logo
search
Conditional Access Problems

How to Fix GDAP Application Blocked by Microsoft Entra Conditional Access (AADSTS53003)

Bushra ParveenBushra Parveen Sep 28, 2026 869 views

Question details

The user needs to resolve an issue where an application managed through GDAP is blocked by Conditional Access policies, preventing token issuance.

Fixing GDAP Application Blocked by Microsoft Entra Conditional Access (Error AADSTS53003)
Product
Microsoft Entra ID (Azure AD)
Device & OS
not provided
Scenario
Attempting to access or manage an application through Granular Delegated Admin Privileges (GDAP) with cross-tenant access settings enabled.
Observed behavior
The system throws error AADSTS53003, indicating that a Conditional Access policy has blocked the token issuance, and the exact sign-in failure event is unclear.
Before you start

Before reaching out to support, note down your tenant ID, the exact AADSTS53003 error code, and the timestamp of the blocked sign-in attempt to help expedite the investigation.

Solution 1Recommended

Submit a Microsoft Support Ticket via Microsoft 365 Admin Center

Because community forums and external responders cannot access your tenant's private diagnostic logs, contacting Microsoft Support directly is the necessary path to investigate backend token-issuance and cross-tenant failures.

Troubleshooting advanced GDAP and Conditional Access issues requires deep visibility into backend Azure AD sign-in logs. Support engineers have the necessary access to safely review your tenant's configuration and pinpoint exactly which policy is triggering the AADSTS53003 block.

1
Log in to the Admin Center

Navigate to the Microsoft 365 admin center (admin.microsoft.com) and log in using your Global Administrator or appropriate admin credentials.

2
Access the Help & Support Panel

On the left-hand navigation menu, click on 'Support' and then select 'Help & support' to open the service request panel.

3
Describe the Issue

Type 'GDAP Application Blocked AADSTS53003' into the search bar and press Enter to view related self-help articles.

4
Create a New Service Request

Click the 'Contact support' button at the bottom of the panel. Fill in the required details, providing your tenant ID, the error code, and timestamps of the failed sign-ins.

5
Submit the Ticket

Choose your preferred contact method (email or phone) and click 'Submit'. A Microsoft support engineer will reach out to review your sign-in logs and Conditional Access policies.

Submit a Microsoft Support Ticket via Microsoft 365 Admin Center
Diagnostics Access Requirement: Only authorized Microsoft support engineers can securely access backend sign-in logs and cross-tenant settings required to diagnose complex AADSTS53003 token-issuance failures.
Free Microsoft Office alternative

Looking for a Lightweight Alternative to Microsoft Office?

Dealing with complex Microsoft Entra admin policies and GDAP configurations can be stressful. If you are looking for a simpler, hassle-free office suite for your daily document, spreadsheet, and presentation needs, WPS Office provides a highly compatible and lightweight alternative.

  1. 1. Visit the Official Website: Go to the official WPS Office website to find the latest free version.
  2. 2. Download the Installer: Click the 'Free Download' button to download the lightweight setup file to your computer.
  3. 3. Install and Enjoy: Run the installer, follow the simple on-screen instructions, and start working on your documents immediately.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight desktop installation that does not rely on complex cloud administrative policies.Free to use with a familiar, easy-to-navigate user interface.Seamless cross-platform usage for Windows, Mac, Linux, iOS, and Android.
microsoft office alternative - wps office

Frequently Asked Questions

What does error code AADSTS53003 mean?

Error AADSTS53003 signifies that access has been blocked by Microsoft Entra Conditional Access policies. This typically happens when the user, device, or application fails to meet required security conditions, such as being on a trusted network or passing Multi-Factor Authentication (MFA).

Can I fix GDAP application blocks without contacting Microsoft support?

If you are the tenant administrator, you can review your own Conditional Access policies and sign-in logs. However, for complex cross-tenant GDAP token failures, community members cannot access your diagnostic logs, so Microsoft support is usually required to identify the specific policy conflict.

Where can I check Conditional Access policies myself?

You can view and manage active policies by logging into the Microsoft Entra admin center, navigating to 'Protection', and clicking on 'Conditional Access'. From there, you can see which policies might be applying to your GDAP application.

How do I find the specific sign-in logs for this blocked event?

Sign-in logs are located in the Microsoft Entra admin center under 'Identity' > 'Monitoring & health' > 'Sign-in logs'. Filtering these logs by the specific application or user can reveal exactly which Conditional Access policy triggered the block.