Error: AADSTS53003 – Access has been blocked by Conditional Access policies. The policy does not allow token issuance.
This error occurs when a Conditional Access policy in the customer tenant blocks access to the Sync 365 service principal or delegated admin account.
Cause: The customer tenant has a policy that restricts access from external users or apps — including those used by Sync 365 — and hasn’t excluded the appropriate accounts or service principals.
Resolution
To fix the issue, exclude the service provider (yourself) from ALL the Conditional Access policies in the customer tenant:
- Login to the customer’s Microsoft Entra ID portal
- Go to Conditional Access → Policies
- For each conditional access policy add an exclusion to "Users and Groups"
- Select: Guest or external users > Service provider users > Enter your partner tenant ID.
- You can potentially exclude the specific account being used with Sync 365 instead.
- Exclude: the Sync 365 delegated admin account (under “Service provider users”)
- Save the policy.
- Select: Guest or external users > Service provider users > Enter your partner tenant ID.
More guidance:
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article