MFA issue with Azure CLI

Kumar Gaurav 0 Reputation points
2026-10-11T22:52:54.4+00:00

I am logging in for the first time using Azure CLI and it keeps failing after the security code is entered on the browser. Message: "your sign-in was successful but you don't have permission to access this resource". I am the owner of the subscription. The conditional access shows a failure under the "Security Defaults" policy. I have tried using the diagnosis tools in entra admin center and azure portal, to no success.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-11T22:53:10.1066667+00:00

    This failure is consistent with a Microsoft Entra Conditional Access requirement, specifically MFA enforcement through Security Defaults or another access policy.

    Use this path:

    1. Stop using username/password sign-in for Azure CLI.
      az login --user <username> --password <password> and ROPC-style password sign-in do not work when MFA is required.
    2. Sign in interactively instead.
      Run:
         az logout
         az login
      
      If the browser flow does not complete correctly, force device code flow:
         az login --use-device-code
      
    3. If the account belongs to multiple tenants, specify the correct tenant explicitly.
      Azure CLI can try the first tenant it finds, which can cause authentication failure against the wrong tenant.
         az login --tenant 00000000-0000-0000-0000-000000000000
      
    4. If the failure is still tied to Conditional Access or Security Defaults, the sign-in policy must be satisfied at sign-in.
      Documented resolution options are:
      • have the Azure administrator enforce MFA at sign-in so the session satisfies Conditional Access requirements
      • if MFA enforcement at sign-in is not possible, authenticate interactively with a claims challenge:
         az logout
         az login --tenant "aaaabbbb-0000-cccc-1111-dddd2222eeee" --scope "https://management.core.windows.net//.default" --claims-challenge "<claims-challenge-token>"
      
    5. For automation or scripts, switch to a workload identity instead of a user identity.
      When MFA is required, the supported approach is to use a service principal or managed identity.
    6. Since the sign-in report already shows failure under Security Defaults, check with the Conditional Access or tenant administrator to review that policy.
      Similar Azure CLI failures with messages like “you don't have access to this” and error 53003 are resolved by correcting Conditional Access restrictions.

    If the account is the only admin and access is blocked by MFA or policy, recovery may require another admin account or tenant access recovery steps before Azure portal and CLI access can be restored.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.