Seeing "Your account has been locked", AADSTS50053, AADSTS50076 or AADSTS53003 when signing in to Microsoft 365? Here's what each error means and the fix.
You try to sign in to Outlook, Teams or the Microsoft 365 portal and get stopped by "Your account has been locked. Contact your support person to unlock it, then try again." Or a code beginning AADSTS, such as AADSTS50053, AADSTS50076 or AADSTS53003. Another common one is "Your sign-in was successful but does not meet the criteria to access this resource", or "You cannot access this right now".
These messages come from Microsoft Entra ID, which handles every Microsoft 365 sign-in. Each code points to a specific cause. Here's what the common ones mean and how to fix them.
Quick answer
Note the full error code and the Correlation ID from "More details". "Account locked" or AADSTS50053 means too many failed attempts: wait and try again with the correct password. AADSTS50076 means MFA is needed, and AADSTS53003 or "does not meet the criteria" means a Conditional Access policy blocked you. Your admin can see the exact reason in the Entra sign-in logs.
Why This Happens
Entra ID checks more than your password. It considers your location, device, app, risk level and your organisation's security policies. If any check fails, it blocks the sign-in and returns an error code. Some are protecting you from an attacker; others mean a policy needs adjusting.
On most error pages, click More details to see the Request ID, Correlation ID and timestamp. Screenshot them for your admin. They make it easy to find the exact sign-in in the logs.
"Your Account Has Been Locked" and AADSTS50053
What it means: Entra's Smart Lockout has temporarily locked the account after too many failed sign-ins, or blocked sign-ins coming from a suspicious location. It may be you mistyping, an old device with an outdated password, or an attacker guessing.
What to do:
- Stop trying and wait. Smart Lockout releases automatically after a short period, which grows with repeated lockouts.
- Check phones and tablets for old email accounts with an outdated password, which can trigger repeated failures.
- Reset your password via self-service password reset (if enabled) at aka.ms/sspr.
- If you didn't cause the failed attempts, tell your admin. It may be a password-guessing attack.
AADSTS50126: Invalid Username or Password
The password was wrong. Check Caps Lock and keyboard layout, and that you're using your work account rather than a personal one. If you recently changed it, other devices may still be using the old one.
AADSTS50057: Account Disabled
An admin has blocked sign-in for the account. This is common after someone leaves, or when an account is suspected of being compromised. Only an admin can unblock it.
AADSTS50076 and AADSTS50079: MFA Required
AADSTS50076 means the sign-in needs multi-factor authentication, perhaps because of a policy change or a new location, and the app didn't complete it. AADSTS50079 means you need to register MFA methods first.
- Sign in through a browser at office.com and complete the MFA prompt or registration.
- If the error comes from an old app or device, such as a phone's built-in mail app using basic authentication, switch to the Outlook app, which supports modern authentication.
- If you've lost your MFA device, see our guide on getting back in after losing your phone.
AADSTS53003 and "Does Not Meet the Criteria"
What it means: a Conditional Access policy blocked access. The password and MFA may be fine, but the sign-in didn't meet the rules, for example:
- Signing in from a country your organisation blocks.
- Using a personal device when only company devices are allowed.
- Using an app or browser that isn't approved.
- A risky sign-in detected by Entra ID Protection.
Related codes include AADSTS53000 (the device must be managed or compliant) and AADSTS53001 (the device must be domain joined). Try from your work laptop or the office network, and send the error details to your admin.
Other Codes You Might See
- AADSTS50034: the account doesn't exist in that directory. Check the username.
- AADSTS50055: the password has expired. Change it.
- AADSTS50020: you're signing in to another organisation's resources with an account that isn't a guest there.
For Your Microsoft 365 Admin
- Sign-in logs. In the Entra admin centre, open the user and look for Sign-in logs, or search all sign-ins by Correlation ID. Each failure shows the error code, location, device, app and, on the Conditional Access tab, which policy applied and why.
- Blocked sign-in. In the Microsoft 365 admin centre, go to Users > Active users, select the user and look for Block sign-in or Unblock sign-in.
- Smart Lockout. Settings are under Entra's authentication methods, in Password protection. The defaults suit most businesses. If one account keeps locking, look at the sign-in log sources: a forgotten device or a password-spraying attack.
- Conditional Access. Use the What If tool on the Conditional Access policies page to see which policies apply to a given user, app and location. Use report-only mode when testing new policies.
- Risky users. If you have Entra ID P2 (included in some licence add-ons), check Identity Protection for risky users and sign-ins.
Don't weaken Conditional Access to get someone working, for example by excluding them from MFA. Fix the cause, and if you must make an exception, make it temporary and tightly scoped.
How to Stop It Happening Again
Most lockouts are caused by forgotten devices with old passwords, users without backup MFA methods, and Conditional Access policies designed without testing. Self-service password reset with MFA, at least two registered methods per user, passwordless sign-in where possible, and well-tested Conditional Access policies with documented exceptions make sign-in both safer and calmer. Our password manager guide helps stop the mistyped-password problem too.
When to Call in Help
If accounts keep locking, you see sign-in attempts from abroad, or you're unsure what your Conditional Access policies do, our cybersecurity service can review and fix them. Our managed IT service handles lockouts day to day. A free IT health check is a good starting point, or contact us directly.
Related Reading
Common questions
Your account has been temporarily locked by Smart Lockout, usually after too many failed sign-in attempts or attempts from a suspicious location. Wait before trying again, and tell your admin if you didn't cause the failures.
It means a Conditional Access policy blocked the sign-in, for example because of your location, device or app. Try from a company device or the office network, and send the error details to your admin to check the sign-in logs.
Your password and MFA worked, but a Conditional Access rule wasn't met, such as requiring a compliant device or an approved app. Your admin can see which policy blocked you in the Entra sign-in logs.
Smart Lockout releases automatically after a short period, which increases with repeated lockouts. If an admin has blocked sign-in instead, only an admin can unblock it.
Want to talk about this?
Book a free 15-minute call and we'll discuss how this applies to your business.
Get IT tips in your inbox
Practical advice for small businesses. No spam.
