Last reviewed: 2026-08-20 · Report a change
How authenticator codes are created
During setup, the service displays a secret as a QR code or text key. The authenticator stores that secret and combines it with the current time to calculate a code. The service performs the same calculation. If the values match within a short window, it accepts the second step.
The QR code is sensitive. Anyone who copies it may be able to generate the same codes. Scan it only on the official service page while intentionally enabling 2FA. Do not save the QR image in an ordinary photo library or send it through chat.
Authenticator apps and phishing
A time-based code is safer than relying on a text message channel, but it is not tied to the destination website. A convincing fake page can ask for the current code and immediately relay it to the real service. Treat every code as a live authentication secret.
Open the service from a bookmark, password manager, or verified guide. If a person or message asks you to read back a code, stop. Support agents should not need a fresh authenticator code. Prefer a passkey or security key when the service offers one because those methods verify the domain cryptographically.
Moving to a new phone
Do not erase the old phone first. Check whether the authenticator supports secure account-based transfer or export, and follow its official instructions. For especially important services, sign in on a trusted computer, add the new authenticator, test a code, and only then remove the old device.
Some authenticator apps sync encrypted records; others keep them only on one device. Understand which model you are using. A screenshot is not a safe backup. Recovery codes or a second hardware authenticator create a cleaner emergency path.
Time errors and rejected codes
TOTP depends on accurate time. Set the device to obtain date and time automatically. If a code is rejected, wait for a fresh code, confirm the correct account entry, and verify that the device clock is right. Repeatedly trying codes on an unknown page is not troubleshooting.
If the account entry was duplicated during a transfer, one copy may contain an old secret. Use a current signed-in session or the service's official recovery steps to register the authenticator again. Do not delete all copies until a replacement method works.
Storage and recovery planning
Keep recovery codes separate from the phone that holds the authenticator. A printed copy in a secure location or an encrypted password-manager record can work, provided the recovery store does not depend entirely on the same locked account.
Record which accounts use the authenticator and review the list before replacing a device. Register two methods on high-value accounts where supported. Recovery planning is part of authentication setup, not an optional task for later.
When choosing or migrating an app, compare the Microsoft Authenticator transfer model, review independent Authy replacement criteria, and prepare a Duo Mobile device-change plan before erasing the old phone.
Practical checklist
How to put this into practice
- Open the official service settings and select authenticator app.
- Scan the QR code only while on the verified domain.
- Enter one generated code to confirm setup.
- Generate and store recovery codes away from the phone.
- Test a new sign-in before ending the current session.
- When changing phones, transfer and verify before wiping the old device.
At a glance
Compare the options
| Property | Authenticator app | SMS code | Security key |
|---|---|---|---|
| Needs mobile service | No | Yes | No |
| Phishing-resistant | No | No | Yes |
| Commonly supported | Yes | Yes | Growing |
| Device-change work | Transfer or re-enroll | Keep number access | Register backup key |
| Main risk | Code relay or lost seed | SIM and message attacks | Loss without backup |
Decision guidance
Choosing the right approach
An authenticator app is a good fit when a service supports TOTP but not a phishing-resistant method, when cellular service is unreliable, or when you need a widely compatible second factor. It is less suitable as the only route to a critical account if the app has no understood transfer or backup model. Decide how a new phone will be enrolled before the old phone is erased.
The QR code shown during setup contains the shared secret used to create future codes. Treat that setup image as more sensitive than an ordinary screenshot. Scan it on the official service page, do not send it through chat, and avoid leaving copies in an unprotected photo library. Save the service’s recovery codes separately instead.
A TOTP code proves possession of the shared secret but does not prove the destination is genuine. A fake page can relay the code immediately. If the service later offers passkeys or security keys, consider upgrading high-value accounts while retaining a tested recovery path.
Operational test
Rehearse the moments when security usually fails
Start with an ordinary device change. Imagine the phone or computer used for this control is unavailable today, not after a carefully planned migration. Identify which trusted device, independent authenticator, recovery code, provider account, or administrator would restore access. Then verify that route without deleting the working method. For Authenticator apps: setup, backup, and safer use, the practical starting action remains: Open the official service settings and select authenticator app. A recovery plan is only useful when the contact information is current and the required material can be reached without first unlocking the same account.
Next rehearse a suspected compromise. Do not answer the suspicious message or use its link to investigate. Open the known service independently, review recent sessions and security changes, and preserve evidence before removing anything. Rotate a reused password, revoke unfamiliar applications, and replace any exposed backup secret. If a second factor produced an unexpected prompt, deny it and assume the primary password may already be known. A strong authenticator helps prevent entry, but it does not clean up a stolen browser session, changed recovery address, malicious forwarding rule, or newly authorized application.
Finally, test the managed-account case. Workplaces, schools, families, and enterprise plans can place sign-in policy with an administrator or external identity provider instead of the service itself. Learn who can reset the control, what proof that person requires, and how an urgent request is authenticated. Never weaken the whole organization to solve one member's lockout. Record the official help route and an internal contact before a problem occurs, and separate administrative recovery from unsolicited support messages. This turns the comparison above—from Needs mobile service onward—into a maintainable choice rather than a one-time setup.
Common questions
Authenticator apps: setup, backup, and safer use FAQ
Can I use an authenticator app without internet?
Yes. TOTP codes are calculated from a stored secret and the current time.
Can I use two authenticator apps?
Some services let you register more than one method; others provide one QR secret. Follow the service's official instructions.
Should I photograph the QR code?
No. The image can contain the secret needed to generate every future code.
Why is my code rejected?
Check the selected account, use a fresh code, and make sure the device time is automatic. Then use official recovery if needed.
Is an authenticator app better than a passkey?
It is useful and widely supported, but a passkey or FIDO security key provides stronger resistance to fake websites.
Apply the idea
Representative service guides
Primary guidance
Sources and further reading
Product interfaces and available methods change. Re-check each service's official help before changing a security setting, and prepare recovery before removing an older authenticator.