Insights & News
Microsoft Authenticator Setup for Business
- September 7, 2026
Microsoft Authenticator is a free app for iOS and Android that approves sign-ins to Microsoft 365 and other accounts, replacing a texted code with a push notification you approve on your phone. For most Australian businesses it is the method staff should be on, and with Microsoft retiring its own SMS and voice authentication on 1 February 2027, moving people onto it has become a deadline rather than a recommendation. One thing to know before you start: it is no longer a password manager, because Microsoft removed that in 2025.
Key facts
- Free on iOS and Android, and no additional Microsoft licence is required to use it.
- Approves sign-ins with a push notification and number matching, which is stronger than a texted code and harder to abuse.
- Also generates time-based codes for non-Microsoft services, so it can replace several separate authenticator apps.
- Stores passkeys, which matters because Microsoft is steering everyone towards them as SMS retires.
- It is no longer a password manager. Microsoft removed password autofill in stages between June and August 2025 and moved saved passwords to Edge.
- If a passkey was created in Authenticator, disabling or removing the app disables that passkey. This trips people up when they change phones.
Why push approval beats a texted code
A texted code is a secret the user reads off one screen and types into another, which means it can be handed to the wrong place. Phishing kits that sit between the user and the real sign-in page capture the code and relay it inside its short validity window, and SIM swapping lets an attacker receive the message directly. Both attacks are routine rather than exotic.
Push approval with number matching closes most of that. Instead of typing a code, the user sees a number on the sign-in screen and enters it into the app. That single change defeats the fatigue attack, where someone spams approval prompts at 2am hoping a half-asleep user taps yes. There is nothing to tap blindly, because the prompt cannot be satisfied without looking at the screen the sign-in came from.
How to set it up
Install Microsoft Authenticator from the App Store or Google Play. Be careful here: search results are full of similarly named apps, and the one you want is published by Microsoft Corporation.
Then, on a computer, sign in to your work account and go to your security information. Add a sign-in method, choose the authenticator app, and scan the QR code the browser displays with the app. The app and the account are now paired. The whole process takes about two minutes per person once someone has done it before.
Do two more things while you are there. Register a second method, so a lost or replaced phone is an inconvenience rather than a lockout. And if the account has SMS or voice registered as its only other method, that is the one to remove once Authenticator is working, because it is being retired anyway.
What it no longer does
Authenticator used to store and autofill passwords. Microsoft removed that across 2025: from June you could no longer add new passwords, in July autofill stopped working and stored payment details were deleted, and from August saved passwords were no longer accessible in the app. They were synced to the Microsoft account and are reachable through Edge instead.
Worth being clear about the consequence for a business. If staff were using Authenticator as their password manager, they are now either using Edge for it or they have quietly gone back to reusing passwords and saving them in browser profiles. Authenticator is an authentication app, not a credential store, and a business needs a proper password manager alongside it.
The one exception is passkeys, which Authenticator does still hold. That creates a dependency worth knowing about: if someone set up a passkey through Authenticator and then deletes the app or wipes the phone without transferring it, the passkey goes with it.
What to do at the business level
Do not leave this to individuals. Work out who is still on SMS or voice, because those are the accounts that break in February 2027, and prioritise anyone whose only registered method is one of them. Then run the migration as a small project rather than a series of support calls: tell staff what is coming, move them in groups, and check the report afterwards rather than assuming.
Decide the policy at the same time. Which methods are permitted, whether SMS is allowed at all as a fallback, and what happens for staff without a work smartphone, where a hardware token is usually the answer rather than an exception you forget about. See multi-factor authentication for how we run this as a managed control, and the SMS and voice retirement for the dates.
Frequently asked questions
Is Microsoft Authenticator free?
Yes. The app is free on both iOS and Android and needs no additional Microsoft licence, so there is no cost argument for staying on text message codes. It works with Microsoft 365 work and school accounts, personal Microsoft accounts, and any other service that supports standard time-based codes, which means one app can often replace several.
What happened to password autofill in Microsoft Authenticator?
Microsoft removed it in stages during 2025. From June 2025 you could no longer add or import passwords, in July autofill stopped working and stored payment information was deleted from the device, and from August 2025 saved passwords were no longer accessible in the app. Passwords were synced to the Microsoft account and are now reachable through Edge. Multi-factor authentication and passkeys were unaffected and continue to work.
Do staff have to install it on a personal phone?
It is the usual arrangement, and the app itself gathers very little, but you cannot compel someone to install work software on a device they own. Where a staff member declines, the answer is not to leave them on SMS, since that is being retired. Provide a work device, or issue a hardware token, which is a small physical device that generates codes and costs less than the incident it prevents. Treat it as a documented exception with an owner rather than a gap.
What happens if a staff member loses their phone or gets a new one?
If they registered a second method, they use that and re-register the app on the new phone, which takes a couple of minutes. If Authenticator was their only method, an administrator has to intervene, and the tempting shortcut at that point is to weaken the account to get them working. Authenticator can also back up account credentials to the cloud for restore onto a new device. Either way, the fix is to register a second method during setup rather than after the first lockout.
If you have staff still receiving codes by text message, that stops working in February 2027 and the migration is easier done now than in January. We can identify who is affected, move them across and set the policy behind it. Request a callback and we will sort it.
About the author
Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on cybersecurity, including multi-factor authentication and passwordless sign-in, Microsoft 365 hardening, identity and access management, and the Essential Eight, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.
Recent Posts
-
Microsoft Authenticator Setup for Business -
Windows Hello for Business: Passwordless Sign-In for SMEs -
Microsoft 365 MFA Setup: Security Defaults or Conditional Access -
Microsoft Is Retiring SMS and Voice MFA: What to Do Before February 2027 -
Choosing a Password Manager for Small Business -
Passkeys vs Passwords: What Businesses Need to Know -
Password Policy for Australian Small Business -
How to Share Passwords Securely With Staff -
What Is Veeam, and Why 4iT Uses It for Backup -
Sophos Intercept X and MDR: Endpoint Protection That Fights Back







