Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

Shivaji 0 Reputation points
2026-07-28T08:15:00.5733333+00:00

Hi,

Some users are from the Philippines and are unable to log in to Outlook and Teams from a web browser and are showing the below error.

Sign-in error code

53003

Failure reason

Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

Additional Details

If this is unexpected, see the conditional access policy that applied to this request in the Azure Portal.

Please give suggestions on the above issue.

Thanks and Regards,

Shivaji

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

2 answers

Sort by: Most helpful
  1. Shivaji 0 Reputation points
    2026-07-28T14:47:05.8533333+00:00

    Hi Julie,

    Please find my response below.

    1.Are all affected users located in the Philippines, or are users in other countries experiencing the same issue as well?---Yes.

    2.When did the issue first begin? Was it after any recent changes to Conditional Access policies, location restrictions, Intune compliance policies, or security settings?---Recently we have added Hong Kong exclusion

    3.Are the affected users able to sign in successfully using:

    Outlook Desktop App?

    Microsoft Teams Desktop App?

    Mobile applications?

    A different browser or network connection?----Issue with browser signin

    4.Is the issue limited to Outlook and Teams, or are other Microsoft 365 services also affected?---Teams and Outlook

    5.In the Microsoft Entra Admin Center, could you navigate to Identity > Monitoring & Health > Sign-in Logs, locate a failed sign-in attempt, then check the Conditional Access tab results and the name of any policy showing as Failure?----Yes.

    6.Under the failed sign-in event, what specific condition or grant control is listed as causing the block (for example: location restriction, device compliance requirement, sign-in risk, or approved client app requirement)?---Grant control block

    7.Are the users signing in from:

    Corporate-managed devices?

    Intune-compliant devices?

    Personal/unmanaged devices?----Intune devices

    8.If a location-based Conditional Access policy is in place, can you confirm whether access from the Philippines is allowed and whether these users are connecting from expected public IP ranges?---Not tested

    Was this answer helpful?


  2. Julie Huynh 2,360 Reputation points Independent Advisor
    2026-07-28T14:25:00.8733333+00:00

    Dear @Shivaji,

    Good day! Welcome to Microsoft Q&A forum!

    Based on your description, I understand that some users located in the Philippines are unable to sign in to Outlook and Microsoft Teams through a web browser. When attempting to authenticate, they receive sign-in error code 53003 with the message "Access has been blocked by Conditional Access policies. The access policy does not allow token issuance." You are looking for guidance on identifying the Conditional Access policy causing the issue and restoring access for the affected users.

    Error 53003 typically indicates that a Microsoft Entra Conditional Access policy is preventing the sign-in request from completing.

    To better understand what may be causing the block, could you please help us with the following information:

    • Are all affected users located in the Philippines, or are users in other countries experiencing the same issue as well?
    • When did the issue first begin? Was it after any recent changes to Conditional Access policies, location restrictions, Intune compliance policies, or security settings?
    • Are the affected users able to sign in successfully using:
      • Outlook Desktop App?
      • Microsoft Teams Desktop App?
      • Mobile applications?
      • A different browser or network connection?
    • Is the issue limited to Outlook and Teams, or are other Microsoft 365 services also affected?
    • In the Microsoft Entra Admin Center, could you navigate to Identity > Monitoring & Health > Sign-in Logs, locate a failed sign-in attempt, then check the Conditional Access tab results and the name of any policy showing as Failure?
    • Under the failed sign-in event, what specific condition or grant control is listed as causing the block (for example: location restriction, device compliance requirement, sign-in risk, or approved client app requirement)?
    • Are the users signing in from:
      • Corporate-managed devices?
      • Intune-compliant devices?
      • Personal/unmanaged devices?
    • If a location-based Conditional Access policy is in place, can you confirm whether access from the Philippines is allowed and whether these users are connecting from expected public IP ranges?

    Your confirmation would be very helpful in ensuring you receive the most suitable support!

    If you’re able to share a bit more about your situation, I might be able to suggest some helpful next steps. 

    Kindly let me know when there are updates or if you need further assistance. Any updates you’re able to share would be really helpful. I appreciate your time and look forward to hearing how things are going! 

    Thank you for your time and patience.


    If you have extra questions about this answer, please click "Comment". 

    Note: Please follow the steps in [our documentation] to enable e-mail notifications if you want to receive the related email notification for this thread. 

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.