← cd ~/errors
// entra id sign-in error · conditional access and devices
AADSTS53002
ApplicationUsedIsNotAnApprovedApp
What it means
The app used isn't an approved app for Conditional Access.
How to fix it
Use an approved client app, such as Outlook mobile instead of a native mail app.
How to investigate
- Open the failed sign-in in the Entra admin center and select the Conditional Access tab. It lists every policy that applied and which one failed.
- Check the Device info tab: whether the device is registered, compliant and managed.
- Use What If in Conditional Access with the same user, app and device platform to reproduce the decision.
- Search the sign-in logs for the request ID or correlation ID from the troubleshooting details on the error page.
Tools that help
Error names and meanings follow Microsoft's error code reference. The fixes are this site's guidance.