Microsoft consolidates its separate two-factor authentication apps into one new app, Microsoft Authenticator, for Android and iOS
As promised, Microsoft has updated and renamed its previous account verification app for Android and iOS, Azure Authenticator, to Microsoft Authenticator.
Context & Ripple Effects
In 2016 Microsoft ran two separate verification apps on mobile; folding Azure Authenticator into a renamed Microsoft Authenticator gave the company one codebase and one brand for account verification on Android and iOS. That consolidation turned out to be the foundation for everything that followed: within a year the same app carried phone-based sign-in instead of passwords, then passwordless logins for Azure Active Directory-connected apps, until by 2021 Microsoft let users drop passwords entirely via Authenticator, Windows Hello, security keys, or codes.
First-order effects
- Azure Authenticator users on Android and iOS are migrated onto a single Microsoft Authenticator app, ending the split between Microsoft's consumer and enterprise verification clients.
Second-order effects
- A unified Microsoft app sharpens the rivalry with Google Authenticator, which responded over time with device-to-device account transfer and eventually cloud backup of 2FA codes tied to a Google Account — a feature-parity race over whose app holds users' second factors.
Third-order effects
- The authenticator app stops being a one-time-code utility and becomes each vendor's identity platform: the same client Microsoft later positioned as a vehicle for blockchain-based decentralized identity and full passwordless access, meaning control of the app increasingly means control of the login itself.
The trend: Authenticator apps are consolidating from simple code generators into vendor-controlled identity hubs that anchor the industry's shift away from passwords.