azureblog.co.uk
← cd ~/errors
// entra id sign-in error · conditional access and devices

AADSTS53002

ApplicationUsedIsNotAnApprovedApp

What it means

The app used isn't an approved app for Conditional Access.

How to fix it

Use an approved client app, such as Outlook mobile instead of a native mail app.

How to investigate

  1. Open the failed sign-in in the Entra admin center and select the Conditional Access tab. It lists every policy that applied and which one failed.
  2. Check the Device info tab: whether the device is registered, compliant and managed.
  3. Use What If in Conditional Access with the same user, app and device platform to reproduce the decision.
  4. Search the sign-in logs for the request ID or correlation ID from the troubleshooting details on the error page.

Tools that help

Error names and meanings follow Microsoft's error code reference. The fixes are this site's guidance.