End-user guide

Microsoft 365 · Account Security

Setting Up Two-Factor Sign-In with Microsoft Authenticator

A calm, step-by-step walkthrough for protecting your work or school Microsoft 365 account with the official Microsoft Authenticator app—including how to confirm you installed the real one.

Prepared by MacWorks360
Verified against Microsoft guidance August 24, 2026
Time required: ~10 minutes

Before you start

What you’ll need

Your phone
Charged, with you
Login
Work email + password
Signal
Wi-Fi or cell data
Computer
To start enrollment

Do this first — every time

Confirm you’re installing the real app

Fake “authenticator” apps do exist in both app stores. They copy the name and icon, then charge subscription fees or harvest your codes. Before you tap Install, check for these three things.

✓ The real app

A
Microsoft Authenticator
Publisher: Microsoft Corporation
  • Publisher reads exactly “Microsoft Corporation”
  • Free — no in-app purchases, no subscription
  • Blue icon, simplified white key/shield mark
  • The store listing links to Microsoft’s official privacy information

✕ Look-alikes to avoid

A
“Authenticator App 2FA”
Publisher: unrelated developer
  • Publisher is anyone other than Microsoft Corporation
  • Lists “in-app purchases” or a free trial that converts to paid
  • Keyword-stuffed name: “Authenticator OTP MFA 2FA Pro”
  • Reviews complaining about charges or refunds
!
Golden rule

The genuine Microsoft Authenticator app is always free and is always published by “Microsoft Corporation.” If a listing asks you to pay, subscribe, or start a trial — it is not the real app. Close it and search again, or use the direct links below.

Step 1

Install Microsoft Authenticator

1
On your phone
Download the app using the verified link for your device

Open one of the links below directly on your phone — this skips the search results and takes you straight to Microsoft’s real listing.

iPhone: apps.apple.com/us/app/microsoft-authenticator/id983156458

Android: play.google.com/store/apps/details?id=com.azure.authenticator

Confirm the publisher says Microsoft Corporation before tapping Install.

QR code linking to the official Microsoft Authenticator listing on the Apple App Store
iPhone / iPad
Scan with your camera app
apps.apple.com/…/id983156458
QR code linking to the official Microsoft Authenticator listing on Google Play
Android
Scan with your camera app
play.google.com/…id=com.azure.authenticator

Each code was generated to point directly at the verified store listing above — scanning it takes you to the same place as typing the link by hand. If you’re reading this on the phone you’re setting up, use the links instead of scanning your own screen.

Step 2

Enroll your account

This part is a back-and-forth between your computer and your phone. Keep both nearby.

2
On your computer
Open Microsoft’s Security info page

Go directly to aka.ms/mysecurityinfo and sign in with your work email and password. Select Add sign-in method, choose Microsoft Authenticator, then select Add.

If Microsoft instead interrupts a normal sign-in with More information required, select Next. Both routes lead to the same setup. If Authenticator is not offered, stop and contact your IT administrator; your organization’s policy controls the available methods.

3
On your computer
Choose Microsoft Authenticator, then continue

Confirm Microsoft Authenticator is selected. On the Start by getting the app screen, select Next. Leave the computer on the Set up your account screen while you pick up your phone.

4
On your phone
Add your work account inside the app

Open Authenticator. If asked, allow notifications—Microsoft needs them to send approval requests. Tap the + (or Add account), choose Work or school account, then choose Scan a QR code. Allow camera access if your phone asks.

9:41


Add account
Personal account
Work or school account
Other (Google, Facebook…)

Tap “Work or school account” — not “Personal account”

5
Computer → phone
Scan the QR code

On your computer, select Next to reveal a QR code. On your phone, point the camera at the code — the app opens the scanner automatically. Can’t scan it? Tap “Can’t scan the QR image?” to enter the code by hand instead.

9:41


Scan QR code
Point your camera here
6
Computer → phone
Approve the test notification with number matching

Your computer shows a two-digit number. Seconds later your phone gets a notification — tap it, then type that same number into the app and confirm.

Number matching is standard for Microsoft Authenticator push approvals. You may not be prompted on every visit because Microsoft can remember a trusted session, and your organization may permit other sign-in methods. Never approve any request you did not start yourself.

9:41


Approve sign-in
Enter the number shown on your screen
27
Deny
Confirm
7
On your computer
Add another recovery method if requested

Your organization may ask for another method for account recovery, such as a mobile number. Follow the on-screen instructions only if this appears. The choices are controlled by your organization’s policy, so some people will not see this screen.

After setup, you can review your methods at aka.ms/mysecurityinfo. Authenticator is preferred for everyday approval; phone text and voice methods are less resistant to phishing and may be disabled by IT.

8
On your computer
You’re done

Select Done on the success screen. Your Security info page should now list Microsoft Authenticator. Future sign-ins that require an Authenticator approval will show a number for you to enter in the app.

Before you close this out

You’ll know it worked when…

Check off each line. If any of these isn’t true, don’t assume it’s fine — jump to Troubleshooting below or contact IT.

  • The Microsoft 365 sign-in page showed a green “Success!” or “All set” confirmation, and you clicked Done.
  • Authenticator on your phone now shows your work email under an account tile labeled with your organization’s name.
  • The Security info page lists Microsoft Authenticator as a sign-in method.
  • If your organization requested a test approval or a second method, you completed it successfully.

If something doesn’t go as shown above

Troubleshooting

Q The QR code won’t scan, or my camera doesn’t recognize it

First confirm you chose Work or school account → Scan a QR code in Authenticator and that the entire QR code is visible on the computer. Increase the computer’s screen brightness, clean the phone camera, and move the phone slightly farther away. If it still fails, select Can’t scan the QR image? on the computer and enter the displayed code and URL manually in Authenticator.

Q The test notification never arrives on my phone

Check that notifications are allowed for Authenticator in your phone’s Settings and that Wi-Fi or cellular data is working. Open Authenticator directly, then use the computer’s retry option if shown. Still nothing after two tries? Contact IT rather than deleting the account or restarting the whole process.

Q I accidentally added it as a Personal account instead of Work or school

Do not delete anything unless you are sure the new entry is the mistaken one; removing a working Authenticator entry can lock you out. Return to aka.ms/mysecurityinfo and repeat the setup using Work or school account. If you cannot tell which entry is safe to remove, contact IT.

Q I entered the wrong number, or the request expired

Deny or dismiss the request, return to the computer, and try again. Microsoft will generate a new number. Check the new number carefully and approve only if you personally started that sign-in.

Q Authenticator asks for a phone PIN, Face ID, or fingerprint just to open it

That’s expected and by design — it stops someone who picks up your unlocked phone from approving sign-ins on your behalf. Use your normal phone unlock method.

Q I got a new phone before telling IT, and now I’m locked out

Stop retrying and contact your IT administrator. They may verify your identity, reset your authentication methods, or issue a Temporary Access Pass if your organization has enabled that option. If you still have the old phone, keep it until the new phone has been registered and tested.

What to expect next

Living with MFA day to day

Signing in normally

After your password, a number appears on screen. Open the notification on your phone (or open Authenticator if it doesn’t arrive), type the matching number, and confirm. The whole thing takes about five seconds once you’re used to it.

You get a prompt you didn’t request

Never approve a notification you didn’t trigger yourself. If Authenticator asks you to confirm a sign-in and you weren’t actively logging in, someone else may have your password.

  1. Tap Deny
  2. Change your Microsoft 365 password immediately
  3. Contact IT using the details below
New phone, or the old one is lost

If you still have the old phone, keep it until the new phone is registered and tested. Authenticator backup may restore the account name, but work or school accounts still require you to sign in and complete registration again. If the old phone is lost or unusable, contact IT; after verifying your identity, they can tell you which recovery option your organization supports.

i
Already have Authenticator for another job or personal account?

That’s fine — the app holds multiple accounts side by side. Just make sure you add your work account as a Work or school account, not a personal one, so it lines up with the correct organization.

Need help partway through?

MacWorks360 supports this rollout end to end. Reach out any time — during setup or after.

Dealing with this in your business?

Ask Richard for practical Apple IT guidance tailored to your team, systems, and next step.

Direct response from Richard—usually within 5–15 minutes during business hours. No obligation.