The policy is on the other tenants side ( the resource tenant) . I would talk to their IT dept.
Sign-ins blocked my nonexisting conditional access policies. 53003
Many of our employees have guest accounts to a team outside our organization. But they are unable to sign in due to a nonexisting conditional access policy. When they try to sign into the guest account they are met with an error message that says "you cannot access this right now" and the error code 53003. The failure reason listed in the Entra ID sign in logs says "Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.“. I have tried disabling all of our condition access policies but they still can not sign in.
According to this article, you can view the Conditional Access tab to get more details about why the Conditional Access conditions were not met and which policies applied. In my case, there are no conditions that were not met.
According to the employees, they are unable to log in using the teams app or microsoft Edge but it works fine using google chrome. This has been an issue since June and i have no been able to figure it out. When logging in using google chrome, the employees got a code in an automated email from the other organization that they could then use to get in. When opening files from the teams channel (using sharepoint), they are met with the same error, even on Chrome.
From the teams app it looks like this:
I am the only one who can log in using the teams app and open files without a problem.
Is this a problem with the policies in our system or does this have something to do with the policies of the other organization? What can be done to fix the issue?
Microsoft Security | Microsoft Entra | Microsoft Entra ID
-
Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
2025-04-07T17:34:25.7+00:00