We manage several Microsoft 365 environments, and over the past month users in different tenants have intermittently reported that Outlook displays an "Access Denied" badge instead of their mail. Sometimes signing in again works, while other times the sign-in prompt loops before eventually letting them in. The issue has occurred with different antivirus products, so a security-software conflict seems unlikely.
We have tried clearing single sign-on credentials from Credential Manager, which appears to restore access temporarily, but the problem returns later. On one day, three users in separate tenants experienced it around the same time. Sign-in logs show successful authentication rather than a rejected attempt or an obvious Conditional Access block.
Our Microsoft support partner has suggested resetting, removing, and reinstalling Outlook, but those steps have not produced a lasting improvement. Has anyone else been seeing this intermittent behavior, particularly with the new Outlook, and found a reliable fix or workaround?
4 Answers
A similar sign-in problem has also appeared in Outlook on the web. In that case, the mobile apps continued working while the browser client failed. It happened during a period of Microsoft service issues and eventually appeared to clear up, so checking the Microsoft 365 service health dashboard is worthwhile when several tenants are affected at once.
This has been a recurring problem with the new Outlook for many organizations. Rebuilding the OST, repairing or reinstalling the application, and applying registry changes did not consistently resolve it. The only dependable workaround we found was moving affected users back to classic Outlook, although that is not ideal if people have already started adopting the new client.
I would compare the Entra sign-in logs for an affected session and check whether authentication is actually being rejected by a Conditional Access policy or another control. If the logs show successful sign-ins even while Outlook is stuck in a loop, that points more toward a client-side problem than an identity-policy failure.
The logs show successful sign-ins, including during the loops. We have not found a rejected attempt or an obvious Conditional Access explanation.
I have seen the same behavior in new Outlook. A reboot usually gets the user back in, but it is only a temporary workaround. There are also cases where notifications appear but the new messages never populate in the inbox, which makes the client difficult to trust for production use.

That matches what we are seeing. We had a period without many new Outlook issues, and users have been switching over on their own, so reverting everyone is not a great long-term answer.