AADSTS53003
Blocked by Conditional Access
Answer: A Microsoft Entra Conditional Access policy prevented token issuance.
Resolution playbook
Fix it, then prove it
Use the error record as the starting point; use tenant evidence to confirm the actual cause.
Likely causes
- The sign-in log is authoritative for which policy applied; do not disable policies based only on this code.
- Conditional Access, MFA, identity risk, session, tenant routing, or account state changed the authentication decision.
- The sign-in used a different application, resource, device, location, or authentication flow than the working comparison.
Recommended fix
- Open the failed sign-in event and review the Conditional Access tab.
- Identify the exact policy and grant or session control that failed.
- Validate user, device, location, application, and authentication-strength conditions.
Verify
- Repeat the sign-in using the intended tenant and supported interactive or non-interactive flow.
- In Entra sign-in logs, confirm the new event succeeds and review Authentication Details and Conditional Access tabs.
- If a policy was changed, confirm the expected policy result using report-only or What If before broad rollout.
Escalate when
- The failure persists after the documented prerequisites and a new authentication/session attempt.
- Multiple users, apps, devices, or networks show the same error, suggesting tenant policy or service scope.
- You can provide the exact UTC time, tenant, application/resource, correlation or request ID, and sanitized logs.
Capture the support evidence
Error code: AADSTS53003
UTC timestamp: <yyyy-mm-dd hh:mm:ssZ>
Correlation ID: <guid>
Tenant ID: <guid>
Application / resource: <name>Template only. Fill it from the failed sign-in and keep user identifiers out of public tickets.
Admin context
The sign-in log is authoritative for which policy applied; do not disable policies based only on this code.
Evidence to preserve
- UTC timestamp and correlation/request ID
- Tenant, application, resource, and authentication flow
- Sanitized service log details and exact operation
Advertisement
