Share via

53003 error

Sebastian Sarieh 0 Reputation points
2026-04-20T12:35:28.8333333+00:00

URGENT. I CANNOT ACCESS IT ADMIN OR ANY USERS ON OFFICE 365 IMSTANCE DUR TO CONDITIONAL ACCESS LOCKOUT. NEED ASSISTANCE WITH THE STEPS TO RECOVER THE WORKSPACE AND GET ACCESS TO THE ACCOUNTS.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-20T12:35:46.1766667+00:00

    Follow these steps to recover access when Conditional Access has locked out all admins and users:

    1. Check for any unblocked admin accounts
      • If there is any other administrator account that can still sign in (for example, a break-glass/emergency account or another global admin), use that account to:
        • Go to the Microsoft Entra admin center.
        • Locate the Conditional Access policy (or policies) causing the block.
        • Disable or modify the policy so that:
          • Admin accounts are excluded, and
          • At least one emergency access account is excluded going forward.
    2. If no admin can sign in at all
      • When all admins are locked out, recovery must be done by Microsoft support:
        1. Submit a support request as the tenant admin:
          • Use the guidance in How to get support to open a support ticket.
          • Clearly state that all administrators are locked out due to Conditional Access and that you need Conditional Access policies updated to restore access.
        2. If you cannot open a ticket from the tenant because no one can sign in:
          • Call Microsoft’s global customer service phone number for business/enterprise support (see “Customer service phone numbers - Microsoft Support” in the context articles).
          • When navigating the IVR, indicate:
            • Product: Office 365 / Microsoft 365 for business.
            • Issue: Authenticator / Conditional Access lockout / admin locked out.
            • Account type: Company/organization.
            • Confirm that you are the tenant administrator and that there are no other admins.
          • Ask specifically to create a service request with the Microsoft Data Protection team to reset or adjust Conditional Access so that an admin can sign in again.
    3. Optional workaround if you cannot reach support directly
      • If support channels require a signed-in admin to open a ticket, create a temporary trial Microsoft 365 tenant (separate from the locked tenant) and:
        • Sign in to the new tenant’s Microsoft 365 Admin Center.
        • Use Help & support to open a ticket.
        • In the ticket, clearly state that:
          • You are locked out of a different, existing tenant.
          • You are the only admin on that tenant.
          • Conditional Access has blocked all admin access.
          • You need the Data Protection team to help restore access or adjust Conditional Access on the original tenant.
        • After the issue is resolved, cancel the trial subscription to avoid charges.
    4. Prevent future lockouts once access is restored
      • After regaining access, immediately:
        • Create and configure at least one emergency access (break-glass) account and exclude it from all Conditional Access policies.
        • Review all Conditional Access policies and ensure:
          • At least one admin account or group is excluded from restrictive policies.
          • Service accounts and service principals are handled appropriately.

    These steps align with Microsoft’s documented guidance: if another admin exists, that admin disables or fixes the policy; if no admin can sign in, Microsoft support (Data Protection team) must intervene to update the Conditional Access policies that prevent access.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.