How to Fix AADSTS53003: Conditional Access Blocking MSP Apps
Question details
Microsoft partner administrators using GDAP are blocked by Conditional Access policies when attempting to access specific applications, resulting in error code AADSTS53003.
- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Administrators attempting to access MSP apps or primary accounts via Granular Delegated Admin Privileges (GDAP).
- Observed behavior
- The system throws error AADSTS53003, blocking application access due to strict tenant-specific Conditional Access policy restrictions.
Ensure you have gathered the affected tenant ID, application name, exact user account, and recent sign-in logs before initiating the support request.
Open a Support Request via Microsoft 365 Admin Center
Since AADSTS53003 often involves complex cross-tenant access settings and GDAP configurations, contacting Microsoft Support is the recommended method to properly investigate and resolve the block.
Troubleshooting this specific error usually requires deep investigation into both the host tenant's Conditional Access policies and your organization's cross-tenant access settings. As partner administrators may not have direct visibility into the exact blocking rule, Microsoft support intervention is necessary.
Sign in to the Microsoft 365 admin center using your partner administrator credentials.
Click on the 'Support' or 'Help & support' tab on the left-hand navigation menu, then select 'New service request'.
Provide a detailed description of the problem, explicitly mentioning the error code AADSTS53003, the affected tenant, the specific application being blocked, and the user account involved.
Include the sign-in details from Entra ID logs and specify any known Conditional Access or cross-tenant access policies that might be interacting with your GDAP setup.
Submit the ticket and coordinate with the assigned Microsoft support engineer to trace the policy block.
Looking for a Hassle-Free Office Suite?
While you wait for Microsoft Support to resolve complex administration and access errors like AADSTS53003, you still need a reliable way to manage your daily documents. WPS Office provides a powerful, completely free alternative to Microsoft Office that operates smoothly without complex cloud access policies.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install the Suite: Run the setup file and follow the on-screen instructions to install the lightweight suite in seconds.
- 3. Open Your Files: Launch WPS Office and directly open your existing Microsoft Office documents with complete format retention.

Frequently Asked Questions
What does error AADSTS53003 mean in Microsoft Entra ID?
This error code indicates that an access attempt has been blocked by your organization's Conditional Access policies. These policies might restrict access based on user location, device compliance status, or specific application rules.
How can I check which Conditional Access policy is causing AADSTS53003?
You can review this in the Microsoft Entra admin center's Sign-in logs. Locate the failed sign-in event, navigate to the 'Conditional Access' tab within the event details, and look for the specific policy that shows a 'Failure' status.
Does GDAP affect cross-tenant Conditional Access?
Yes, Granular Delegated Admin Privileges (GDAP) interact directly with cross-tenant access settings. If the host tenant has stringent Conditional Access policies, it may block MSP applications from accessing the environment, requiring you to configure specific exclusions or trust settings.




