AADSTS53003 🔷 Azure

AADSTS53003: Access has been blocked by Conditional Access policies

Sign-in succeeded, but a Conditional Access policy blocked access — device, location, app or risk conditions weren’t met.

Seen on: Azure

Meaning

The sign-in log’s Conditional Access tab shows which policy applied. Common: non-compliant/unregistered device, blocked country/IP, legacy authentication, or an app not allowed.

Common causes

  • Device not compliant or not hybrid/Entra joined
  • Location/IP blocked
  • Legacy authentication blocked
  • Client app not approved

⚡ Quick fix

  1. Check Entra sign-in logs → Conditional Access tab
  2. Meet the requirement (enrol device, use approved client, allowed network)
  3. Ask an admin to adjust the policy if appropriate

Detailed fix by platform

Azure CLI

  1. # Portal: Entra ID → Sign-in logs → select the failure → Conditional Access tab

How to diagnose

  1. Policy — Which policy blocked?
  2. Device — Compliance state
  3. Location — IP/country

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.