AADSTS53003: Access has been blocked by Conditional Access policies
Sign-in succeeded, but a Conditional Access policy blocked access — device, location, app or risk conditions weren’t met.
Seen on:
Azure
Meaning
The sign-in log’s Conditional Access tab shows which policy applied. Common: non-compliant/unregistered device, blocked country/IP, legacy authentication, or an app not allowed.
Common causes
- Device not compliant or not hybrid/Entra joined
- Location/IP blocked
- Legacy authentication blocked
- Client app not approved
⚡ Quick fix
- Check Entra sign-in logs → Conditional Access tab
- Meet the requirement (enrol device, use approved client, allowed network)
- Ask an admin to adjust the policy if appropriate
Detailed fix by platform
Azure CLI
# Portal: Entra ID → Sign-in logs → select the failure → Conditional Access tab
How to diagnose
- Policy — Which policy blocked?
- Device — Compliance state
- Location — IP/country
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
- App Service Application Error Azure App Service: ":( Application Error" / container didn’t respond to HTTP pings
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026