They all generate the same codes
Almost every authenticator implements the same open standard, generating a six-digit code from a shared secret and the current time. That means any of them will work with any service that offers authenticator-app two-factor authentication, and you can move between them freely if you keep the original setup codes.
The differences that matter are backup, synchronisation across devices, whether secrets can be exported, and how well the app protects itself with a PIN or biometric lock.
How the main options compare
Google Authenticator now supports account synchronisation, which fixed its historical weakness, though the export path remains limited. Microsoft Authenticator adds encrypted cloud backup and push approvals for Microsoft accounts, making it the natural choice inside that ecosystem. Authy remains popular for its multi-device support and encrypted backups, with the caveat that its desktop applications were retired.
Password managers such as 1Password, NordPass, Proton Pass and Bitwarden also store codes. That is convenient and vastly better than no second factor, though it does put the password and the code in one place, which is a trade-off worth making consciously.
- Google Authenticator: simple, now syncs, limited export
- Microsoft Authenticator: encrypted backup, push approvals
- Authy: multi-device, encrypted backup, mobile-focused
- Password managers: convenient, single point of compromise
- Hardware keys: strongest, phishing-resistant, costs money
Backup is the decision that matters
Most people who lose access to their accounts do so because they replaced a phone without moving their codes. Whatever app you choose, either enable its encrypted backup with a strong separate password or store every service's recovery codes offline at setup.
Recovery codes are the universal safety net. Print them or keep them in an encrypted file that is not stored inside the account they protect, and regenerate them after any suspected compromise.
Where passkeys and hardware keys fit
Authenticator codes can still be phished: a live relay page collects your password and code and uses them within seconds. Passkeys and hardware security keys are bound to the real domain and cannot be replayed, so prefer them wherever a service supports them.
Keep an authenticator app for the many services that still offer nothing better, and remove text-message recovery from any account that allows you to.
Switching apps safely
Do not delete the old app first. For each important account, sign in, disable two-factor authentication and re-enable it, scanning the new QR code with the new app and confirming a code works before moving on. Save the fresh recovery codes as you go.
Work through your email and password manager first, then banking, then everything else. Keep the old phone accessible until the list is complete.
- Re-enrol account by account, never bulk-delete
- Verify a code works before moving on
- Save new recovery codes for each service
- Email and password manager first
