Quick troubleshooting view
A Conditional Access policy denies access for the observed sign-in context.
- No-compliant device
- Disallowed country or IP
- Legacy client
- Open Sign-in logs
- Read the Conditional Access result
- Identify the blocking policy
- Correct only the component confirmed by the checks
- Retest the original symptom after the change
- Escalate with collected evidence when the cause remains unclear
Contextual technician plan
Perform this check and preserve the observed result before changing configuration.
“Open Sign-in logs” should produce an observation that clearly confirms or rules out “No-compliant device”.
If the observation is normal, lower “No-compliant device” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “No-compliant device” first. Related action: Correct only the component confirmed by the checks.
Perform this check and preserve the observed result before changing configuration.
“Read the Conditional Access result” should produce an observation that clearly confirms or rules out “Disallowed country or IP”.
If the observation is normal, lower “Disallowed country or IP” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Disallowed country or IP” first. Related action: Retest the original symptom after the change.
Perform this check and preserve the observed result before changing configuration.
“Identify the blocking policy” should produce an observation that clearly confirms or rules out “Legacy client”.
If the observation is normal, lower “Legacy client” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Legacy client” first. Related action: Escalate with collected evidence when the cause remains unclear.
Repeat the same validation test after the correction and confirm the original symptom is gone. Validate stability before closing the incident.
Before changing configuration, record the current value and a way back.
Escalate with the exact symptom, scope, timestamp and completed checks when the issue remains unresolved.
+Open the complete detailed guideDetailed explanations and original troubleshooting content.
A Conditional Access policy denies access for the observed sign-in context.
Likely causes
- No-compliant device
- Disallowed country or IP
- Legacy client
- Risk or targeted application
Checks in priority order
- Open Sign-in logs
- Read the Conditional Access result
- Identify the blocking policy
- Fix the condition instead of disabling the policy
When to escalate
Escalate when the failure affects multiple users, a production dependency is unavailable, or logs show a component outside your control. Include timestamps, scope, tests already performed, and the last known working state.