Back to Blog
Privacy & Security
10 min read

Authenticator Codes Not Working After a New Phone? Fix the Pairing

An existing authenticator troubleshooting illustration reused for rejected codes after a phone change

The Short Answer

A rotating six-digit code proves only that the app has a setup secret and a clock. It does not prove that the secret matches the account you are trying to open. After a phone change, rejected codes usually come from one of four layers: time, account selection, transfer or restore, or service enrollment.

Protect your remaining access before troubleshooting. Do not delete the old app, remove the account, clear app data, or reset two-factor authentication until you have another working sign-in path. If the old phone is gone, start with our lost-phone authenticator recovery plan.

Why a Correct-Looking Code Can Be Wrong

Most authenticator entries use the Time-Based One-Time Password algorithm. RFC 6238 combines a secret shared during enrollment with a time step, commonly 30 seconds. The service calculates its own expected value. If the phone uses another secret, another account entry, or sufficiently different time, the values will not match.

  • Wrong secret: the new phone contains an older enrollment or a different service's QR setup.
  • Wrong identity: two entries share a similar label, but one belongs to another email, tenant, workspace, or environment.
  • Wrong time: automatic date, time, or time-zone settings are off.
  • Expired or reused code: the code changed during entry or was already accepted once.
  • Different verification method: the page expects a push approval, recovery code, SMS code, or service-specific challenge rather than TOTP.

Run This Safe Diagnostic Order

  1. Stop repeated guesses. Too many attempts may trigger a temporary lock or make recovery harder.
  2. Turn on automatic date and time. Also verify the correct time zone, then reopen the authenticator and sign-in page.
  3. Match the full account identity. Check service name, email, username, organization, and environment—not only the six digits.
  4. Wait for a fresh code. Enter it near the beginning of its cycle and submit once.
  5. Check transfer state. Confirm that the account was imported, synced, or restored rather than manually recreated from an unrelated QR code.
  6. Test another authorized factor. Use a backup code, security key, passkey, trusted device, or official recovery route if available.
  7. Re-enroll from the service. From a verified session, remove only the confirmed stale factor and scan the new setup QR code. Test before signing out.

Google Authenticator Transfers

Google says codes can sync to a new device when you sign in to the same Google Account inside Google Authenticator. Without account sync, the old app can export accounts as transfer QR codes for the new device. Google's official Authenticator instructions also advise checking code expiry, the correct service and account, and accurate device time when a code is rejected.

A transfer QR code contains sensitive authentication material. Scan it only into the intended authenticator on a device you control. Do not screenshot, email, upload, or store it in an ordinary photo library.

Microsoft Authenticator Restores

Microsoft's restore behavior depends on the account type. Its official recovery guide says some one-time-password accounts restore codes, while work or school accounts may restore only the account name and require another sign-in. A visible account tile after restore therefore does not always mean enrollment is complete.

Follow the status shown for each account. “Action required” or “sign in” means there is another verification step; repeatedly entering the rotating code will not replace it.

If the Old Phone Is Still Available

  • Keep it offline from daily use but powered and protected until migration is verified.
  • Use the authenticator's official transfer or export flow where supported.
  • For services that do not transfer cleanly, open the service's security settings from a trusted session and enroll the new device.
  • Test one fresh code for every critical account before removing anything from the old phone.
  • Generate and securely store new recovery codes after changing the factor.

Our complete authenticator transfer guide covers the planned migration flow. The order matters: add, test, recover, and only then retire.

If You Are Locked Out

The authenticator app cannot ask a third-party service to trust a new secret. Recovery belongs to the account provider. Use only the provider's official domain and support flow; ignore search ads, messages, or lookalike sites asking for a live code, password, recovery key, transfer QR image, or remote access to your device.

Once access is restored, add a second recovery path, label each authenticator entry clearly, save backup codes outside the phone, and document which accounts depend on the app. Then review Authenticator App 2FA if you want a focused iPhone vault for future enrollments.Download Authenticator App 2FA – Vats on the App Store

Frequently Asked Questions

Why do my old phone's authenticator codes work but my new phone's do not?

The new phone may not hold the same setup secret for that service, may be showing a similarly named account, or may have incorrect system time. A normal-looking rotating code does not prove that the new app is paired to the service.

Can I fix rejected codes by reinstalling the authenticator app?

Reinstalling rarely repairs the pairing by itself and can remove locally stored accounts. Preserve access, backups, exports, and recovery codes before deleting or resetting any authenticator app.

Does an authenticator app need internet after moving phones?

Time-based codes can normally generate offline once the correct secret is present, but sync, restore, transfer, account recovery, and service enrollment may require a connection.

What if I no longer have the old phone?

Try an already signed-in device, backup code, security key, passkey, SMS or email fallback if the service offers one, or the service's official account-recovery process. The authenticator app cannot recreate a service secret it never received or backed up.

Should I remove 2FA while moving phones?

Usually no. Keep the old factor active until the new factor is enrolled and tested. For critical accounts, add a second recovery method and save fresh backup codes before retiring the old device.

See Authenticator in action before downloading

Keep exploring

View all articles