Nextworks Logo
Back to Nextworks  

Authenticator Apps

Examination
   

MOVE FROM SMS TO TOTP

August 2026 | Nextworks


MFA Authenticator App

Two-factor authentication (2FA) requires two distinct forms of identification to verify identity before granting access to an account or system.

Common 2FA Methods

  1. SMS one-time code sent to a mobile number
  2. One-time code or link sent by email
  3. Time-based one-time password (TOTP) generated by an authenticator app

SMS and email methods are being phased out in favor of authenticator apps.



Why the change?

Attackers have repeatedly compromised SMS and email channels.


SMS Vulnerabilities

Phone-number transfers (SIM swaps) often rely on weak carrier authentication. Attackers can socially engineer carriers into porting a number to a device they control and then intercept 2FA codes. This low-sophistication attack has enabled account takeovers, particularly of high-value targets such as cryptocurrency and banking accounts.

In addition, the Signaling System No. 7 (SS7) protocol used to route SMS messages between carriers contains long-standing design flaws that allow interception or redirection by adversaries with network access.

Email Vulnerabilities

Email accounts are routinely compromised through phishing or other attacks. Once an attacker controls the inbox, they can trigger password-reset flows. If the same address also serves as the 2FA channel, both factors are bypassed in a single compromise.


Authenticator Apps

MFA Authenticator Download

Apps such as Google Authenticator, Microsoft Authenticator, or Authy generate short-lived TOTP codes locally on the user’s device.

Setup and verification work as follows:

  1. The service displays a QR code that encodes a shared secret. The app scans it so both sides hold the same secret.
  2. The app combines the secret with the current time (typically 30-second windows) and applies a standard algorithm to produce a six-digit code.
  3. At login the user enters the code shown in the app; the service independently generates the matching code and compares them.

Because the codes are short-lived and derived from a secret stored only on the device (and the server), they eliminate dependence on carrier or email delivery channels.



Official Guidance and Platform Changes

CISA and the FBI explicitly advise against SMS-based 2FA for sensitive accounts, citing interception risks and documented telecom-network compromises.

Microsoft will retire SMS (and voice delivery) 2FA for Microsoft 365 (Entra ID) on February 1, 2027. Organizations that still require telephony methods may continue them. However, doing so means swimming up river and requires a number of overides.



Recommended Action

Wherever a service offers an authenticator-app option, enable it — especially for email, password managers, banking, and other high-value accounts. Most account settings pages allow this change directly.



Final Thoughts

SMS remains preferable to no second factor and continues to be used where authenticator apps are unsupported.

Authenticator apps themselves are not invulnerable; they remain susceptible to phishing, device malware, and other attacks. They should therefore be treated as one additional layer within a broader defense-in-depth strategy rather than a complete solution.



Goodbye to IT headaches and hello to IT proficiency. Locally owned and operated, Nextworks has earned a 5-star rating on Google. We guarantee IT cohesion in 30 days or less, or your money back.

Lean more about Nextworks IT Managed Services.



[ Return to News & Commentary home. ]

[ Return to Nextworks IT home. ]

Visit our Blog