logo
search
Conditional Access Problems

How to Fix AADSTS53003: Conditional Access Blocking MSP Apps

Maira MehtabMaira Mehtab Sep 22, 2026 869 views

Question details

Microsoft partner administrators using GDAP are blocked by Conditional Access policies when attempting to access specific applications, resulting in error code AADSTS53003.

Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Administrators attempting to access MSP apps or primary accounts via Granular Delegated Admin Privileges (GDAP).
Observed behavior
The system throws error AADSTS53003, blocking application access due to strict tenant-specific Conditional Access policy restrictions.
Before you start

Ensure you have gathered the affected tenant ID, application name, exact user account, and recent sign-in logs before initiating the support request.

Solution 1Recommended

Open a Support Request via Microsoft 365 Admin Center

Since AADSTS53003 often involves complex cross-tenant access settings and GDAP configurations, contacting Microsoft Support is the recommended method to properly investigate and resolve the block.

Troubleshooting this specific error usually requires deep investigation into both the host tenant's Conditional Access policies and your organization's cross-tenant access settings. As partner administrators may not have direct visibility into the exact blocking rule, Microsoft support intervention is necessary.

1
Log in to the Admin Center

Sign in to the Microsoft 365 admin center using your partner administrator credentials.

2
Navigate to Support

Click on the 'Support' or 'Help & support' tab on the left-hand navigation menu, then select 'New service request'.

3
Detail the issue

Provide a detailed description of the problem, explicitly mentioning the error code AADSTS53003, the affected tenant, the specific application being blocked, and the user account involved.

4
Attach relevant policies and logs

Include the sign-in details from Entra ID logs and specify any known Conditional Access or cross-tenant access policies that might be interacting with your GDAP setup.

5
Submit the request

Submit the ticket and coordinate with the assigned Microsoft support engineer to trace the policy block.

Free Microsoft Office alternative

Looking for a Hassle-Free Office Suite?

While you wait for Microsoft Support to resolve complex administration and access errors like AADSTS53003, you still need a reliable way to manage your daily documents. WPS Office provides a powerful, completely free alternative to Microsoft Office that operates smoothly without complex cloud access policies.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Install the Suite: Run the setup file and follow the on-screen instructions to install the lightweight suite in seconds.
  3. 3. Open Your Files: Launch WPS Office and directly open your existing Microsoft Office documents with complete format retention.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight local software that runs without relying on complicated tenant access policies.Built-in robust PDF editing tools for comprehensive document management.Familiar user interface requiring zero learning curve for a seamless transition.
microsoft office alternative - wps office

Frequently Asked Questions

What does error AADSTS53003 mean in Microsoft Entra ID?

This error code indicates that an access attempt has been blocked by your organization's Conditional Access policies. These policies might restrict access based on user location, device compliance status, or specific application rules.

How can I check which Conditional Access policy is causing AADSTS53003?

You can review this in the Microsoft Entra admin center's Sign-in logs. Locate the failed sign-in event, navigate to the 'Conditional Access' tab within the event details, and look for the specific policy that shows a 'Failure' status.

Does GDAP affect cross-tenant Conditional Access?

Yes, Granular Delegated Admin Privileges (GDAP) interact directly with cross-tenant access settings. If the host tenant has stringent Conditional Access policies, it may block MSP applications from accessing the environment, requiring you to configure specific exclusions or trust settings.