Microsoft confirmed in September 2024 that it fixed a Microsoft Authenticator design flaw that could replace an existing third-party TOTP credential when a newly scanned QR code looked like the same account. The result was a normal-looking six-digit code that later failed for the original service. The fix reduces future collisions, but it does not automatically restore a secret that was already replaced.
What Microsoft Authenticator was overwriting
The defect involved how the app identified and stored third-party time-based one-time password (TOTP) entries. It was not a weakness in the TOTP algorithm and was not primarily about Microsoft Entra push approvals.
A QR enrollment code commonly contains an otpauth:// URI with a label, issuer, username, secret, algorithm, digit count and code period. For example:
otpauth://totp/Acme:[email protected]?secret=...&issuer=Acme&algorithm=SHA1&digits=6&period=30
Two different systems can produce the same visible issuer and email address while using different secrets. Microsoft Q&A reports describe collisions when labels matched, while later reporting described reused account fields such as usernames and issuer information. The exact trigger depended on how each service formatted its QR code.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Under the old behavior, Authenticator could treat the new enrollment as an existing record and replace the older local secret instead of keeping two separate entries. The remote accounts were not deleted; the app’s stored TOTP entry was overwritten or made unavailable under the expected name.
Microsoft Q&A examples document the reported duplicate-label behavior: Microsoft Q&A report on TOTP labels and provisioning data and a second duplicate-label report.
What the failure looked like
- You scan a new TOTP QR code.
- Authenticator displays a familiar or duplicate-looking account name.
- You assume the new account was added separately.
- The earlier secret is replaced or no longer available under its expected entry.
- Later, the code appears normal but is rejected by the original service.
Because the failure can occur well after enrollment, users and help desks may initially suspect a wrong password, clock drift, an outage or the wrong account.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Who was most exposed
The issue was conditional, not universal. Risk was higher for people who:
Recommended Free Tools
- Used the same email address across several services.
- Managed multiple Microsoft Entra tenants.
- Used separate production, staging, partner or administrator portals.
- Enrolled several systems using the same organization name.
- Kept personal and work accounts in one Authenticator installation.
- Added accounts during migrations or MFA re-registration.
- Used QR codes with generic issuer and account labels.
What Microsoft changed
Microsoft told CSO Online that updated Authenticator behavior distinguishes duplicate-looking third-party TOTP accounts more safely. When a new account has the same name as an existing entry, the app can prompt you to rename the new entry rather than silently allowing a collision. The intended outcome is preservation of separate credentials; Microsoft has not publicly documented the internal database key or every matching rule.
CSO reported the confirmation on September 17, 2024, after describing complaints spanning roughly eight years. That phrase is a reporting history, not a precisely published vulnerability-disclosure timeline. The delay may have reflected the dependence on individual QR-code formats, the delayed symptom and the boundary between app storage and third-party provisioning, but Microsoft has not established a definitive cause.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Source: CSO Online’s report of Microsoft’s confirmation.
Which versions contained the reported fix?
| Platform | Version associated with the 2024 fix report | Qualification |
|---|---|---|
| iOS | 6.8.15 | CSO reported that some users had to trigger the App Store update manually. |
| Android | 6.2409.6094 | Microsoft documentation lists this version in connection with FIPS-related Android changes, not as an independent changelog for the overwrite correction. |
These are historical fixed-version markers, not claims about the latest versions in 2026. Install the current release offered by the official Apple App Store or Google Play Store. The rollout was reported around September 10–11, 2024, with possible regional variation. Microsoft’s Authenticator documentation is at Microsoft Learn.
Free tools Windows power users keep installed
One-click scans. No signup required.
Was this a security vulnerability?
It was a security-relevant design flaw, but the documented impact was mainly availability and account access. Losing a valid TOTP secret can lock you out and force recovery through support or an administrator. The cited reporting does not establish that an attacker could remotely steal the secret, redirect codes or take over an account through this behavior alone. Calling it an account-takeover vulnerability would overstate the evidence.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Will updating recover an overwritten account?
Usually, no. The update is principally preventive. Recovery depends on whether another path to the account still exists:
- The original QR code or setup key.
- Saved recovery codes.
- Another enrolled authentication method.
- An active signed-in session.
- An administrator or service-provider MFA reset.
- A backup or export that contains the original credential.
Recovery sequence
- Try a recovery code or alternate method.
- If you are already signed in, open the service’s security settings and remove and re-enroll Authenticator.
- For a work or school account, contact the identity administrator or help desk.
- Ask the service provider to reset TOTP/MFA enrollment when self-service recovery is unavailable.
- Scan the replacement QR code only after confirming that a recovery route exists.
- Save the new recovery codes securely.
Menu names and administrator controls differ by service and Entra tenant. An administrator should remove the failed registration where appropriate, complete a controlled re-registration and verify that the new method works before closing the incident.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What users should do now
- Update Authenticator from the official app store.
- Review entries with identical or highly similar names, especially those sharing an email address or organization label.
- Test important accounts while another recovery option is available.
- Do not delete an old entry until the corresponding service confirms that the replacement works.
- Generate and securely store backup codes where available.
- Keep at least one additional recovery method for critical accounts.
- Ask your organization how MFA resets and emergency access are handled.
Distinct labels such as Acme – Production, Acme – Admin, Acme – Partner tenant and Acme – Staging make entries easier to recognize. A renamed display label is only a user-interface aid; it does not prove that the service-side MFA registration is correct.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Backup, phone migration and passkeys
Cloud backup is separate from the overwrite correction. Microsoft’s transfer guidance says supported entries can be restored, but work and school accounts generally require signing in again to complete setup. Passkeys are handled separately from ordinary Authenticator backup. Do not wipe the old phone until the restored sign-in has been completed and tested.
See Microsoft’s backup and transfer guidance.
What administrators should check
- Document an MFA reset and re-registration procedure.
- Require at least two recovery methods for privileged users.
- Test help-desk and emergency-access workflows.
- Inventory users who rely exclusively on TOTP.
- Use distinct labels for production, staging and tenant-specific registrations.
- Provide a controlled migration plan if changing authenticator products.
Microsoft Entra administrators also need to account for Conditional Access, registration campaigns, permitted authentication methods and passkey policy. A consumer’s preferred TOTP app may not satisfy an organization’s policy.
Should you switch authenticator apps?
| Option | Best fit | Main trade-off |
|---|---|---|
| Microsoft Authenticator | Microsoft Entra push, passwordless sign-in, passkeys and third-party TOTP | General-purpose TOTP users must manage duplicate-label and migration risks; enterprise policy may govern its use. |
| Google Authenticator | Standalone TOTP across unrelated services | Does not replace Microsoft-specific Entra workflows. |
| Password manager with TOTP | Convenience from storing passwords and codes together | Concentrates credentials and may conflict with organizational policy. |
| Hardware security keys or passkeys | Phishing-resistant authentication | Requires compatible services, enrollment planning and spare/recovery credentials. |
| SMS or voice | Fallback where stronger methods are unavailable | Generally weaker than authenticator apps and phishing-resistant methods. |
Switching usually means re-enrolling services one by one because TOTP secrets cannot always be exported. Product information: Microsoft Authenticator, Google Authenticator, 1Password, Bitwarden, Yubico security keys and FIDO passkeys. Check current pricing and organizational policies before choosing a product.
Bottom line
Update Authenticator, inspect duplicate-looking third-party TOTP entries and verify critical accounts with a backup method available. Microsoft’s 2024 change addresses the silent-collision behavior going forward, but an entry that was already overwritten may still require recovery codes, an active session or administrator-assisted MFA re-registration.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




