A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
Changing which alias is primary on the Microsoft account doesn't affect Artifact Signing identity validation emails. The verification link is always sent to the Primary Email value entered in the Artifact Signing identity validation request, and that email must be able to receive messages (with links) from external senders.
For this scenario, use the following checks and next steps:
- Confirm which email was used in the current, active identity validation request
- In the Azure portal, open the Artifact Signing account.
- Go to Identity validations and select the validation that is currently In Progress (matching the Identity Validation ID being used).
- In the details pane, verify the Primary Email value. This is where the verification link is sent.
- Check for common delivery issues
- Ensure the Primary Email address is not a distribution list (for organization validation, the primary email must be able to receive external email with links).
- Check junk/spam folders and any security filters for the mailbox used as Primary Email.
- Make sure the mailbox can receive emails from external domains and that no transport rules or security products are blocking Microsoft mail.
- Handle an expired or failed email verification
- If the email verification link was not used within seven days, the link expires and a new link cannot be resent on the same request. In that case, a new identity validation request must be created with the correct primary email.
- If the email validation status shows Failed and the email was never received, create another identity validation request and ensure the primary email is a mailbox (not a distribution list) that can receive external email with links.
- When organization identity validation fails for email reasons
- If the organization identity validation fails because the email verification was missed, a new identity validation request is required.
- If it fails for other reasons (for example, documentation could not be validated after all attempts), onboarding to Artifact Signing cannot proceed and the Artifact Signing account should be deleted to avoid charges.
- If the current request is stuck and no email is received
- Do not create multiple parallel identity validation requests for the same entity; this does not speed up processing.
- Instead, either:
- Create a single new identity validation request with a verified, working primary email address and monitor it, or
- If more help is needed (for example, status unclear or repeated failures), open a case via Azure Support or ask on Microsoft Q&A using the artifact-signing tag, referencing the Identity Validation ID.
The fact that the alias used in the form was not the primary alias at submission time does not by itself block the verification email. The critical factors are: the exact Primary Email value stored in the identity validation request, its ability to receive external email with links, and whether the seven‑day validity window for the verification link has passed. If that window has passed or the email validation shows Failed, create a new identity validation request and use the correct, working mailbox as the primary email.
References: