Guide

How to Set Up 2FA on a New Phone Without Losing Access

Getting a new phone when you have 2FA enabled across dozens of accounts is one of the most nerve-wracking parts of upgrading. Do it wrong and you could be locked out permanently. Do it right and the whole process takes about 20 minutes.

Step 1: Do This Before You Switch Phones

The most important thing is not to wipe or trade in your old phone until you've confirmed 2FA is working on the new one. Many people hand in their old phone at a carrier store before setting up their authenticator on the new device โ€” this is how people get locked out.

Also, locate your backup codes for each important account before you start. These are the one-time codes you were given when you first set up 2FA. If you saved them, keep them accessible during the transfer process. If you don't have them, generate new ones from each account's security settings now, while you still have access.

Step 2: Transfer Your Authenticator App

How you transfer depends on which authenticator app you use. The two most common are Google Authenticator and Authy โ€” and they work very differently.

Transferring Google Authenticator

Google Authenticator added an "Export accounts" feature that makes transferring straightforward. On your old phone, open Google Authenticator โ†’ tap the three-dot menu โ†’ Transfer accounts โ†’ Export accounts. Select all accounts and it generates a QR code. On your new phone, open Google Authenticator โ†’ Transfer accounts โ†’ Import accounts โ†’ scan the QR code from your old phone.

If you have Google Account sync enabled (added in 2023), your codes are automatically synced to your Google Account and will appear on the new phone when you sign in. See our full Google Authenticator transfer guide for step-by-step details.

Transferring Authy

Authy stores your codes in an encrypted cloud backup, so switching phones is easier. Install Authy on your new phone, sign in with the same phone number, and your codes will sync automatically after you enter your backup password. The key is having your backup password โ€” if you've forgotten it, you'll need to use backup codes for each account.

Authy also has a "multi-device" feature that lets you keep both phones active during a transition, which is useful.

Step 3: Verify Before Wiping Your Old Phone

After the transfer, log out of one of your important accounts and log back in using the 2FA code from your new phone. Confirm it works. Then test 2-3 more accounts. Only once you've confirmed everything works should you proceed with wiping or trading in your old phone.

If something doesn't work โ€” use your backup codes to access the account, then disable and re-enable 2FA from scratch on your new phone.

If You Already Switched and Are Locked Out

If you've already wiped your old phone and now can't access 2FA codes, you have a few options. Try your saved backup codes first โ€” this is what they're for. If you don't have backup codes, use the account's recovery process: most services allow recovery via verified email address, trusted phone number, or identity verification. See our guide on what to do when locked out of a 2FA account.

For Google specifically, the account recovery process is thorough but can take 3-5 days to verify your identity. For crypto exchanges, recovery options are often more limited โ€” contact support immediately.

What About SMS-Based 2FA During a Switch?

SMS 2FA follows your phone number, not your device, so it usually survives a phone upgrade without any action โ€” codes are delivered to your number regardless of which handset receives them. The caveats are timing and SIM swapping. If you are moving to a new carrier or changing numbers, keep the old number active until every important account has been verified with the new one, and update your phone number in each account's security settings while you still have access. If you have ever been a victim of SIM swapping, avoid SMS as a second factor altogether and use an authenticator app or hardware key instead.

Setting Up 2FA Fresh on the New Phone

If you cannot transfer your authenticator app at all, you can rebuild each account on the new device manually. Sign in to each service on the new phone using backup codes or email recovery, then go to that service's security settings and disable 2FA, re-enable it, and scan the fresh QR code into your new authenticator app. It is slower than transferring, but it also gives you an opportunity to clean up: remove old methods you no longer use, generate new backup codes, and store them in your password manager. Prioritise accounts in order of importance โ€” email first, then banking, crypto, social media, and work accounts.

Key Takeaways

Transfer your authenticator before wiping your old phone. Save backup codes before you start. Test on your new phone before completing the handover. If you use Authy, the process is largely automatic. If you use Google Authenticator, use the built-in export feature or enable Google sync.

Transferring Other Authenticators: Microsoft, 1Password and Bitwarden

Microsoft Authenticator stores codes locally but can back them up if you sign in with your Microsoft account and enable the Backup feature in the app's settings; on the new phone, sign in again and the codes are restored. 1Password and Bitwarden handle this differently โ€” TOTP secrets live inside your vault, so installing the app on the new phone and signing in to your vault brings the codes with you automatically, with no QR transfer step.

Ente Auth is worth a mention for privacy-minded users: like Authy, it keeps an encrypted cloud copy, so the new phone restores everything after you sign in with your account password. Whichever app you use, the rule is the same โ€” sort out the backup while the old phone is still in your hands, not after it leaves them.

Common Mistakes When Switching Phones With 2FA

  • Handing the old phone to a trade-in kiosk before testing the new one, then realising a code is missing.
  • Forgetting the Authy backup password and discovering cloud restore is locked behind it.
  • Leaving Google Authenticator's cloud sync disabled, then assuming the codes would just appear.
  • Updating the phone number on only half of your accounts, so the others keep sending codes to the old number.
  • Storing backup codes in a note on the old phone โ€” the very device you are about to erase.

Every one of these is avoidable with ten minutes of preparation. Make a list of your five most important accounts, confirm you can generate codes for them from the new device, and only then wipe or sell the old handset.

Cloud Sync vs Local Export: Which Should You Use?

Cloud sync (Authy, Ente Auth, Google Authenticator with backup enabled) is the low-effort option: codes follow your account, device changes become a non-event, and a stolen phone costs you nothing. The trade-off is that your TOTP secrets now live on a server, which makes the security of that account the security of all your codes โ€” a compromised Authy or Google account is a compromised everything.

Local export (Google Authenticator's QR transfer) keeps secrets on your devices only, which suits people who distrust storing credentials in the cloud. The cost is manual work: every phone change means an export step, and a broken screen before an export means account-by-account recovery. For most people, encrypted cloud backup protected by a strong account password is the pragmatic middle ground.

Quick Answers About Moving 2FA to a New Phone

Will the old phone keep generating codes after the transfer? Yes, the secret is duplicated rather than moved. Both phones stay valid until you remove the account from the old app.

Do I need internet to scan the export QR code? No โ€” the transfer happens device-to-device through the camera.

How long does the whole process take? A full export-import for a typical set of accounts takes around 20 minutes including the verification sign-ins.

What if I have dozens of accounts? Transfer them all at once with export, then verify the five most important before wiping anything.

Should I keep the old phone turned on during the whole switch? Yes, and do not wipe it until the new device generates valid codes. Keeping both phones active for a day or two is the safest overlap.

What if my authenticator app asks for a PIN or fingerprint before export? That is expected security โ€” enter it, then continue with Export accounts. It prevents someone with your unlocked phone from copying your codes.

Is there a way to move codes without the old phone at all? Only if you saved backup codes or have cloud sync enabled. Without either, you must re-enrol each account on the new phone manually.

Related Articles