You have probably typed a six digit code from a text message before signing into your bank or email account. That is two-factor login, and it is a great habit to have. There is a safer version of that same idea, and it already lives on your phone. It is called an authenticator app.

If you read our earlier guide on what two-factor authentication is, you know why a second login step matters. This article goes one step further. It explains apps like Google Authenticator and Microsoft Authenticator, why security experts prefer them over text message codes, and exactly how to set one up.

You do not need to be a tech expert for this. Give yourself about 10 minutes, and we will walk through it together, one step at a time.

What is an authenticator app?

An authenticator app is a free app on your phone that generates a new numeric code every 30 seconds, and you type that code in along with your password to prove it is really you signing in.

Popular examples include Google Authenticator and Microsoft Authenticator. Both are free, and both work with many websites, not only Google or Microsoft accounts. Once you turn one on for a website (your bank, your email, Facebook, and so on), that site will ask for your password and then a fresh code from the app every time you sign in on a new device.

This is a form of two-factor login, the same idea behind the text message codes many sites already use. The difference is where the code comes from.

Plain talk: two-factor authentication

Two-factor authentication, sometimes called 2FA or multi-factor authentication, means you prove who you are two ways: something you know (your password) and something you have (your phone). It stops most scammers even if they have already stolen your password.

Why authenticator apps are safer than text message codes

Text message codes are better than a password alone. But security agencies rate them as one of the weaker forms of two-factor login. The Cybersecurity and Infrastructure Security Agency (CISA) advises that not all forms of multi-factor authentication offer equal protection, and it recommends stronger methods when they are available, according to its MFA guidance page.

The federal government’s own technical standard goes further. The National Institute of Standards and Technology (NIST), in its Digital Identity Guidelines (Special Publication 800-63B), formally labels text message codes sent over the phone network as a “restricted” authenticator. NIST tells organizations to watch for warning signs like a sudden SIM change or number porting before trusting a text message code, because those are signs the phone number itself may no longer be safe.

An authenticator app code never travels over the phone network at all. It is created right on your phone using a shared secret and the time of day, so there is no text message for a scammer to reroute.

The problem with SMS: SIM swapping

Here is the specific risk. In a SIM swap scam, a criminal convinces your phone company to move your phone number onto a SIM card they control, often using stolen personal details or a fake ID. Once that happens, any text message code meant for you, including your bank’s login code, goes straight to the scammer instead.

An authenticator app is not affected by this, because the code is not tied to your phone number at all. It is tied to the app itself, on the device you have in your hand.

Safety tip

If your phone suddenly loses all signal and cannot make calls or send texts, and you did not turn on airplane mode, call your phone company right away using a different phone. This is one of the clearest signs of a SIM swap in progress.

How an authenticator app works, in plain terms

When you turn on an authenticator app for a website, that site shows you a QR code (a small square barcode) on the screen. You open the authenticator app, choose “scan a QR code,” and point your phone’s camera at it. The app and the website now share a secret code that only the two of them know.

From that point on, the app uses that secret plus the current time to create a new six digit number every 30 seconds. The website does the same math on its end. If your two numbers match, you are let in.

Because the app relies on your phone’s clock rather than a text message, it keeps working even with no signal or data connection, according to Google’s own support page for Google Authenticator. This makes it more reliable when you are traveling or your phone service is spotty.

Say this

“Can you help me scan a QR code to set up my authenticator app? I want to make sure I do it right and write down the backup codes.”

Google Authenticator vs. Microsoft Authenticator

Both apps do the core job well. Here is how they differ.

Feature Google Authenticator Microsoft Authenticator
Cost Free Free
Works with non-Google sites Yes Yes
One-tap push approval No, code only Yes, for supported accounts
Works with no signal Yes, after setup Yes, for codes (push needs data)

If a site simply asks you to add “an authenticator app,” either one will work. If you use a lot of Microsoft or work accounts, Microsoft Authenticator’s one-tap approval can be a little faster day to day.

How to set up Google Authenticator

  1. On your phone, open the App Store (iPhone) or Google Play (Android) and search for “Google Authenticator.” Install it.
  2. Open the app once so it is ready to use.
  3. On your computer or phone, go into the security or login settings for the account you want to protect (your email, bank, or another site) and look for “two-factor authentication,” “2-Step Verification,” or “authenticator app.”
  4. Choose the option for an authenticator app. The site will show you a QR code.
  5. In the Google Authenticator app, tap the plus sign, then “Scan a QR code,” and point your camera at the screen.
  6. The app will show a six digit code. Type that code into the website to confirm the setup is working.
  7. Write down any backup codes the site offers and keep them somewhere safe, like a locked drawer, not saved as a photo on your phone.

How to set up Microsoft Authenticator

  1. Download Microsoft Authenticator from the App Store or Google Play, following Microsoft’s own setup instructions for your phone type.
  2. Open the app and allow notifications if asked, since these power the one-tap approval feature.
  3. Go to the security settings of the account you want to protect and choose “authenticator app” as your two-factor method.
  4. When the QR code appears, tap the plus sign inside Microsoft Authenticator, choose “Other account,” and scan it.
  5. Confirm the six digit code the app shows matches what the website expects.
  6. Save any backup codes the site gives you in a safe, offline place.

Try this

Set up your authenticator app for your email account first. Your email is often the key that resets every other password, so it deserves the strongest protection you have.

If you lose your phone

This is the part people worry about most, and it has a clear answer: backup codes. Every site that offers an authenticator app also gives you a short list of one-time backup codes when you turn it on. Write those down on paper and keep them somewhere safe at home, separate from your phone.

If you ever lose your phone, you can use a backup code to sign in, then set up the authenticator app again on your new phone. Most sites also offer an account recovery process if you have lost your backup codes too, though it can take longer. If you would rather keep a text message or email code as a backup method alongside your authenticator app, our guide on setting up two-step verification by email walks through that option.

It is also worth keeping a family safe word on hand for phone-based emergencies. If a scammer ever calls pretending to be a relative in trouble, our guide on setting up a family safe word explains how that simple habit protects you. And if you ever tap a suspicious link while checking your accounts, our calm 10-minute checklist walks you through exactly what to do next.

Where to go from here

Switching from text message codes to an authenticator app takes about 10 minutes per account, and it closes one of the more common doors scammers use to break into online accounts. Start with your email, then move on to your bank and any account that holds money or personal details.

For more ways to spot and stop scams before they cost you anything, our book Scam-Proof walks through this and other everyday protections in the same plain, step-by-step style as this article.