New phone, same accounts: moving 2FA
The installation of the authentication application itself does not play code. Move entries and check logins before you clear your previous phone.
In this guide
The new phone shows an empty application, although the previous one had several entries. This does not necessarily mean losing accounts. Applications with TOTP codes can use sync, export or only local record. First set which mechanism was enabled on you.
Make a list of important services without rewriting the secrets themselves. Leave the old phone and working sessions at your fingertips. Book time to check each account, not just the first code.
When the application synchronizes entries
Log in a new application to the right supplier's account and follow its recovery instructions. Check if you have expected entries. The similarity of the list does not prove that every secret is up to date.
In Google Authenticator, you can synchronize the codes saved in your Google account. The application can also work without an account. In the latter option, logging in to Google on a new phone will not automatically play local entries from an old device.
Synchronization has consequences for recovery: you must be able to access the account that stores a copy. Do not base its only 2FA method solely on the same inaccessible copy.
When transfer or reconfiguration is needed
If the application has an export and import function, use the official procedure on both devices. The transfer QR code contains secrets to generate codes. Treat it as a set of keys to transfer accounts.
Not every pair of applications supports a compatible migration format. If the transfer is impossible, go through your account:
- Log in with the old code running.
- In the service settings, choose to change the authentication application or add a new method.
- Set up a new secret on your new phone and confirm it by code.
- Save new recovery codes if the service generated a new set.
Do not disable all 2FA if the service allows you to safely replace the method. If it needs to be disabled and re-enabled, perform both actions in one session.
Test before cleaning your phone
For each valid account, open a new login window and use the code from the new device. When there are many entries, check out the names you have checked in the prepared list. Do not save the codes on it.
Also check if the recovery copy is up to date. Removing an entry from the application does not have to invalidate the secret on the service side. If the old phone was stolen or the secret could have cut, change the configuration in the service instead of just copying the same codes.
When the old phone is gone
Try a synchronized copy, a second registered component or recovery code. If none of this is available, there is an official recovery of a particular service. The new application will not play secrets on the basis of the email address itself.
Do not use people who are promising to “turn around 2FA”. Do not transmit codes, passwords or screen access to them. After you have recovered your account, add a backup method and remove the lost device where the service provides this option.