How to Set Up Google Authenticator — Step by Step Guide
· By Paul Harvey
Google Authenticator is a free mobile app that generates time-based one-time passwords (TOTP) for two-factor authentication (2FA). While Mycelium 365 recommends Microsoft Authenticator for Microsoft 365 business accounts, Google Authenticator works with any service that supports TOTP — including Google Workspace, banking apps, and third-party SaaS platforms.
How to set up Google Authenticator — step by step
Download Google Authenticator from the App Store or Google Play. On iPhone open the App Store, on Android open the Google Play Store, and search "Google Authenticator". Confirm the publisher is "Google LLC" before installing to avoid look-alike apps.
Open the app and tap "Get started". On first launch, sign in with the Google account you want to use for cloud backup — this ensures your codes can be restored if you lose the device. You can skip sign-in and use the app locally, but backup will be disabled.
In the service you want to protect, go to Security → 2-Step Verification. For Google Workspace this is at myaccount.google.com/security; for other services look under Account Settings, Security, or Sign-in. You must have 2-Step Verification enabled before you can add an authenticator app.
Select "Authenticator app". Choose "Authenticator app" (sometimes labelled "TOTP" or "Software token") as your second factor. The service will display a QR code and a text setup key.
Scan the QR code or enter the setup key manually. In Google Authenticator, tap the "+" icon at the bottom right and choose "Scan a QR code". Point your camera at the code — if scanning fails, tap "Enter a setup key" and type the key by hand.
Enter the 6-digit code to verify setup. The app immediately generates a rolling 6-digit code. Type it into the verification field on the service before the 30-second timer expires to confirm the pairing.
Save backup codes in a secure location. Every service that supports TOTP offers one-time backup codes. Download or print them and store them in a password manager or a physical safe — these are your only recovery route if you lose your phone.
How to set up Google Authenticator on a new phone
The fastest way to move Google Authenticator to a new phone is the built-in transfer feature. On the old phone, tap the menu → Transfer accounts → Export accounts, select the accounts you want to move, and generate a QR code. On the new phone install Google Authenticator, tap Transfer accounts → Import accounts, and scan the code — all selected accounts appear instantly. If you are signed in with the same Google account and enabled cloud sync, your codes should already be waiting on the new device after sign-in. If you no longer have the old phone, you must fall back to the backup codes you saved during setup and re-register each account manually. Without backup codes and without cloud sync you will need each service's account recovery process, which can take days for business accounts.
Google Authenticator vs Microsoft Authenticator — which should Australian businesses use?
For any business running Microsoft 365, Microsoft Authenticator is the clear choice: it supports one-tap push notifications, number matching, passwordless sign-in, and deep integration with Entra ID Conditional Access — none of which Google Authenticator can do. Google Authenticator only generates 6-digit TOTP codes, so every sign-in requires typing them in manually. Where Google Authenticator wins is universality: it works with any TOTP service, so it is a solid choice for Google Workspace tenants, standalone SaaS accounts (GitHub, AWS, Xero, MYOB), and personal banking apps. Many Australian businesses run mixed environments and use both — Microsoft Authenticator for their Microsoft 365 estate and Google Authenticator (or the TOTP feature inside Microsoft Authenticator) for everything else. If you are Microsoft-first, standardise on Microsoft Authenticator and use its "Other account" option to hold any TOTP codes you would otherwise put in Google Authenticator.
Is Google Authenticator safe for business use?
Yes — Google Authenticator's TOTP codes are dramatically safer than SMS-based 2FA because they cannot be intercepted through SIM-swap attacks, number porting fraud, or SS7 exploits on the mobile network. The codes are generated on the device itself using a shared secret and the current time, so there is nothing to intercept in transit. That said, Google Authenticator has real limitations for business use. Until 2023 it had no cloud backup at all, and even now the sync feature depends on a personal Google account rather than a managed business identity. It has no push notifications, no number matching, no phishing-resistant sign-in, and no way for administrators to enforce or monitor its use centrally. For high-security environments — finance, legal, healthcare, ML2+ Essential Eight targets — Mycelium 365 recommends Microsoft Authenticator with Conditional Access, or FIDO2 hardware security keys for privileged accounts.
If you are unsure which authenticator app fits your business, or you want MFA rolled out consistently across your Microsoft 365 tenant, get in touch with Mycelium 365 — we scope technology roadmaps and MFA deployments for Australian businesses of 20–300 users.
When Google Authenticator is the right choice for Australian businesses
Not every Australian business runs on Microsoft 365, and Google Authenticator remains a sensible default in a few specific scenarios. Google Workspace tenants get the tightest integration, because 2-Step Verification, Advanced Protection, and the Authenticator app are all built and maintained by the same vendor. Sole traders and micro-businesses (under 20 users) who need free, no-configuration 2FA on a handful of SaaS tools often find the app easier to roll out than a full Entra ID plan. Contractors and consultants who move between multiple client tenants can use Google Authenticator to hold TOTP codes for services where they do not have a work identity, keeping personal and client accounts separate. In each of these cases, the same rules apply: always enable cloud sync, always save backup codes, and always keep a second recovery method (a hardware key or trusted device) so a single lost phone cannot lock you out of the business.
Frequently asked questions
Can I use Google Authenticator for Microsoft 365?
Yes — Microsoft 365 supports any TOTP-based authenticator, so Google Authenticator will work. However, Microsoft Authenticator is strongly recommended for Microsoft 365 because it adds push notifications, number matching, passwordless sign-in, and Entra ID Conditional Access integration that Google Authenticator cannot provide.
What happens if I lose my phone with Google Authenticator?
If you enabled cloud sync, sign into Google Authenticator on a new phone with the same Google account and your codes will restore automatically. If you did not, use the backup codes you saved during setup, or go through each services account recovery process — which can take days for business accounts.
Does Google Authenticator work without internet?
Yes. TOTP codes are generated locally using the device clock and a shared secret stored on the phone, so they work offline, in flight mode, and with no mobile data. You only need internet to enable cloud sync or transfer accounts between devices.