Skip to content

Authenticator without Microsoft & Google

75 min Average
Ein Wrap auf einem weißen Teller mit einem Rand, dessen Muster am Rand an eine Kette mit großen Gliedern erinnert. Der Wrap ist in sechs Teile geschnitten, die außen alle einen Stern tragen. Das äußere Wrap-Stück rechts ist etwas aufdie Seite gefallen und ein wenig Füllung ist auf den Teller gerutscht. Illustration: Florian Biege

We all use passwords to protect our data, for example when using online banking or our email account. But passwords alone can be insecure: if others figure them out (for example, through carelessness, a data breach or a cyberattack), your data is at risk.

The second factor (known as ‘two-factor authentication’, or ‘2FA’ for short) then acts as an additional security barrier: an app generates a code (a six-digit number), without which access to your data is denied. A new numerical code is generated after around 30 seconds. Only the app on your device knows these constantly changing access keys. Wherever possible, you should therefore enable two-factor authentication (2FA), particularly for email accounts, online banking, your cloud storage, the Deutsche Bahn’s DB Navigator, or when using government services.

The Authenticator apps from Microsoft and Google also do this for you – though they store your codes in a locked cage in the cloud: you cannot export the access codes (with Google, it’s very difficult) and transfer them to another app. Microsoft and Google are therefore deliberately making it difficult for us to use other services. Furthermore, to the best of our knowledge, Google does not encrypt data when codes are transmitted.

However, you can liberate your personal services and accounts (your employer may require you to use a specific app). Take a little time to make this change, which is not as easy as it sounds.

Different ways to cook

Our digital switch recipes provide an easy, simple way to give Big Tech the push, but there are other options available. We have tried to make it easy by focusing on a single approach and a small number of options, but there are other alternatives that are just as good. After all, what we mean by ‘good’, ‘not so good’ and ‘bad’ is open to debate: DI.DAY is about easy ways to give Big Tech the push (without getting into purism or being preachy). Our decisions are based on advice from our advisory panel.

An overview of the alternatives is available on the next page:

Ingredients

1 smartphone

with Android or iOS

1 list of services

for which you are using two-factor authentication

Recovery codes of all services

– Make sure you back it up before making the change!

Notepad

for notes

1 computer

makes the move easier

Preparation

Warning: Switching from Microsoft or Google Authenticator to a big-tech-free alternative is a little more complicated than switching to other services. If you make a mistake during the switch, you could lose access to your accounts. So, before you start, you should back up the ‘recovery codes’ for all your services. They’ll be your lifeline if anything goes wrong.

1 Get an overview

Make a list of all the services for which you use two-factor authentication. These are likely to include email accounts, social media, bank accounts, cloud services or online shopping sites. For each service, make a note of the name, email address or username, and the recovery codes.

2 Recovery codes

Go to every service where you use two-factor authentication and download or print out the recovery codes. You’ll need these codes if you lose access to a service whilst moving house. Keep them in a safe place – ideally printed out and stored in a safe – or digitally in a password manager that you can access even without two-factor authentication.

3 Export QR codes from Google Authenticator

This step is necessary if your security codes are currently stored with Google. If you’re using the Microsoft Authenticator, continue with step 4.

  • Open the Google Authenticator app.
  • Tap your profile picture / Google Account icon in the top right-hand corner.
  • Select ‘Transfer accounts’ from the menu.
  • Tap ‘Export accounts’.
  • Verify your identity (using your fingerprint, face scan or PIN).
  • Select the accounts you wish to transfer (some users recommend selecting no more than two accounts at a time).
  • Tap ‘Next’ in the bottom right-hand corner.

The app will now generate a QR code on your screen. Take a screenshot of it. You can then scan this screenshot (which you may have printed out) using the QR code reader in the new app (step 6).

4 Select new 2FA app

There are several good alternatives to Microsoft or Google Authenticator, particularly open-source programmes:

offers encrypted backups, biometric unlocking and the option to store backups in the cloud. The app is particularly user-friendly.

for iOS and Android: A simple but effective app developed by Red Hat. It supports TOTP.

for iOS, Android, Windows and Linux: offers end-to-end encryption, cross-platform synchronisation as well as import from Google and Microsoft Authenticator.

for Android, iOS, Windows, macOS, Linux: offers end-to-end encryption and synchronisation between devices (with a Proton account); can also be used without a Proton account. The generated codes can be exported.

for Android, iOS: also available as a browser extension.

is part of the Bitwarden password manager (see switch recipe), but can also be used as a stand-alone app at all times. It offers encrypted backups and synchronisation with the Bitwarden account.

5 Launch new app

The first time you launch the new app, you’ll set up encryption: choose a strong password (or use fingerprint biometrics for quick access). These codes are then stored in encrypted form on your smartphone – not in a third-party cloud.

6 Setting up 2FA accounts

From Google: Set up the new accesses by scanning the QR codes you saved in step 3. There have been reports that not all third-party Authenticator apps can read the codes generated by Google Authenticator. Then follow the same procedure as for Microsoft.

From Microsoft: Go through your list and set up your new logins. To do this, go to the relevant website, log in (still using the Microsoft or Google Authenticator) and set up a new 2FA access. You’ll usually find this option in the account or security settings.

Scan the QR code (or setup key) for each service, for example for your account on Bahn.de or the DB Navigator. Test the new 2FA immediately: enter the numeric code displayed on the website. You will only have activated the second factor once the service has confirmed it.

For Microsoft accounts:

  • Go to mysignins.microsoft.com → ‘Security info’ → ‘Add a sign-in method’ → ‘Authenticator app’.
  • Select ‘I’d like to use a different authenticator app’.
  • Scan the QR code displayed.

If you want to be on the safe side with work-related two-factor authentication codes, you may want to keep the Microsoft Authenticator app.

Dessert

To ensure your codes aren’t lost if you lose your smartphone or switch to a new one: Open the ‘Backups’ settings in the app and enable automatic backups. Choose a strong backup password – without this password, the file is worthless. We recommend also copying the backup file to a secure location: your own cloud storage (see our switch recipe Cloud Storage) or an external USB stick. You can later transfer everything to a new mobile in just a minute by importing this backup file with your security keys.

Enjoy your meal! You have just taken a big step towards a more independent digital existence.

Once you #DIDit – share our post about the digital switch and inspire others to take control of their own digital lives!

Topping

Passkeys instead of codes: More and more services now support passkeys – the modern, phishing-proof successor to passwords plus 2FA. Where a service offers them, you can set them up as an additional security measure. What’s more, Aegis also shows how much time each code takes to generate.

View more recipes

The DI.DAY website is funded by your donations