AADSTS53003: access blocked by Conditional Access
Likely causes
- A policy blocks the user's location or country.
- A policy blocks the app, platform or client type (for example legacy authentication).
- A policy blocks sign-ins with high user or sign-in risk.
- A new policy was switched on without being tested in report-only mode.
How to fix it
- On the error page, select More details and copy the Request ID, Correlation ID and time.
- Admins: in the Entra admin center, open Monitoring & health > Sign-in logs, find the failure and open the Conditional Access tab to see which policy blocked it and why.
- Fix the condition, not the policy, where you can: sign in from an allowed network, use a supported app, or clear the user risk.
- If the policy itself is wrong, test changes with the What If tool before you change it.
Checked against: learn.microsoft.com, learn.microsoft.com