Decide whether to transfer or rebind
Some apps support transfer QR codes or encrypted cloud restore. Other migrations require visiting each platform, removing the old authenticator, and binding a new one. For high-risk accounts, rebinding through the official settings page gives the clearest audit trail.
Test every login
A migration is not complete when the entry appears in the new app. Sign out in a controlled browser session, sign back in, and verify that backup codes or another factor still work before deleting the old copy.
Clean up after confirmation
Remove stale authenticator entries, revoke old device sessions where appropriate, and regenerate backup codes if the old phone was lost, sold, or handled by another person.
Recovery actions
- Make an account inventory before starting the phone transfer.
- Export or restore the authenticator according to that app's official documentation.
- Verify GitHub, Google, Microsoft, finance, hosting, and domain accounts one by one.
- Keep the old phone powered and connected until the last high-value account is confirmed.
Important limits
- A cloud phone backup does not always include authenticator secrets.
- Some work or school accounts are policy-controlled and cannot be moved by the end user alone.
- Do not rely on SMS as the only fallback for high-value accounts.