How to Fix GDAP Application Blocked by Microsoft Entra Conditional Access (AADSTS53003)
Question details
The user needs to resolve an issue where an application managed through GDAP is blocked by Conditional Access policies, preventing token issuance.

- Product
- Microsoft Entra ID (Azure AD)
- Device & OS
- not provided
- Scenario
- Attempting to access or manage an application through Granular Delegated Admin Privileges (GDAP) with cross-tenant access settings enabled.
- Observed behavior
- The system throws error AADSTS53003, indicating that a Conditional Access policy has blocked the token issuance, and the exact sign-in failure event is unclear.
Before reaching out to support, note down your tenant ID, the exact AADSTS53003 error code, and the timestamp of the blocked sign-in attempt to help expedite the investigation.
Submit a Microsoft Support Ticket via Microsoft 365 Admin Center
Because community forums and external responders cannot access your tenant's private diagnostic logs, contacting Microsoft Support directly is the necessary path to investigate backend token-issuance and cross-tenant failures.
Troubleshooting advanced GDAP and Conditional Access issues requires deep visibility into backend Azure AD sign-in logs. Support engineers have the necessary access to safely review your tenant's configuration and pinpoint exactly which policy is triggering the AADSTS53003 block.
Navigate to the Microsoft 365 admin center (admin.microsoft.com) and log in using your Global Administrator or appropriate admin credentials.
On the left-hand navigation menu, click on 'Support' and then select 'Help & support' to open the service request panel.
Type 'GDAP Application Blocked AADSTS53003' into the search bar and press Enter to view related self-help articles.
Click the 'Contact support' button at the bottom of the panel. Fill in the required details, providing your tenant ID, the error code, and timestamps of the failed sign-ins.
Choose your preferred contact method (email or phone) and click 'Submit'. A Microsoft support engineer will reach out to review your sign-in logs and Conditional Access policies.

Looking for a Lightweight Alternative to Microsoft Office?
Dealing with complex Microsoft Entra admin policies and GDAP configurations can be stressful. If you are looking for a simpler, hassle-free office suite for your daily document, spreadsheet, and presentation needs, WPS Office provides a highly compatible and lightweight alternative.
- 1. Visit the Official Website: Go to the official WPS Office website to find the latest free version.
- 2. Download the Installer: Click the 'Free Download' button to download the lightweight setup file to your computer.
- 3. Install and Enjoy: Run the installer, follow the simple on-screen instructions, and start working on your documents immediately.

Frequently Asked Questions
What does error code AADSTS53003 mean?
Error AADSTS53003 signifies that access has been blocked by Microsoft Entra Conditional Access policies. This typically happens when the user, device, or application fails to meet required security conditions, such as being on a trusted network or passing Multi-Factor Authentication (MFA).
Can I fix GDAP application blocks without contacting Microsoft support?
If you are the tenant administrator, you can review your own Conditional Access policies and sign-in logs. However, for complex cross-tenant GDAP token failures, community members cannot access your diagnostic logs, so Microsoft support is usually required to identify the specific policy conflict.
Where can I check Conditional Access policies myself?
You can view and manage active policies by logging into the Microsoft Entra admin center, navigating to 'Protection', and clicking on 'Conditional Access'. From there, you can see which policies might be applying to your GDAP application.
How do I find the specific sign-in logs for this blocked event?
Sign-in logs are located in the Microsoft Entra admin center under 'Identity' > 'Monitoring & health' > 'Sign-in logs'. Filtering these logs by the specific application or user can reveal exactly which Conditional Access policy triggered the block.




