AADSTS53000: device isn't compliant
Likely causes
- The device isn't enrolled in Intune or another approved MDM.
- The device fails a compliance setting, such as encryption, OS version or passcode.
- Compliance status hasn't updated yet after a fix.
- The user is signing in from a personal device or unsupported browser.
How to fix it
- Open the Company Portal app on the device and check its status. It lists what’s out of compliance and how to fix it.
- Fix the listed items (install updates, turn on encryption, set a passcode), then select Check status or Check access in Company Portal to re-evaluate.
- If the device isn’t enrolled, enroll it through Company Portal or your normal setup process.
- In a browser, use one that supports device sign-in, such as Microsoft Edge signed in with the work account.
- Admins: check the device’s compliance details in Intune and the sign-in logs to confirm which policy applied.
Checked against: learn.microsoft.com, learn.microsoft.com