Appearance
How to Fix "You Can't Access This From Here" Conditional Access Errors
Estimated Time to Fix: 5 minutesApplies to: Windows 11, Windows 10, macOS, Microsoft 365 Web Apps
Article Type: Troubleshooting
Last Updated: 2026-07-26
Summary
The "You can't access this from here" error occurs when Microsoft 365 blocks your sign-in attempt because of a corporate Conditional Access security policy. IT departments use these policies to protect company data by restricting access based on location, device status, or browser type. This guide shows you how to satisfy the security check and sign in successfully.
Symptoms
- Seeing a sign-in block screen with the heading
"You can't access this from here". - Error code
53003or message stating your organization requires a compliant device or trusted network. - Access works on your office desktop, but fails on your home laptop or mobile device.
Prerequisites
- Active work or school Microsoft 365 login credentials.
- Access to your company's approved VPN software (if working remotely).
- Company Portal app installed on your device (for managed Windows PCs).
Instructions
1. Connect to Your Company VPN or Network
Conditional Access policies frequently block sign-in attempts originating from home Wi-Fi networks or personal cellular connections.
- Click the Network icon in the Windows taskbar system tray (bottom-right corner).
- Open your corporate VPN client (such as GlobalProtect, Cisco Secure Client, FortiClient, or native Windows VPN).
- Enter your work credentials and complete the MFA authentication prompt.
- Return to your web browser or app and click Try again on the Microsoft 365 sign-in page.
2. Switch to an Approved Browser or Desktop App
Some organizations enforce browser restrictions that require modern authentication extensions or specific web browsers.
- Close Chrome, Firefox, or Safari.
- Open Microsoft Edge, which automatically passes your Windows work account identity and device token to Azure AD.
- Navigate to
portal.office.comand sign in. - Alternatively, open the installed desktop app (such as Outlook or Teams) instead of using the web browser version.
3. Verify Device Compliance in Company Portal
If your company requires a "compliant device," Windows must report its antivirus status, disk encryption (BitLocker), and update status to Microsoft Intune.
- Press the Windows Key, type
Company Portal, and select the app. - Click Devices in the left navigation menu.
- Select your computer name.
- Click Check status under Device status.
- Wait 60 seconds while Windows re-evaluates compliance.
- If the status changes to Can access company resources, restart your browser and sign in again.
4. Collect Error Details for IT Support Escalation
If your device is compliant and you are connected to the VPN but still blocked, a specific Conditional Access rule requires an IT admin override.
- On the
"You can't access this from here"screen, click More details. - Locate the following lines:
- Request ID / Correlation ID: (e.g.,
a1b2c3d4-e5f6-...) - Timestamp: (e.g.,
2026-07-26T09:15:00Z) - App name: (e.g.,
Microsoft TeamsorOffice 365 Exchange Online)
- Request ID / Correlation ID: (e.g.,
- Copy these details and paste them into your IT support request.
TIP
Sending the exact Correlation ID allows your IT department's Entra ID administrator to search the sign-in logs instantly and pinpoint which policy rule (such as an unapproved IP range or missing MAM policy) triggered the block.
Troubleshooting
WARNING
Never attempt to bypass Conditional Access using personal proxy servers or unapproved VPNs. These actions violate corporate security policies and will trigger automated account lockouts.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Error Code 53003 | Conditional Access policy block | Connect to company VPN or switch to Microsoft Edge |
| "Device is not recognized" | Computer not registered in Azure AD | Open Company Portal and click Check status |
| Blocked on personal laptop | Policy restricts access to company hardware | Use a company-issued laptop or access via Virtual Desktop (AVD) |
| Error occurs only in Google Chrome | Missing Windows Accounts extension | Install the official Windows Accounts Chrome extension |