A cloud-based identity and access management service for securing user authentication and resource access
When I try to open the APIM developer portal administration site, I get error 53003 - Your sign-in was successful but you don't have permission to access this resource.
In API Management portal, clicking on the Developer Portal link to access the portal administration site, asks me to sign-in. When I sign in with the administrator account I get an error advising:
You don't have access to this
Your sign-in was successful but you don't have permission to access this resource.
Clicking More Details, shows this:
Error Code: 53003
Request Id: Removed PII
Correlation Id: Removed PII
Timestamp: 2025-12-30T11:45:42.277Z
App name: API Management Developer Portal PROD
App id:Removed PII
IP address: Removed PII
Device identifier: Removed PII
Device platform: Windows 10
Device state: Managed
Flag sign-in errors for review: Enable flagging
If you plan on getting help for this problem, enable flagging and try to reproduce the error within 20 minutes. Flagged events make diagnostics available and are raised to admin attention.
I understand error 53003 is related to Conditional Access, so I have checked my Sign-in logs and can see the failed sign-ins. The secific error in the sign-in log is:
Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.
But, there is nothing listed under Conditional Access.
All of my CA policies are set to report only, so they should not be blocking anything. There is no useful information in the CA Policy report either. In fact, CA report is showing zero failures!
Microsoft Security | Microsoft Entra | Microsoft Entra ID
-
VEMULA SRISAI • 13,900 Reputation points • Microsoft External Staff • Moderator
2025-12-30T12:40:05.9966667+00:00 Hello Mark Morrall ,
Thank you for sharing the details. The error 53003 indicates that access is being blocked by a Conditional Access policy, even though your policies appear to be in report-only mode. This usually happens when a policy targeting “All users” or “All cloud apps” enforces conditions like device compliance or MFA.
Please try the following steps:
- Enable flagging on the error page and reproduce the issue within 20 minutes. Then check the Sign-in logs → Conditional Access tab using the Correlation ID to identify the exact policy causing the block.
- Review all CA policies, including report-only ones, for conditions such as “Require compliant device” or “Require hybrid Azure AD join.”
- Confirm that your admin account and device meet compliance requirements or temporarily exclude them from the policy to test.
- Validate that the API Management Developer Portal app is not inadvertently blocked by policy scope.
Once you identify the policy, adjust its conditions or exclusions to allow access. Let me know if you need help interpreting the sign-in logs or modifying the policy.
For your reference:
https://learn.microsoft.com/en-us/entra/identity/conditional-access/troubleshoot-conditional-access
-
Mark Morrall • 51 Reputation points
2025-12-30T12:59:37.2866667+00:00 Thanks for getting back to me so quickly. I have tried your suggestions and I still only get 'Not Applied' in the Conditional Access column.
I ran the sign-in diagnostic, and this is what I got:
A sign-in attempt made by admin**** from their home tenant, Removed PII*, to API Management Developer Portal PROD in tenant* Removed PII failed with the error code 53003. This error is emitted because the user was not granted access to the tenant Removed PII*, and was subsequently blocked by a Conditional Access policy in the resource tenant. By design, we do not show policy details for the resource tenant in the home tenant. For this reason, the conditional access policy details are not captured in the troubleshooting details.*
Solution
An admin in the resource tenant, Removed PII*, should review the CA policies applied for this sign-in attempt and add the user as a guest of the tenant, if they aren't a member.*
The resource tenant Removed PII does not appear to be one of mine.
-
VEMULA SRISAI • 13,900 Reputation points • Microsoft External Staff • Moderator
2025-12-30T13:22:09.8633333+00:00 Mark Morrall Thank you for running the diagnostic and sharing the results. Based on the output, the sign-in attempt is failing because the account
admin**belongs to the home tenant (042**), but the API Management Developer Portal resides in a different resource tenant (72f**). Conditional Access policies in the resource tenant are blocking token issuance, and by design, policy details from that tenant are not visible in your logs.Next Steps:
- Confirm whether you have access to the resource tenant (72f988** ). If not, this indicates the portal belongs to another organization.
- An administrator in that resource tenant must:
- Add your account as a guest user in their tenant.
- Review and adjust Conditional Access policies to allow guest access.
- If this tenant is unexpected, verify the API Management instance you are trying to access and ensure you are using the correct subscription and tenant.
- Add your account as a guest user in their tenant.
Here’s the official Microsoft guidance for this scenario: https://learn.microsoft.com/entra/identity/conditional-access/troubleshoot https://learn.microsoft.com/entra/external-id/add-users
Please confirm if the API Management instance belongs to your organization or a partner tenant. Let me know if you need help checking the tenant association or adding guest access.
-
Mark Morrall • 51 Reputation points
2025-12-30T13:47:46.9166667+00:00 I cannot find any record of that TenantId.
-
VEMULA SRISAI • 13,900 Reputation points • Microsoft External Staff • Moderator
2025-12-30T14:07:48.0066667+00:00 Mark Morrall Thank you for confirming. Since you cannot find any record of the tenant ID
72f988bf-********, this indicates that the API Management Developer Portal you’re trying to access belongs to a different Azure AD tenant most likely Microsoft’s default tenant or a partner organization.Will connect offline with you to assist your further.
-
VEMULA SRISAI • 13,900 Reputation points • Microsoft External Staff • Moderator
2026-01-05T20:11:01.5433333+00:00 Mark Morrall Could you please confirm which account or tenant you intended to use for accessing the API Management Developer Portal? If possible, share the exact portal URL so we can verify whether it belongs to your organization’s tenant or an external one.
Also, please let us know your available timings for a call so we can assist you further.
-
Mark Morrall • 51 Reputation points
2026-01-05T20:35:16.2233333+00:00 Hi, I currently have two services:
- debtview-apim
- debtview-apim2
The first one is the one I want to use, but I couldn't get the developer portal working, so I set up the second one. That one isn't working either. So, ideally I want to delete the 2nd one (apim2) and keep the first one. But, there is another issue. On the first one, the develper portal is the old style site, but apim2 uses the new style site.
What I want to do is use the original apim but update the developer site to the new style. The url for the original developer site is https://debtview-apim.developer.azure-api.net
-
VEMULA SRISAI • 13,900 Reputation points • Microsoft External Staff • Moderator
2026-01-05T21:28:42.6233333+00:00 Mark Morrall I have scheduled a call and shared the meeting link in private message, please check once.
-
Matt Hunt • 15 Reputation points
2026-01-08T10:31:59.0733333+00:00 Hi, curious what the outcome of this was? I am experiencing the exact same behaviour as Mark with all APIM instances of Standard V2 SKU.
-
Mark Morrall • 51 Reputation points
2026-01-08T10:37:38.9766667+00:00 Hi Matt, I had a support call with MS a couple of days ago. The issue wasn't resolved on that call, and I am waiting for further feedback.
I will update when I have anything more.
-
VEMULA SRISAI • 13,900 Reputation points • Microsoft External Staff • Moderator
2026-01-08T10:52:19.2333333+00:00 Mark Morrall We appreciate your patience while we continue working on this issue. Our team is reviewing the case, and we’ll provide you with an update as soon as we have more information. Please feel free to reach out if you have any additional details or questions in the meantime.
-
Matt Hunt • 15 Reputation points
2026-01-08T11:19:29.5166667+00:00 If it's of any assistance to resolution, I've discovered that this only seems to be applying to API Management Instances of the v2 SKUs.
I have just deployed multiple API Management instances of various SKUs with default configurations and find that:
- StandardV2 - results in 53003, CA policy applied on the resource tenant - assuming this is Microsoft's service tenant.
- PremiumV2 - results in 53003, CA policy applied on the resource tenant - assuming this is Microsoft's service tenant.
- Standard - no issues.
- Developer - no issues.
Thanks for the speedy reply Mark, would appreciate you share any further findings here. I have reached out to Microsoft with a support query separately.
-
Jan Vincel (ElipsLife) • 5 Reputation points
2026-01-08T17:33:32.21+00:00 We are getting exactly same issue.
API Management tier StandardV2 - Conditional Access error 53003 with the Microsoft service tenant 72f988bf-***
We tried following:
- Configured B2B collaboration with the Microsoft tenant
- Disabled proxy on client computer
- Enabled Entra ID and CORS in APIM
- Added permission API Management Service Contributor
Nothing solved the issue. We will contact Microsoft support channel separately.
-
Mark Morrall • 51 Reputation points
2026-01-08T18:05:11.71+00:00 Thanks Matt & Jan, that's useful information, especially that it only seems to be affecting V2 instances. Wish I had know that before I spent 2 days creating my API's.
-
Mark Morrall • 51 Reputation points
2026-01-14T15:18:36.3766667+00:00 Quick update. This has now been escalated internally at Microsoft and I am waiting for a call back from them.
-
Matt Hunt • 15 Reputation points
2026-01-19T14:41:30.0433333+00:00 Hi Mark, not sure if you've had any updates from Microsoft here but it seems to me that the config pane of the developer portal is accessible again for v2 SKUs.
I have noticed that on the sign-in info, the Resource tenant ID is now pointing at my Entra ID tenant, and not at the 72f988bf-* ID which I assume to be Microsoft's tenant.
Thanks all involved in escalating this issue to resolution.
-
Mark Morrall • 51 Reputation points
2026-01-20T12:37:20.5533333+00:00 Thanks Matt, sadly it still isn't working for me, but I guess it's progress. I haven't heard from MS yet.
-
Siddhesh Desai • 8,210 Reputation points • Microsoft External Staff • Moderator
2026-02-09T18:21:37.68+00:00 Is there any other user in your tenant who is able to access the Developer site?
-
Siddhesh Desai • 8,210 Reputation points • Microsoft External Staff • Moderator
2026-02-24T21:20:12.65+00:00 Are you still facing the issue or is it resolved?
-
Mark Morrall • 51 Reputation points
2026-02-24T21:23:47.03+00:00 It seems to have resolved itself about 2 weeks ago. I was suddenly able to access the portal.
Did anything change behind the scenes?
Sign in to comment