How to Back Up and Restore Microsoft Authenticator for Work Accounts
Question details
Organizations need to back up and restore Microsoft Authenticator accounts to maintain MFA access when migrating managed mobile devices between MDM platforms.
- Product
- Microsoft Authenticator
- Device & OS
- Android
- Scenario
- Migrating corporate Android devices from Hexnode to Intune, which requires wiping the phones and re-enrolling them.
- Observed behavior
- Users must safely back up their authentication tokens and restore them on the newly enrolled device, though some work accounts demand re-registration post-enrollment.
Ensure you have a personal Microsoft account available to use as the recovery account, as Microsoft Authenticator does not support using a work or school account as the primary backup account.
Configure Backup, Restore, and Pilot Test for Device Migration
Use the built-in cloud backup feature with a personal account, and run a pilot test to identify whether your organization's security policies require MFA re-registration.
When wiping devices for an MDM migration (such as Hexnode to Intune), preserving Microsoft Authenticator data is critical. However, due to strict enterprise security policies, a simple backup and restore might not automatically grant access to work or school accounts without additional verification.
Open the Microsoft Authenticator app on the original device, tap the three-dot menu, select Settings, and turn on 'Cloud Backup'. Sign in with your personal Microsoft account to save your credentials.
After wiping and enrolling the Android device into Intune, install Microsoft Authenticator. Open the app, select 'Begin recovery' at the bottom of the screen, and sign in with the same personal Microsoft account.
Check your restored work or school accounts. If they display an 'Action required' prompt, tap it and follow the on-screen instructions to re-authenticate or scan a new QR code provided by your IT department.
Before rolling out the migration to all users, perform this entire wipe, enroll, and restore process on a single pilot device to document the exact re-registration steps required by your organization's MFA settings.
Equip Your Managed Devices with WPS Office
While you navigate device management and authentication setups, consider deploying WPS Office as a lightweight, highly compatible alternative to Microsoft Office for your newly enrolled Android devices.
- 1. Download the App: Get WPS Office directly from the Google Play Store or push it to managed devices via Intune.
- 2. Launch and Edit: Open the app to immediately view, edit, and create documents without complex enterprise licensing hurdles.
- 3. Save and Share: Save your files in standard Office formats to maintain seamless workflow compatibility with external partners.

Frequently Asked Questions
Can I use my work or school account to back up Microsoft Authenticator?
No. Microsoft Authenticator requires a personal Microsoft account to serve as the recovery account for the cloud backup feature.
Why do I have to scan a QR code again after restoring my work account?
For security reasons, many IT administrators configure multifactor authentication policies that require tokens to be re-verified or re-registered whenever a device is wiped or moved to a new management system.
Where can I get further help if the Authenticator restore process fails?
For complex enterprise deployment and migration scenarios, it is recommended to consult the official Microsoft Authenticator Q&A forums for detailed, expert assistance from Microsoft engineers.




