Appearance
Summary
If you're blocked from signing in by a security policy — not because of a wrong password — this guide helps you figure out what's happening and how to regain access. These blocks come from MFA (multi-factor authentication) failures, Conditional Access rules, or automated risk detection.
Symptoms
- You see
You cannot access this right noworYour sign-in was blockedafter entering the correct password - The error says
Sign-in was blocked by Conditional Access policy - MFA verification fails even though you're approving the prompt on your phone
- You see
Your account is at riskorUnusual activity detected - You can sign in from one device but not another, or from home but not the office (or vice versa)
Before You Start
- Access to the phone or device registered for MFA
- Your Microsoft Authenticator app or the phone number registered for SMS/call verification
Instructions
1. Identify the Type of Block
The error message tells you what's going on. Match your message below:
| Error Message | What It Means | Go To |
|---|---|---|
Your sign-in was blocked by Conditional Access | A company security rule is blocking your device, location, or app | Step 2 |
MFA verification failed or We didn't hear from you | Your MFA attempt timed out or wasn't received | Step 3 |
Your account is at risk or Unusual activity detected | Microsoft detected suspicious behavior on your account | Step 4 |
You cannot access this right now | Generic Conditional Access denial | Step 2 |
2. Fix Conditional Access Blocks
Conditional Access policies are security rules your company sets. They control who can access what from where and on which devices.
Common reasons for a block:
- Unmanaged device: You're signing in from a personal computer or phone that isn't enrolled in your company's device management (Intune).
- Blocked location: You're connecting from a location your company hasn't approved (like a public Wi-Fi network or a different country).
- Unapproved app: You're using a third-party email app instead of Outlook, or an old version of an Office app.
What to do:
- Try signing in from your company-issued device — if you're on a personal device, switch to your work laptop or phone.
- Connect to your company VPN — if you're working remotely, the VPN may be required to satisfy the location policy.
- Use the approved app — switch to Outlook (instead of a third-party email client) or update your Microsoft 365 apps to the latest version.
- Check the "More details" link — some block pages include a More details or Remediation link that tells you exactly which policy blocked you.
INFO
Conditional Access policies are set by your IT team. If you're doing everything right and still getting blocked, the policy may need an exception for your situation. Ask IT to check which policy is blocking you and whether your device or location can be added to it. Send them the full error text, the request or correlation ID shown on the block page, the time you tried, and the device and network you were on — those four details let them find your sign-in in the logs on the first attempt.
3. Fix MFA Failures
A prompt that never arrives and a prompt that fails are different problems with different fixes.
If MFA verification times out, isn't received, or keeps failing:
- Check your phone's internet connection. Authenticator push notifications require an internet connection (Wi-Fi or cellular data).
- Open the Microsoft Authenticator app and check for a pending approval prompt. If none appears, the notification may have expired.
- Try again — go back to the sign-in page and request a new MFA prompt.
- Use an alternative method: On the MFA prompt screen, look for I can't use my Microsoft Authenticator app right now or Sign in another way. Choose:
- Text message — a code is sent to your registered phone number
- Phone call — you receive an automated call to verify
- If your phone is lost or broken: See How to Recover Your Microsoft Authenticator App After Losing Your Phone.
The text-message and phone-call fallbacks have an announced end date. Microsoft is making passkeys the default sign-in experience for work accounts. From September 1, 2026, passkeys are enabled automatically for anyone currently set up for SMS or voice, and the next time those users sign in and complete MFA they are prompted to register one — a prompt you can postpone, by default as often as you like. From February 1, 2027, organizations that have not arranged their own telecom provider through the Microsoft Security Store can no longer use SMS or voice for MFA; organizations that do arrange one keep both. Use an alternative method above works today and is still the right thing to try when a prompt never arrives. If text message and phone call are the only backup methods on your account, register a passkey or the Authenticator app as well — after that date, an account left with only SMS or voice gets a passkey registration prompt that has to be completed before signing in can continue.
WARNING
If you keep receiving MFA prompts you didn't request, do not approve them. Someone may be trying to sign in with your password. Change your password immediately and report it to your IT team.
4. Fix Risk-Based Blocks ("Your Account Is at Risk")
Microsoft automatically flags accounts for suspicious activity — like sign-in attempts from unusual locations or compromised credentials found in data breaches.
- Go to https://mysignins.microsoft.com from any device.
- Sign in with your work email and password.
- If prompted, complete MFA verification.
- Review your Recent activity for any sign-ins you don't recognize (unfamiliar locations, devices, or times).
- If Microsoft requires it, change your password — follow the on-screen prompts. If you cannot remember the current one, the reset falls back to the recovery methods already registered on your account. How to Set Up Self-Service Password Reset (SSPR) shows what to have on file, and it is worth doing the moment you are back in — a risk block on an account with no registered methods becomes a helpdesk call instead of a two-minute reset.
- After changing your password, try signing in to your work apps again.
If you're unable to sign in to the review page, contact your IT team and tell them: "My account has been flagged for risk. I need help reviewing my account activity and clearing the risk."
5. Verify Access Is Restored
Check the apps you use most before you treat the lockout as resolved.
- Sign in to https://portal.office.com.
- Open Outlook, Teams, and OneDrive to confirm each app loads normally.
- If you reset your password, update it on your phone and other devices to prevent re-lockout.
Troubleshooting
WARNING
If your account is blocked and you cannot resolve it through any self-service method, contact your IT team immediately. Provide: your email address, the exact error message (screenshot if possible), the device you're using, and your location (home, office, travel).
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| "Conditional Access block" on personal device | Device not enrolled in company management | Sign in from your company-issued device or enroll your device in Company Portal |
| MFA prompt never arrives on phone | Poor internet connection or expired app registration | Check Wi-Fi/data; open the Authenticator app to refresh; try SMS instead — Microsoft-provided SMS retires February 1, 2027, see the note under Fix MFA Failures |
| Blocked when traveling or using hotel Wi-Fi | Location-based Conditional Access policy | Connect to your company VPN before signing in |
| "Your organization requires a compliant device" | Device doesn't meet security requirements | Ensure your device has the latest OS updates and Company Portal is installed |
| Repeated MFA prompts you didn't request | Someone else has your password | Change your password immediately; do not approve the prompts |