A cloud-based identity and access management service for securing user authentication and resource access
AADSTS53003 means authentication succeeded, but Microsoft Entra refused to issue a token because Conditional Access blocked the request. Changing Chrome, clearing cookies, or correcting NTP will not alter that decision.
Ask an Entra administrator to open Sign-in logs and find the event by timestamp, request ID, or correlation ID. In the Conditional Access tab, identify the applied policy and failed grant control. Reproduce the user, Microsoft 365 resource, Linux platform, browser, and network in the What If tool.
Fix the control shown by the logs: register and enroll the Linux device and use a supported browser if device compliance is required; complete MFA if required; or correct an unintended user, location, platform, or application assignment. Test changes in report-only mode first. If the VM runs unattended automation, replace interactive user sign-in with an approved workload identity and application permissions. Only your tenant’s Entra administrator can change the blocking policy.