The SharePoint-hosting organization’s Microsoft Entra administrator must review the failed sign-in and either help you satisfy or appropriately adjust the security policy producing AADSTS530032.
AADSTS530032 means BlockedByConditionalAccessOnSecurityPolicy: the resource tenant has a security policy that blocks the request.^1^ Since the file belongs to another organization, this is generally not something GoDaddy or a password reset can resolve.
What to send to the organization
- Reproduce the error once.
- On the error page, select More Details.
- Copy and send the SharePoint owner or IT administrator:
- Error code:
530032
- Timestamp
- Request ID
- Correlation ID
- Your sign-in email address
- The SharePoint file or site being accessed
- Ask them to examine the corresponding sign-in event and determine which security or Conditional Access policy blocked your external account.
Do not post the IDs publicly. They are diagnostic identifiers intended for the administrator or Microsoft Support. Selecting More Details exposes the information needed to locate the event.^2^
What their Entra administrator should check
An administrator with at least the Reports Reader role should:
- Open Microsoft Entra admin center → Entra ID → Monitoring & health → Sign-in logs.
- Filter by your username, timestamp, or correlation ID.
- Open the failed SharePoint sign-in.
- Review:
- Conditional Access
- Troubleshooting and support
- Device Info
- Authentication Details
- Additional Details
- Select the failed Policy Name to see the requirement that was not met.
- If necessary, select Basic info → Troubleshoot Event to run the Sign-in diagnostic.^2^
The resulting policy detail determines the remedy. For example, the organization might require a particular authentication method, location, client, or managed/compliant device. The administrator should provide the approved way to meet that requirement or change the policy only if your access is intended and the change meets the organization’s security requirements.
External-user policy boundary
For external access, the organization hosting the SharePoint resource—the resource tenant—evaluates its Conditional Access policies and cross-tenant settings. Depending on its trust configuration, it may accept authentication or device claims from another Entra organization, require MFA in its own tenant, or block access when a required device claim cannot be evaluated.^3^
Because your email is hosted by GoDaddy, the hosting organization should also verify that:
- Your external/guest identity exists under the exact email address used for the invitation.
- The SharePoint site or file is assigned to that guest identity.
- You are opening the latest invitation link and selecting that same identity when prompted.
Those checks address guest provisioning and permissions, but they do not replace investigating 530032: the recorded error specifically identifies a tenant security-policy block.
Since global sign-out, password reset, and two-factor setup did not help, repeating those actions is unlikely to change this policy decision. If the organization’s administrator cannot identify the failed policy evaluation, they should open a Microsoft support request and include the request ID, timestamp, and sign-in event details.^2^
References
- Microsoft Entra authentication and authorization error codes
- Troubleshoot sign-in problems with Conditional Access
- Authentication and Conditional Access for External ID