AADSTS530034 / AADSTS530032 - Delegated Admin Blocked

AADSTS530034 / AADSTS530032 – Delegated Admin Blocked Due to Risk

Error: AADSTS530034 / AADSTS530032 – Delegated administrator or user blocked due to risk

This error occurs when Microsoft flags the delegated admin account as a risky user, or when security defaults block access unexpectedly.


Cause: Risky user detection in your own partner tenant or default security settings in the customer tenant may block delegated access based on conditional access policies.

Resolution

Step 1 – Check for Risky User in Your Tenant

  1. Go to your own tenant’s Microsoft Entra ID (Azure AD)
  2. Navigate to Security → Risky users
  3. If your delegated admin account is listed:
    • Select the account → click Dismiss user risk
    • Note: changes can take up to 24 hours to propagate across Microsoft systems

Step 2 – Check for Security Defaults in the Customer Tenant

  1. Go to the customer’s Microsoft Entra ID portal
  2. Navigate to Properties → Manage security defaults
  3. Turn off security defaults if not intentionally used

For tighter control, replace security defaults with targeted Conditional Access Policies.