Share via

Error 53003

TTI Naomi 0 Reputation points
2026-03-21T06:01:33.4133333+00:00

Hi team

We are completely locked out of our Microsoft 365 tenant due to a misconfigured Conditional Access policy in Microsoft Entra ID.

All Global Administrator accounts are blocked with Error 53003, and there is currently no way to access the tenant.

This is a business-critical outage affecting all administrative operations.

We require immediate assistance to reset or disable the Conditional Access policies so we can regain access.

Affected accounts: All Global Admins

Error code: 53003

Impact: Full administrative lockout

Request: Please escalate this case to the Data Protection / Tenant Recovery Team urgently and assist in restoring admin access.

We are available to perform domain/DNS verification immediately if required.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-21T06:01:49.6233333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Error 53003 (BlockedByConditionalAccess) indicates that Conditional Access policies are blocking sign-in. When all Global Administrators are locked out due to misconfigured Conditional Access, recovery must be handled by an administrator who still has access or by Microsoft Support (Data Protection / Tenant Recovery).

    Since all Global Admins are blocked, follow this path:

    1. Confirm no other admin can still sign in
      • Verify whether there are any other administrator accounts (including break-glass/emergency access accounts) that are not affected by the Conditional Access policy.
      • If such an account exists, sign in with that account and disable or modify the misconfigured Conditional Access policy in Microsoft Entra ID.
    2. If no admin can access the tenant
      • This is a tenant lockout scenario. Conditional Access documentation explicitly states that if no admin can update the policy, a support request must be opened so Microsoft can adjust the policies that prevent access.
      • Because sign-in to the locked tenant is not possible, use one of these approaches (as shown in similar MFA lockout cases):
        • Contact Microsoft Support by phone and request a service ticket for a tenant lockout / Conditional Access lockout so the case can be routed to the Data Protection / Tenant Recovery team.
        • If the tenant is managed through a partner/reseller, ask the partner to open a support request on behalf of the tenant.
        • Alternatively, create a separate temporary Microsoft 365 tenant (for example, via a trial subscription) and from that tenant’s admin center open a support ticket clearly stating that the issue concerns a different, existing tenant where all Global Admins are locked out by Conditional Access.
    3. Information to provide to Support
      • State that all Global Administrators are blocked by Conditional Access (error 53003 / BlockedByConditionalAccess).
      • Provide the locked tenant’s primary domain name and an affected admin UPN.
      • Indicate that this is a full administrative lockout and that domain/DNS verification can be performed immediately.
      • Once the case is escalated, the Data Protection / Tenant Recovery team will verify ownership and then update or disable the Conditional Access policies that are preventing access.
    4. Preventing future lockouts
      • After access is restored, configure at least two Global Administrator accounts and dedicated emergency access (break-glass) accounts that are excluded from Conditional Access policies. These accounts are specifically recommended so that misconfigured policies do not cause tenant-wide admin lockouts.
      • When designing Conditional Access policies, avoid blanket policies that apply to all admins without exclusions, and always test policies before enforcing them.

    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.