Knowledge Base / Accounts / Conditional Access and Blocked Sign-In Troubleshooting
Problem
A user is denied access to Microsoft 365, OneDrive, or company apps even though the password is correct. The sign-in is blocked by a policy, device condition, or security rule.
These issues often happen when the user is on an untrusted device, using a new location, or not meeting device compliance requirements. Check the access policy before changing user settings.
Symptoms to check
- The user receives a message that the app or location is not trusted.
- Sign-ins work on one device but fail on another.
- Access is denied only when connected remotely or from a shared network.
Possible causes
- Conditional access policy blocks the user, location, or device state.
- The device is not enrolled, compliant, or managed.
- Time, VPN, or network settings are preventing policy evaluation.
Resolution
- Review the sign-in error details and note the exact reason shown to the user, such as device compliance, risk level, or location restrictions.
- Verify whether the user is using a managed device, a compliant browser, or a trusted network. Confirm the device meets the required policy before escalating.
- Check whether the user recently changed their location, IP address, VPN, or network. A new location or VPN may trigger policy enforcement.
- Confirm the device is enrolled in Intune or another management platform and is compliant with the organization's rules before allowing access.
- If the policy is correct but the user is still blocked, collect the relevant sign-in logs and escalate to the identity or security team for a policy review.
Prevention and preparation
- Use device compliance and trust policies that match employee workflows.
- Train users to confirm they are on a managed, compliant device before reporting access issues.
- Document which locations, VPNs, and networks are expected to pass policy checks.
Related guides
Still not fixed? Record the exact failure message, timestamp, and user location, then escalate to the security or identity team with the policy and device details.
Submit a ticketLast reviewed: October 2026