End-user guide
Microsoft 365 · Account Security
A calm, step-by-step walkthrough for protecting your work or school Microsoft 365 account with the official Microsoft Authenticator app—including how to confirm you installed the real one.
Before you start
What you’ll need
Do this first — every time
Confirm you’re installing the real app
Fake “authenticator” apps do exist in both app stores. They copy the name and icon, then charge subscription fees or harvest your codes. Before you tap Install, check for these three things.
✓ The real app
- Publisher reads exactly “Microsoft Corporation”
- Free — no in-app purchases, no subscription
- Blue icon, simplified white key/shield mark
- The store listing links to Microsoft’s official privacy information
✕ Look-alikes to avoid
- Publisher is anyone other than Microsoft Corporation
- Lists “in-app purchases” or a free trial that converts to paid
- Keyword-stuffed name: “Authenticator OTP MFA 2FA Pro”
- Reviews complaining about charges or refunds
The genuine Microsoft Authenticator app is always free and is always published by “Microsoft Corporation.” If a listing asks you to pay, subscribe, or start a trial — it is not the real app. Close it and search again, or use the direct links below.
Step 1
Install Microsoft Authenticator
Open one of the links below directly on your phone — this skips the search results and takes you straight to Microsoft’s real listing.
iPhone: apps.apple.com/us/app/microsoft-authenticator/id983156458
Android: play.google.com/store/apps/details?id=com.azure.authenticator
Confirm the publisher says Microsoft Corporation before tapping Install.
Each code was generated to point directly at the verified store listing above — scanning it takes you to the same place as typing the link by hand. If you’re reading this on the phone you’re setting up, use the links instead of scanning your own screen.
Step 2
Enroll your account
This part is a back-and-forth between your computer and your phone. Keep both nearby.
Go directly to aka.ms/mysecurityinfo and sign in with your work email and password. Select Add sign-in method, choose Microsoft Authenticator, then select Add.
If Microsoft instead interrupts a normal sign-in with More information required, select Next. Both routes lead to the same setup. If Authenticator is not offered, stop and contact your IT administrator; your organization’s policy controls the available methods.
Confirm Microsoft Authenticator is selected. On the Start by getting the app screen, select Next. Leave the computer on the Set up your account screen while you pick up your phone.
Open Authenticator. If asked, allow notifications—Microsoft needs them to send approval requests. Tap the + (or Add account), choose Work or school account, then choose Scan a QR code. Allow camera access if your phone asks.
Tap “Work or school account” — not “Personal account”
On your computer, select Next to reveal a QR code. On your phone, point the camera at the code — the app opens the scanner automatically. Can’t scan it? Tap “Can’t scan the QR image?” to enter the code by hand instead.
Your computer shows a two-digit number. Seconds later your phone gets a notification — tap it, then type that same number into the app and confirm.
Number matching is standard for Microsoft Authenticator push approvals. You may not be prompted on every visit because Microsoft can remember a trusted session, and your organization may permit other sign-in methods. Never approve any request you did not start yourself.
Your organization may ask for another method for account recovery, such as a mobile number. Follow the on-screen instructions only if this appears. The choices are controlled by your organization’s policy, so some people will not see this screen.
After setup, you can review your methods at aka.ms/mysecurityinfo. Authenticator is preferred for everyday approval; phone text and voice methods are less resistant to phishing and may be disabled by IT.
Select Done on the success screen. Your Security info page should now list Microsoft Authenticator. Future sign-ins that require an Authenticator approval will show a number for you to enter in the app.
Before you close this out
You’ll know it worked when…
Check off each line. If any of these isn’t true, don’t assume it’s fine — jump to Troubleshooting below or contact IT.
- ✓The Microsoft 365 sign-in page showed a green “Success!” or “All set” confirmation, and you clicked Done.
- ✓Authenticator on your phone now shows your work email under an account tile labeled with your organization’s name.
- ✓The Security info page lists Microsoft Authenticator as a sign-in method.
- ✓If your organization requested a test approval or a second method, you completed it successfully.
If something doesn’t go as shown above
Troubleshooting
First confirm you chose Work or school account → Scan a QR code in Authenticator and that the entire QR code is visible on the computer. Increase the computer’s screen brightness, clean the phone camera, and move the phone slightly farther away. If it still fails, select Can’t scan the QR image? on the computer and enter the displayed code and URL manually in Authenticator.
Check that notifications are allowed for Authenticator in your phone’s Settings and that Wi-Fi or cellular data is working. Open Authenticator directly, then use the computer’s retry option if shown. Still nothing after two tries? Contact IT rather than deleting the account or restarting the whole process.
Do not delete anything unless you are sure the new entry is the mistaken one; removing a working Authenticator entry can lock you out. Return to aka.ms/mysecurityinfo and repeat the setup using Work or school account. If you cannot tell which entry is safe to remove, contact IT.
Deny or dismiss the request, return to the computer, and try again. Microsoft will generate a new number. Check the new number carefully and approve only if you personally started that sign-in.
That’s expected and by design — it stops someone who picks up your unlocked phone from approving sign-ins on your behalf. Use your normal phone unlock method.
Stop retrying and contact your IT administrator. They may verify your identity, reset your authentication methods, or issue a Temporary Access Pass if your organization has enabled that option. If you still have the old phone, keep it until the new phone has been registered and tested.
What to expect next
Living with MFA day to day
After your password, a number appears on screen. Open the notification on your phone (or open Authenticator if it doesn’t arrive), type the matching number, and confirm. The whole thing takes about five seconds once you’re used to it.
Never approve a notification you didn’t trigger yourself. If Authenticator asks you to confirm a sign-in and you weren’t actively logging in, someone else may have your password.
- Tap Deny
- Change your Microsoft 365 password immediately
- Contact IT using the details below
If you still have the old phone, keep it until the new phone is registered and tested. Authenticator backup may restore the account name, but work or school accounts still require you to sign in and complete registration again. If the old phone is lost or unusable, contact IT; after verifying your identity, they can tell you which recovery option your organization supports.
That’s fine — the app holds multiple accounts side by side. Just make sure you add your work account as a Work or school account, not a personal one, so it lines up with the correct organization.
Need help partway through?
MacWorks360 supports this rollout end to end. Reach out any time — during setup or after.
