Authenticator Catch 22, the sequel

I wrote an article very much like this a year or so ago.  Since then, several friends have fallen victim to the Authenticator Catch 22 disease, so I decided a repeat article is in order.

So, what exactly is Authenticator Catch 22 disease?

This unfortunate condition occurs when an Authenticator user gets a new phone and gets rid of the old one before setting up Authenticator on the new phone. This is a BIG NO-NO!! Each and every Microsoft account you have REQUIRES you be fully signed in to add an authentication method.  If Authenticator on your old phone is the SOLE second factor you have for an account and it isn’t available, CATCH 22!!!  The account is now dead to you. If this is an MSA or Outlook.com accont, you have VERY limited options, the account is likely lost.  If this is a Business account, Microsoft Business support MAY be able to fix it for you. Regardless, this is a nightmare no one needs!!!

What can I do to avoid it?

I’m glad you asked!  There are several ways around this disaster:

  1. Keep the old phone long enough to use it to setup Authenticator on the new phone. I, personally, have taken this a step further in that I have TWO old phones with Authenticator still installed and active on them.  My Microsoft accounts will support as many Authenticator apps as I feel like setting up and they ALL get/produce the same codes. They’re no longer useful as phones, but they all do WiFi and that’s all I need.
  2. Setup as many second factors as you can.  I have as many alternate phone numbers and email addresses setup for each Microsoft account I have as the account will allow me to add.
  3. Go into account setup, tell it you have a new Authenticator app, let it bring up a new QR code, take a screenshot of this QR code and keep is somewhere safe.  Use it to setup a new Authenticator in the future.

I kinda view number 3 as an added security risk.  Should anyone come across these stored QR codes and recognize them for what they are, they will have full access to this/these Microsoft account(s),

The long and short of it is that this Authenticator trap is entirely avoidable, if you take a few easy steps when starting out.  One more thing, if at all possible, use the old phone number on the new phone.  One of the common alternate second factors is a phone number and the original phone number is a common choice for a second factor; it will DIE if you don’t re-use it.