How to Set Up the Microsoft Authenticator App
Multi-factor authentication (MFA) means your password alone is no longer enough to get into your account — you also approve each sign-in from your phone. This guide walks you through enrolling the Microsoft Authenticator app from scratch, confirming it works, and what to do when something goes sideways. Budget about five minutes.
What You'll Need
Your phone — the one you carry day to day, not a temporary or shared device.
A computer to sign in to your account. Recommended, but you can do the whole thing on your phone if you don't have one handy.
A few minutes somewhere with a decent internet or cell signal.
Use a phone you'll have long-term. Authenticator becomes your everyday sign-in key, so a personal phone is almost always the right choice over a loaner or shared device.
Step 1: Install the App
On your phone, download Microsoft Authenticator (it's free) from your app store:
iPhone — open the App Store and search for Microsoft Authenticator.
Android — open the Google Play Store and search for Microsoft Authenticator.
Make sure it's the official app published by Microsoft Corporation — the icon is a blue and gray padlock-style symbol. Open it once installed, and if it asks to send notifications, tap Allow. That's how it will prompt you to approve sign-ins later.
Step 2: Start Setup on Your Computer
Open a browser and go to https://aka.ms/mfasetup.
Sign in with your work email and password if prompted.
On the Security info page, click + Add sign-in method.
Choose Authenticator app, then click Add.
When the screen says Start by getting the app, click Next — you've already installed it.
A QR code appears. Leave this page open; you'll scan it next.
Step 3: Add Your Account in the App
Back on your phone, in the Microsoft Authenticator app:
Tap the + (plus) icon, usually in the top corner.
Choose Work or school account.
Tap Scan a QR code. Tap Allow if it asks for camera permission.
Point your phone's camera at the QR code on your computer screen.
The account is added automatically once the code is recognized.
Step 4: Approve the Test Sign-In
On your computer, click Next. A notification is sent to your phone.
Your computer screen shows a two-digit number.
Open the notification on your phone, type in that number, and tap Yes or Approve.
Your computer confirms the setup succeeded. Click Done. You're enrolled.
That two-digit number is called number matching. It proves you are the one approving the sign-in — not an attacker hoping you'll tap "Approve" out of reflex. Never approve a request you didn't start.
No Computer? Set It Up From Your Phone
You can complete enrollment entirely on your phone:
Install the Microsoft Authenticator app (Step 1 above).
In your phone's browser, go to https://aka.ms/mfasetup and sign in.
Follow the prompts to add the Authenticator app. Instead of a QR code, tap an option like Pair my account to the app or Can't scan? — your phone opens Authenticator and links the account directly.
Complete the test approval when prompted.
How Sign-In Works From Now On
The next time you sign in:
Enter your email and password as usual.
A number appears on your screen.
Your phone buzzes — open the notification, type in the number, and tap Approve.
That's it. No codes to memorize or retype.
When Something Goes Wrong
If… | Do this |
|---|---|
No notification arrives | Open the Authenticator app manually — the pending request usually shows inside it. Confirm notifications are enabled for the app and your phone has signal. |
The QR code won't scan | Raise your screen brightness so the code is fully visible. Still stuck? Click Can't scan image? on the computer for a code and URL to enter manually. |
It says the code is incorrect | Check that the number on your phone matches your computer screen exactly. If the request timed out, start the sign-in over. |
You got a new phone | Set up Authenticator on the new phone before wiping the old one. If the old phone is already gone, contact the help desk to reset your sign-in methods. |
If your phone was lost or stolen, contact the help desk right away — don't wait until you have a replacement. We'll revoke the old device's access so it can't be used to approve sign-ins.
Still Stuck?
Reach out to the support team and we'll walk you through it. Have your phone with you when you contact us — it makes the fix far faster.