQ says push notifications “won’t work for third-party accounts, like Google or Facebook” — you will type codes for those. And Microsoft says it no longer supports Authenticator versions more than a year old, so keep the app updated.

How to use iPhone’s built-in verification codes

iPhone can generate the same codes without a separate app, storing them alongside your saved passwords. Apple’s guide to automatically filling in verification codes on iPhone describes two methods.

If the QR code is on another screen

  1. On your computer or iPad, open the website’s account settings and choose to enable two-factor authentication with an authenticator app. A QR code appears.
  2. Scan it with the iPhone camera.
  3. Select your saved account for that website. A verification code appears below the user name and password.
  4. Type that code into the website on your other device.

If you only have your iPhone

  1. In the website’s settings, choose the option to use a setup key, then copy it.
  2. Open the Passwords app, tap All, then tap your account for the site.
  3. Tap Edit, then Set Up Code, paste the setup key and tap Use Setup Key.

When a site later asks for a code, iPhone suggests it above the keyboard, so you do not have to switch apps. Under Settings > General > Autofill & Passwords you can choose whether codes that are filled in automatically are deleted after use.

Moving your codes to a new phone

Changing phones is a common way to get locked out, so plan for it before you trade in your old one.

  • Google Authenticator with sync: sign in to your Google Account in the app on the new phone and your codes sync automatically.
  • Google Authenticator without sync: on the old phone, tap Menu > Transfer accounts > Export accounts, select the accounts and show the QR code (or codes). On the new phone, choose Import accounts and scan them.
  • Microsoft Authenticator: Microsoft offers back up and restore features, but its FAQ warns that installing the app on a new device does not remove the old one. You must delete the app from the old device and also turn off verification for that device in your account’s security settings.
  • iPhone Passwords: codes travel with your saved passwords when they are synced to your new iPhone.

If a code is ever lost, the backup codes you saved in step 6 are your way back in.

Troubleshooting: codes that don’t work

  • “Invalid code” every time: TOTP codes depend on the clock. Google says Authenticator’s old time-correction setting is no longer available in version 7.0 and the app now uses your operating system’s time, so make sure your phone updates its date and time automatically.
  • Code expired: wait for the next code and enter it straight away.
  • Wrong account: if you have several codes for one site, rename them in the app so you can tell them apart.
  • Google Authenticator missing as a sign-in option: Google can take up to seven days to make it available for your Google Account.

Never share your codes

One of the most common threats to 2FA is social rather than technical: scammers call or text pretending to be your bank, a delivery company or tech support and ask you to “confirm” a code. Google states plainly that you won’t receive a call from Google to verify a code, and the FTC’s advice is not to share a verification code with anyone if you did not contact them first. A legitimate company never needs the code from your authenticator app.

Bottom line

Setting up an authenticator app is one of the highest-value security jobs you can do in half an hour. Pick one app — Google Authenticator if you want simple cross-device sync, Microsoft Authenticator if you use Microsoft or work accounts, or the Passwords app if you live on iPhone — then work through your email, bank, social and shopping accounts, saving backup codes as you go. Where a site offers passkeys, use those instead; everywhere else, an authenticator app beats a text message.

Frequently asked questions

What is the best authenticator app?

For most people, Google Authenticator, Microsoft Authenticator or the verification codes built into the iPhone Passwords app all work well, because they generate the same standard TOTP codes. Pick Google Authenticator for easy sync, Microsoft Authenticator if you use Microsoft or work accounts, and the Passwords app if you use an iPhone.

Is an authenticator app safer than SMS codes?

Yes. The FTC says app-generated codes are not susceptible to SIM card swap attacks, which can let criminals receive your text messages. Passkeys and security keys are safer still because they resist phishing.

Do authenticator apps work without internet?

Yes. Codes are calculated on the phone from a stored secret and the current time, so Google Authenticator and Microsoft Authenticator generate codes without an internet connection or mobile service.

What happens if I lose my phone with my authenticator app?

Use the backup codes you saved when you set up 2FA, or restore your codes from a synced account such as Google Authenticator's Google Account sync. Without either, you will need each service's account recovery process.

Can I use Google Authenticator for non-Google accounts?

Yes. Google says the app generates one-time codes for any site or app that supports authenticator app 2-Step Verification. Scan the site's QR code from inside the app to add it.

Sources

More on Two-factor authentication →Two-factor authenticationAuthenticator appsGoogle AuthenticatorMicrosoft AuthenticatorAccount security
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all