A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
Manual log inspection for a specific tenant or identity validation request can't be performed here. For this scenario, the supported paths are:
- Create a new identity validation request
- When email verification fails, the documented remediation is to submit a new identity validation request.
- Ensure the primary email address is an individual mailbox (not a distribution list) and can receive emails with links from external senders.
- If the email verification link expires (not clicked within 7 days), a new identity validation request is required; links can’t be resent for the same request.
- If email verification still fails with a new request
- Use Azure Support to have the Artifact Signing team review the case. Provide:
- Tenant ID
- Subscription ID/name
- Artifact Signing account name
- Identity Validation Id (from the Identity Validation details pane in the Azure portal)
- The primary and secondary email addresses used
- You can also post on Microsoft Q&A with the artifact-signing tag for additional assistance, but tenant‑specific log review and backend checks are done via Azure Support.
- Use Azure Support to have the Artifact Signing team review the case. Provide:
- Confirm prerequisites and configuration
- Verify that the New identity button is active and that the account used has the Artifact Signing Identity Verifier role.
- For public identity validation, ensure all required fields (organization name, website URL, business identifier, address, etc.) are accurate and match public records.
- If identity validation fails for reasons other than email verification and additional documentation is requested, there are only three attempts to upload documents. After that, onboarding can’t proceed for that request.
- If identity validation repeatedly fails and can’t be resolved
- If the Microsoft validation team can’t validate the information even after requested documentation is provided, onboarding to Artifact Signing can’t proceed. In that case, the guidance is to delete the Artifact Signing account to avoid being billed for unused resources.
- When it is safe to submit a new identity validation
- A new identity validation request can be submitted at any time, provided the required role is assigned and the previous request is not being reused for email verification.
- If a new identity validation is needed for the same organization but with a different primary email address while another validation exists, contact Azure Support to continue onboarding.
For the specific backend reason codes, delivery status, or internal step where email verification fails, only Azure Support and the Artifact Signing team can access and interpret those logs.
References: