What Are Authenticator Apps and How Do They Work? (2024)

An authenticator app is a secure and easy method of identity verification that works by generating number codes that users enter alongside their credentials to access an account. Keep reading for details on how authenticator apps work and how to use them.

What Does an Authenticator App Do?

Authenticator apps are used as an additional method of verification for Multi-Factor Authentication (MFA). MFA is an important security measure that protects your account in case your password is compromised. Passwords are compromised frequently in today’s cybersecurity environment due to data breaches and sophisticated phishing attacks, among other types of cyber threats.

Some of the most popular apps include Google Authenticator and Microsoft Authenticator. To verify your identity, an authenticator app generates a code called a Time-based One Time Password (TOTP) that you enter along with your username and password when you log into an account. The code is usually six to eight digits.

Why You Should Use an Authenticator App

Experts recommend using MFA on every account that it’s available to increase security and better protect your personal data. An authenticator app is a free, simple and secure way to use MFA, and most accounts with security settings offer it as an option.

How Authenticator Apps Work

Authenticator apps work based on the TOTP verification model. When you set up MFA on your account and choose TOTP, the account server will create a QR code that the authenticator app will scan. The QR code contains a secret algorithm that uses the current time as a factor in generating TOTP codes.

The authenticator app and the account server will be the only parties that possess the secret algorithm. They will independently use the secret to generate the exact same codes at the exact same time.

When the user logs in, they will enter the code displayed in the authenticator app. The server will check if the entered code matches the code that it generated. If the codes match, the user is granted access. If not, user access is denied.

There are many options for authenticator apps. Popular standalone phone apps include Google Authenticator and Microsoft Mobile Phone Authenticator.

Authenticator apps can also be integrated into a password manager like Keeper Password Manager. A password manager securely stores all your credentials, including passwords, passkeys and TOTP codes. This option is the most convenient because password managers sync across all devices and some can autofill your TOTP code along with your credentials. It also means you don’t have to wrangle with multiple devices just to log in.

Are Authenticator Apps Secure?

Authenticator apps are secure because they keep the code local to your device and the codes are not sent unencrypted over the internet. This means they can’t be intercepted through common cyber attack methods. Since the codes reset every thirty to sixty seconds, it’s difficult for cybercriminals to steal them. Because using an authenticator app is simple, free and secure, it’s now the most recommended type of MFA.

For a long time, the default MFA method was a one-time code sent by SMS text to your phone or by email. However, there are a number of security flaws with this method. These messages are not encrypted. Since they are not encrypted, cybercriminals will be able to see the codes in plain text if they intercept them. These codes are often valid from fifteen minutes to a few hours, which gives cybercriminals time to steal the codes and use them to log into your account.

SIM swapping also makes this type of MFA vulnerable. SIM swapping is an attack in which a cybercriminal impersonates you to convince a phone provider to switch your phone number to a new SIM card on their phone so they can receive your phone calls and texts – including the SMS codes sent for MFA.

Authenticator apps are unlikely to be compromised, but there are some rare instances in which they could be. The codes can be stolen if a hacker gains access to the app on your device. That means, if you have a standalone authenticator app, a hacker that steals and hacks into your physical device might be able to access your codes.

Theoretically, if a cybercriminal stole the QR code itself, and thus the secret algorithm, they could hack into your accounts. But this is uncommon in practice. This is only possible if the account servers are insecure, if you compromise the QR code by sharing it with others or if you save a screenshot of it in an insecure location.

To protect the TOTP codes in your authenticator app, you should keep your device protected with a PIN code so only you can open the device. You should also keep the QR code a secret by not sharing it or saving screenshots of it.

Steps To Set Up an Authenticator App

Here are the steps to set up an authenticator app:

  1. Choose your authenticator app. We recommend using a password manager, but you have a few different options to choose from. Choose whatever is easiest for you to use.
  2. Download the application to your device. If you’re using a standalone authenticator app we recommend downloading it onto your phone because you are most likely to have your phone whenever you need to log into an account.
  3. Request a QR code from your account. This can usually be found in the security settings of the account you want to secure under your MFA options.
  4. Scan the QR code with the authenticator app. The application you’re using will use either the device camera or a screenshot function to scan the QR code.
  5. You’re ready to go! Use the displayed TOTP code in the authenticator app to log into your account. If you choose to use a password manager for your TOTP codes, they will autofill for you upon login.

Use Authenticator Apps for MFA

Authenticator apps are highly secure and easy to set up and use. We highly recommend the use of an authenticator app for MFA. Keeper Password Manager integrates authenticator app functionality right into its application, which streamlines your cybersecurity and makes it easy to secure your accounts.

Start a free 30-day trial of Keeper Password Manager to see how we can make your digital life more secure.

What Are Authenticator Apps and How Do They Work? (2024)

FAQs

What Are Authenticator Apps and How Do They Work? ›

An authenticator app is a mobile application that provides an extra layer of security to your online accounts by generating time-based one-time passwords (TOTPs). These passwords are used for two-factor authentication (2FA) and help protect your accounts from unauthorized access.

What is the purpose of an authenticator app? ›

An authenticator app helps you to improve your online security by adding two-factor logins to any accounts you connect to the authenticator. This makes it harder for hackers to access your accounts, so we highly recommend using an authenticator app and two-factor authentication.

What are the disadvantages of the authenticator app? ›

Since the verification codes are generated within the app and not sent via text message, attackers cannot easily intercept them. However, there are some drawbacks to using authenticator apps. One of the main concerns is the risk of losing access to accounts if a user loses their device or accidentally deletes the app.

Do I really need an authenticator app? ›

Authenticator apps are not only faster and more reliable than SMS 2FA, they also enforce an additional layer of security, such as a passcode, a password or biometrics (i.e. fingerprint).

Is the authenticator app free? ›

Duo's authenticator app is available on the free version of the Duo platform. What We Like: Duo Mobile is well designed, works on both iOS and Android, and can be used as an authentication method for nearly any application or web service that uses TOTP passcodes for MFA.

Is it safe to use authenticator app? ›

You should use an authenticator app over SMS authentication because it is more secure and less likely to be intercepted by cybercriminals. Authenticator apps generate 2FA codes locally on a device, rather than sending them unencrypted over text message.

Can someone access my authenticator app? ›

Physical access and people looking over your shoulder

Someone might look over your shoulder when you're using an authenticator app and see the one-time code. And not only one code, as authenticators often display several codes in a row. So the intruder could log in to any of those accounts if they saw the code.

Why avoid Google Authenticator? ›

Backup is cumbersome.

Also, the services often offer reserve codes instead of explicitly suggesting to save the secret. If you lose your secret and log in with a reserve code, you will have to redo the entire TOTP registration process again. Backup codes are sent online, which is often insecure.

Can you trust the authenticator app? ›

Is There Anything Safer Than an Authenticator App? Using an authenticator app is one of the better types of MFA. It's always better to use some kind of MFA than none at all, and authenticator apps are free, easy to use, and widely available. However, the top option for safety is a dedicated hardware key MFA device.

Can authenticator apps track you? ›

The Microsoft authenticator does not track you and it does not log location data. It will list your logins to MCC-protected resources as a method for you to recognize unauthorized access attempts. The only push notifications it will ever send you are approval requests for logins to MCC systems.

Does authenticator cost money? ›

Microsoft Authenticator is a free app that helps you sign in to all your accounts without using a password - just use a fingerprint, face recognition, or a PIN.

What is the most secure authenticator app? ›

After testing it, Duo Mobile remains our top pick. Along with using a password manager, the most important thing you can do to secure your online accounts is to enable two-factor authentication (2FA) everywhere you can. After testing 10 2FA apps, we think Duo Mobile is the best choice for most people.

Can hackers get past Google Authenticator? ›

The method universally accepted as most secure is via external authenticator app. External authenticator apps like Microsoft Authenticator or Google Authenticator don't use codes, so no codes can be intercepted.

Do you need wifi for authenticator app? ›

Can I use an authenticator app without an internet connection? Yes, authenticator apps work offline, meaning they do not require an internet connection to generate code.

Does Apple have an authenticator app? ›

To manually set up 2FA authentication using the built-in iOS authenticator app, open the 'Settings' app on your device. Now, swipe down, find the 'Passwords' option and tap on it. Here, you will see an option that lets you create a new login or password or choose from an existing one.

What can authenticator app see? ›

The Microsoft authenticator does not track you and it does not log location data. It will list your logins to MCC-protected resources as a method for you to recognize unauthorized access attempts. The only push notifications it will ever send you are approval requests for logins to MCC systems.

What information does an authenticator app collect? ›

Authenticator collects your GPS information to determine what country you are located in. The country name and location coordinates are sent back to the system to determine if you are allowed to access the protected resource.

What if I don't want to use authenticator app? ›

Go to Azure Active Directory > Security > MFA. Under MFA settings, select Additional cloud-based MFA settings. Under service settings, select Microsoft Authenticator app. Change the setting to Disabled.

Why is Microsoft Authenticator app needed? ›

A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation. Comment Use comments to ask for clarification, additional information, or improvements to the question.

Top Articles
11 Tips to Reduce Labor Costs at Your Retail Business | ICL
Portugal D7 Visa: Your Guide to a Passive Income Residency
Dannys U Pull - Self-Service Automotive Recycling
Patreon, reimagined — a better future for creators and fans
Faridpur Govt. Girls' High School, Faridpur Test Examination—2023; English : Paper II
St Petersburg Craigslist Pets
Z-Track Injection | Definition and Patient Education
How to change your Android phone's default Google account
Videos De Mexicanas Calientes
Lesson 1 Homework 5.5 Answer Key
Umn Biology
Lesson 2 Homework 4.1
Slag bij Plataeae tussen de Grieken en de Perzen
Seafood Bucket Cajun Style Seafood Restaurant in South Salt Lake - Restaurant menu and reviews
House Party 2023 Showtimes Near Marcus North Shore Cinema
Walmart Double Point Days 2022
Vanessa West Tripod Jeffrey Dahmer
Star Wars: Héros de la Galaxie - le guide des meilleurs personnages en 2024 - Le Blog Allo Paradise
Lazarillo De Tormes Summary and Study Guide | SuperSummary
Praew Phat
Skip The Games Fairbanks Alaska
Acts 16 Nkjv
Drug Test 35765N
MyCase Pricing | Start Your 10-Day Free Trial Today
F45 Training O'fallon Il Photos
Klsports Complex Belmont Photos
Marilyn Seipt Obituary
Star Wars Armada Wikia
Myaci Benefits Albertsons
Hannah Jewell
How often should you visit your Barber?
Bi State Schedule
Warren County Skyward
The Hoplite Revolution and the Rise of the Polis
140000 Kilometers To Miles
Leland Nc Craigslist
Pill 44615 Orange
Helloid Worthington Login
The Complete Guide To The Infamous "imskirby Incident"
Studentvue Columbia Heights
State Legislatures Icivics Answer Key
Dadeclerk
Convenient Care Palmer Ma
Trap Candy Strain Leafly
Me Tv Quizzes
Mugshots Journal Star
Tattoo Shops In Ocean City Nj
Garland County Mugshots Today
FedEx Authorized ShipCenter - Edouard Pack And Ship at Cape Coral, FL - 2301 Del Prado Blvd Ste 690 33990
2000 Ford F-150 for sale - Scottsdale, AZ - craigslist
FactoryEye | Enabling data-driven smart manufacturing
Latest Posts
Article information

Author: Aron Pacocha

Last Updated:

Views: 6319

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Aron Pacocha

Birthday: 1999-08-12

Address: 3808 Moen Corner, Gorczanyport, FL 67364-2074

Phone: +393457723392

Job: Retail Consultant

Hobby: Jewelry making, Cooking, Gaming, Reading, Juggling, Cabaret, Origami

Introduction: My name is Aron Pacocha, I am a happy, tasty, innocent, proud, talented, courageous, magnificent person who loves writing and wants to share my knowledge and understanding with you.