Fix: Microsoft 365 Blocked When Travelling Overseas (Error 53003)

Microsoft Entra ID logo

A customer contacted us while travelling in Vietnam, unable to access their Microsoft 365 email or SharePoint from their laptop. They were completely locked out and had never experienced this before, with several weeks of travel ahead. We identified the issue as a Conditional Access policy blocking sign-ins from unapproved countries. Here is what caused it.

Symptoms

When attempting to sign in to Microsoft 365 (Outlook, Teams, SharePoint, OneDrive, or any M365 app) from an overseas location, users see one of the following error messages:

You cannot access this right now
Your sign-in was successful but does not meet the criteria to access this resource. For example, you might be signing in from a browser, an app, or a location that is restricted by your admin.

Error Code: 53003
Failure Reason: Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

Microsoft 365 conditional access error - You cannot access this right now - Error 53003 when travelling overseas

The “You cannot access this right now” error displayed when signing in to Microsoft 365 from a blocked country.

Common variations of this issue include:

  • Sign-in succeeds but then immediately shows “You don’t have permission to access this resource”
  • Access works for one user but not another travelling to the same destination
  • Access that was working stops when switching to a different Wi-Fi network or location

Affected Software

  • Service: Microsoft 365 (all apps, including Outlook, Teams, SharePoint, OneDrive)
  • Platform: All platforms (Windows, macOS, iOS, Android, web browser)
  • Related Services: Microsoft Entra ID (formerly Azure AD), Conditional Access, Microsoft Defender for Cloud Apps (MCAS)

Cause

This error occurs when your organisation has Conditional Access policies configured in Microsoft Entra ID that restrict sign-ins based on geographic location. These policies are a security measure that blocks authentication attempts from countries where your organisation does not normally operate.

When you travel overseas and connect to a local network (Wi-Fi, hotel internet, airport lounge), your IP address resolves to the country you are in. If that country is not on the approved list in your organisation’s Conditional Access policy, your sign-in is blocked with Error 53003.

Resolution

The fix depends on whether you manage your own Microsoft 365 tenant or have a managed IT provider.

If you manage your own tenant

  1. Sign in to the Microsoft Entra admin center
  2. Navigate to Protection > Conditional Access > Named locations
  3. Edit your existing named location (or create a new one) to add the countries the user is travelling to
  4. Ensure the relevant Conditional Access policy references this named location in its conditions
  5. Add the travelling user to any policy that grants access from the updated named locations
  6. Allow 5-15 minutes for the policy changes to propagate, then have the user try signing in again
  7. Important: Set a reminder to remove the temporary country access when the user returns

You can verify the block in Microsoft Entra > Sign-in logs by filtering for the affected user. Look for entries with Status “Failure” and Sign-in error code 53003, which confirms the Conditional Access policy is blocking the sign-in.

Microsoft Entra sign-in logs showing Error 53003 conditional access failure when signing in from overseas

Microsoft Entra sign-in logs showing a Failure with error code 53003 on a Conditional Access policy block.

If you have a managed IT provider

  1. Contact your IT provider before you travel with the following details:
    • Which users need overseas access
    • Which countries you will be visiting
    • Your departure and return dates
  2. Your provider will add a temporary exception to the Conditional Access policy for the specified dates and countries
  3. If you are already overseas and locked out, contact your provider. They can usually resolve this within 15-30 minutes during business hours

For GCIT Managed Customers

If you are a GCIT customer, your Microsoft 365 tenant is protected by our Block Untrusted Countries Conditional Access policy. This policy restricts sign-ins to Australia by default, with exceptions for countries that have been specifically approved for your organisation.

How country blocks work

As part of your managed security, GCIT deploys location-based Conditional Access policies that:

  • Allow sign-ins from Australia (and any other approved countries for your organisation)
  • Block sign-ins from all other countries
  • Generate a Microsoft Defender for Cloud Apps (MCAS) alert when a sign-in is attempted from a new country, so our team can investigate

This prevents attackers from using stolen credentials to sign in from overseas locations, which is one of the most common attack patterns in Microsoft 365 breaches.

How to request a travel exception

To avoid access issues while travelling, contact GCIT support before your trip:

Provide the following details:

  1. The names and email addresses of the users who will be travelling
  2. The countries you will be visiting (including any transit countries)
  3. Your departure and return dates

Our team will add a Travelling Users exception that temporarily allows access from the specified countries for the duration of your trip. This exception is automatically removed when your travel dates expire.

How to avoid travel exceptions altogether with phishing-resistant MFA

If you travel frequently, there is a better option than requesting exceptions every trip. GCIT offers phishing-resistant MFA (passkeys and FIDO2 security keys) as part of our managed security service. Users with phishing-resistant MFA enabled are excluded from country-based blocking entirely, meaning you can sign in from anywhere in the world without needing a travel exception.

This is possible because phishing-resistant MFA provides a much stronger authentication guarantee than traditional MFA methods (SMS codes, authenticator app push notifications). Passkeys and FIDO2 keys are cryptographically bound to the legitimate Microsoft sign-in page and cannot be intercepted by phishing attacks, even from overseas locations.

To qualify for this, your organisation must also have Huntress Managed ITDR (Identity Threat Detection and Response) on your managed service plan. Huntress ITDR provides 24/7 monitoring of your Microsoft 365 identities for suspicious behaviour, including:

  • Impossible travel events (sign-ins from two locations that are geographically impossible within the timeframe)
  • Sign-ins from unrecognised devices
  • Anomalous authentication patterns
  • Credential compromise indicators

With Huntress ITDR as a safety net, GCIT can confidently remove country restrictions for users with phishing-resistant MFA, giving you seamless global access without sacrificing security.

To discuss upgrading to phishing-resistant MFA and Huntress ITDR, contact your GCIT account manager or reach out to our team.

Important Notes

  • Conditional Access policy changes can take 5-15 minutes to propagate. If access does not work immediately after your IT provider confirms the change, wait and try again.
  • If you are using a VPN while overseas, your sign-in location will be determined by the VPN exit point, not your physical location. A VPN routing through Australia may bypass the block, but a VPN routing through another blocked country will not.
  • Cruise ship internet often routes through satellite providers whose IP addresses resolve to unexpected countries. If you are travelling by cruise, let your IT provider know so they can plan for this.

Need help with Microsoft 365 access while travelling?

Our team can set up a travel exception in minutes, or help you upgrade to phishing-resistant MFA for seamless global access.

Contact GCIT

Was this article helpful?
Ready to secure and simplify your IT? Talk to a GCIT expert today.