Checklist
AADSTS53000 vs AADSTS53003: troubleshooting Conditional Access sign-in blocks
Based on the article: AADSTS53000 vs AADSTS53003: troubleshooting Conditional Access sign-in blocks · 4 min read
AADSTS53000 and AADSTS53003 both leave a user looking at an access-denied page after a perfectly good sign-in, but they point at different problems. One says the device didn't meet a requirement; the other says a policy refused to issue a token at all. In this post I'll show how to tell them apart, find the exact policy in the sign-in logs, and fix the usual causes.
Symptoms to confirm
The user's password and MFA are accepted, and then access stops.
| Code | Name | What it means |
|---|---|---|
AADSTS53000 | DeviceNotCompliant | A policy requires a compliant device, and Microsoft Entra ID doesn't see this device as compliant. |
AADSTS53001 | DeviceNotDomainJoined | A policy requires a Microsoft Entra hybrid joined (domain-joined) device, and this device isn't recognized as one. |
AADSTS53003 | BlockedByConditionalAccess | A policy evaluated the sign-in and doesn't allow a token to be issued. A Block access grant is the classic cause. |
Likely causes
Conditional Access is evaluated after first-factor authentication.
- The device really isn't compliant. It isn't enrolled, it fails a setting, or it was just enrolled and its compliance hasn't been registered yet. Compliance also isn't evaluated properly if the user has no Intune license.
- The browser didn't send the device identity. Without it, even a compliant laptop looks like an unknown device. Private windows (InPrivate, Incognito) don't send it either.
- The device object isn't in the expected state. For 53001 this is usually a hybrid join that never completed.
- For 53003, a block policy matched on location, device platform, client app or risk. The platform condition is derived from information the client provides, such as the user agent, so an unexpected client can fall into a "block unsupported platforms" policy.
Checklist
- 1
Find the blocked sign-in
In the Microsoft Entra admin center (Reports Reader is enough), go to Entra ID › Monitoring & health › Sign-in logs. Filter by the correlation ID, or by username, date and status Failure.
- 2
Read the Conditional Access tab
Every evaluated policy is listed with its result; the one showing Failure is your blocker. Select the ellipsis next to it: the left side shows what was collected at sign-in, the right side whether it satisfied the policy.
- 3
Read the Device info tab
- No device ID: the client didn't present device identity. Fix the browser (step 4) or the app.
- Device ID present, Compliant is No: fix compliance in Intune (step 5).
- Join type missing or unexpected (53001): troubleshoot device registration with
dsregcmd /status.
- 4
Fix browser device identity
Browser on Windows What it needs Microsoft Edge Native support. The user must be signed in to the Edge profile with the work account that's connected to Windows. Google Chrome The Microsoft Single Sign On extension, or Chrome's CloudAPAuthEnabledpolicy.Mozilla Firefox 91+ "Allow Windows single sign-on for Microsoft, work, and school accounts" enabled (the WindowsSSOpolicy).On macOS, browser device identity depends on the Microsoft Enterprise SSO plug-in being deployed through MDM.
- 5
Fix compliance
In the Microsoft Intune admin center, open Devices › All devices, select the device and check Device compliance to see which policy and setting is failing. Confirm the user has an Intune license, fix the setting, then sync the device from its page in the admin center, or on Windows from Settings › Accounts › Access work or school › account › Info › Sync.
- 6
For 53003, review the policy conditions
Identify which location, platform, client app or risk condition matched. Then decide whether the block is correct, or whether the policy needs a narrower condition or a documented exclusion.
Verify
- Have the user retry in a normal browser window or the app. In the new sign-in event, the blocking policy should show Success, and Device info should show the device ID with Compliant and Managed set to Yes.
- Run the What If tool from Entra ID › Conditional Access › Policies › What If for the same user, app, device platform and client app. It lists the policies that apply and the grant controls they require. It doesn't check whether a real device is compliant, so pair it with the sign-in log.
Prevent it next time
- Never scope a compliant-device or Block policy to all users and all resources without exclusions. Microsoft warns this can lock out admins who don't have an enrolled device. Always exclude your emergency-access accounts.
- Deploy browser settings with Intune: the Chrome extension or policy, Firefox's
WindowsSSOpolicy, and Edge sign-in. - Make sure every platform you allow has a compliance policy assigned, and know how the tenant-wide Mark devices with no compliance policy assigned as setting is configured.
- Roll out new device-based policies in report-only mode and review the Failure results before enforcing.