A customer contacted us while travelling in Vietnam, unable to access their Microsoft 365 email or SharePoint from their laptop. They were completely locked out and had never experienced this before, with several weeks of travel ahead. We identified the issue as a Conditional Access policy blocking sign-ins from unapproved countries. Here is what caused it.
Symptoms
When attempting to sign in to Microsoft 365 (Outlook, Teams, SharePoint, OneDrive, or any M365 app) from an overseas location, users see one of the following error messages:
You cannot access this right now
Your sign-in was successful but does not meet the criteria to access this resource. For example, you might be signing in from a browser, an app, or a location that is restricted by your admin.Error Code: 53003
Failure Reason: Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.
The “You cannot access this right now” error displayed when signing in to Microsoft 365 from a blocked country.
Common variations of this issue include:
- Sign-in succeeds but then immediately shows “You don’t have permission to access this resource”
- Access works for one user but not another travelling to the same destination
- Access that was working stops when switching to a different Wi-Fi network or location
Affected Software
- Service: Microsoft 365 (all apps, including Outlook, Teams, SharePoint, OneDrive)
- Platform: All platforms (Windows, macOS, iOS, Android, web browser)
- Related Services: Microsoft Entra ID (formerly Azure AD), Conditional Access, Microsoft Defender for Cloud Apps (MCAS)
Cause
This error occurs when your organisation has Conditional Access policies configured in Microsoft Entra ID that restrict sign-ins based on geographic location. These policies are a security measure that blocks authentication attempts from countries where your organisation does not normally operate.
When you travel overseas and connect to a local network (Wi-Fi, hotel internet, airport lounge), your IP address resolves to the country you are in. If that country is not on the approved list in your organisation’s Conditional Access policy, your sign-in is blocked with Error 53003.
Resolution
The fix depends on whether you manage your own Microsoft 365 tenant or have a managed IT provider.
If you manage your own tenant
- Sign in to the Microsoft Entra admin center
- Navigate to Protection > Conditional Access > Named locations
- Edit your existing named location (or create a new one) to add the countries the user is travelling to
- Ensure the relevant Conditional Access policy references this named location in its conditions
- Add the travelling user to any policy that grants access from the updated named locations
- Allow 5-15 minutes for the policy changes to propagate, then have the user try signing in again
- Important: Set a reminder to remove the temporary country access when the user returns
You can verify the block in Microsoft Entra > Sign-in logs by filtering for the affected user. Look for entries with Status “Failure” and Sign-in error code 53003, which confirms the Conditional Access policy is blocking the sign-in.
Microsoft Entra sign-in logs showing a Failure with error code 53003 on a Conditional Access policy block.
If you have a managed IT provider
- Contact your IT provider before you travel with the following details:
- Which users need overseas access
- Which countries you will be visiting
- Your departure and return dates
- Your provider will add a temporary exception to the Conditional Access policy for the specified dates and countries
- If you are already overseas and locked out, contact your provider. They can usually resolve this within 15-30 minutes during business hours
For GCIT Managed Customers
If you are a GCIT customer, your Microsoft 365 tenant is protected by our Block Untrusted Countries Conditional Access policy. This policy restricts sign-ins to Australia by default, with exceptions for countries that have been specifically approved for your organisation.
How country blocks work
As part of your managed security, GCIT deploys location-based Conditional Access policies that:
- Allow sign-ins from Australia (and any other approved countries for your organisation)
- Block sign-ins from all other countries
- Generate a Microsoft Defender for Cloud Apps (MCAS) alert when a sign-in is attempted from a new country, so our team can investigate
This prevents attackers from using stolen credentials to sign in from overseas locations, which is one of the most common attack patterns in Microsoft 365 breaches.
How to request a travel exception
To avoid access issues while travelling, contact GCIT support before your trip:
- Email: support@gcit.com.au
- Phone: 1300 369 111
Provide the following details:
- The names and email addresses of the users who will be travelling
- The countries you will be visiting (including any transit countries)
- Your departure and return dates
Our team will add a Travelling Users exception that temporarily allows access from the specified countries for the duration of your trip. This exception is automatically removed when your travel dates expire.
How to avoid travel exceptions altogether with phishing-resistant MFA
If you travel frequently, there is a better option than requesting exceptions every trip. GCIT offers phishing-resistant MFA (passkeys and FIDO2 security keys) as part of our managed security service. Users with phishing-resistant MFA enabled are excluded from country-based blocking entirely, meaning you can sign in from anywhere in the world without needing a travel exception.
This is possible because phishing-resistant MFA provides a much stronger authentication guarantee than traditional MFA methods (SMS codes, authenticator app push notifications). Passkeys and FIDO2 keys are cryptographically bound to the legitimate Microsoft sign-in page and cannot be intercepted by phishing attacks, even from overseas locations.
To qualify for this, your organisation must also have Huntress Managed ITDR (Identity Threat Detection and Response) on your managed service plan. Huntress ITDR provides 24/7 monitoring of your Microsoft 365 identities for suspicious behaviour, including:
- Impossible travel events (sign-ins from two locations that are geographically impossible within the timeframe)
- Sign-ins from unrecognised devices
- Anomalous authentication patterns
- Credential compromise indicators
With Huntress ITDR as a safety net, GCIT can confidently remove country restrictions for users with phishing-resistant MFA, giving you seamless global access without sacrificing security.
To discuss upgrading to phishing-resistant MFA and Huntress ITDR, contact your GCIT account manager or reach out to our team.
Important Notes
- Conditional Access policy changes can take 5-15 minutes to propagate. If access does not work immediately after your IT provider confirms the change, wait and try again.
- If you are using a VPN while overseas, your sign-in location will be determined by the VPN exit point, not your physical location. A VPN routing through Australia may bypass the block, but a VPN routing through another blocked country will not.
- Cruise ship internet often routes through satellite providers whose IP addresses resolve to unexpected countries. If you are travelling by cruise, let your IT provider know so they can plan for this.
Related Resources
- Microsoft Learn: Conditional Access – Location conditions
- Microsoft Learn: Named locations in Conditional Access
- Microsoft Learn: Passwordless authentication options
- GCIT KB: Fix: Claude MCP Server Blocked by Conditional Access Policy
Need help with Microsoft 365 access while travelling?
Our team can set up a travel exception in minutes, or help you upgrade to phishing-resistant MFA for seamless global access.