Guides

From Microsoft Authenticator

Microsoft Authenticator can back up only into itself. The third-party accounts have to be re-enrolled.

Short version: No export. Re-enrol the non-Microsoft accounts; keep the app for Microsoft sign-in if you use it.

Steps

  1. Separate the two kinds of account

    Microsoft work/school and personal accounts use push approval and passwordless sign-in — those aren't TOTP and can't move. Everything else (GitHub, AWS, your bank) is ordinary TOTP and can.

  2. Re-enrol each TOTP account

    Sign in to the service, security settings, disable and re-enable two-factor, scan the new QR with Vault2FA. Save the fresh recovery codes.

  3. Optionally keep Microsoft Authenticator

    Only for the Microsoft accounts. Remove the third-party entries from it once they're in Vault2FA so you don't have stale duplicates.

  4. Make a backup

    Settings → Backup → Export encrypted backup.

Worth knowing

Afterwards

Make an encrypted backup (Settings → Backup) before you delete the old app, and check the support page if a code is rejected — it is nearly always the phone's clock.

Stuck? support@vault2fa.app. Never send a secret or a backup file by email.