Forum Discussion
Having issues logging into the development subscription with the initial admin user.
When trying to login to the admin portal, teams, myapps, etc with the intial admin user getting an error message after initial authentication via password.
- Tenant: r99jlnpy.onmicrosoft.com
- Admin account: mailto:email address removed for privacy reasons
- Error: AADSTS53003
- Correlation ID: 557f733a-1e70-414a-847d-6a36396e05a5Request ID: 3c8a96f3-4442-4233-a8de-657191663c00
The administrator account authenticates successfully but is blocked by Conditional Access (AADSTS53003) from accessing MyApps, Admin Center, Entra ID, and MFA registration pages, resulting in a complete administrative lockout of the sandbox tenant
1 Reply
- CameronTaylor1998Brass Contributor
AADSTS53003 means Conditional Access blocked the sign-in. Resetting the password will not resolve the policy requirement, and the error alone does not identify which policy is responsible.
- If another authorized admin or an emergency-access account can sign in, have them open Entra admin center > Entra ID > Monitoring & health > Sign-in logs. Find the failed attempt using your correlation ID and its timestamp, then inspect the Conditional Access tab.
- Check the failed policy’s requirements. If it requires a compliant device or an approved location, try the appropriate managed device or network. If the policy unintentionally blocks all administrative access, an admin with Conditional Access permissions needs to correct the specific policy or apply a narrowly scoped recovery exclusion.
- If no admin account can access the tenant, this requires Microsoft support. Use the support route available through your Microsoft 365 Developer Program dashboard or, if your sandbox benefit comes through Visual Studio, the Visual Studio subscription support portal. State clearly: “Developer sandbox tenant-wide administrator lockout caused by Conditional Access; no administrator can access Entra to remediate the policy.”
Provide the tenant name, both IDs, the UTC timestamp of a recent failed sign-in, and whether any other administrator account exists. Microsoft will need to verify ownership before assisting with tenant access.
Keep the existing sandbox while pursuing recovery. Deleting and recreating it is not an account-unlock procedure and could cost you the tenant’s data and configuration.