Trusted Signing identity validation flipping Success→Failed for 15-year-old DUNS — please advise

Pat M 0 Reputation points
2026-05-27T05:40:22.8533333+00:00

I have a Trusted Signing account (Sound-Arrival-DevGroup) that

had an identity validation in Success status. Twice within 24

hours it has flipped to Failed without any stated reason in the

detail panel.

Failed validations:

  • <pii removed>
  • <pii removed>

Business: <pii removed>

DUNS: <pii removed>

Address: <pii removed>

Identity type: Public

Subscription ID: b<pii removed>

The Azure portal Identity Validation panel shows the correct

organization name, street, city, state, ZIP, and country. The

detail panel does NOT expose the failure reason. Have not

submitted a third validation to avoid stacking failures.

Please share the specific match failure so I can correct and

re-submit.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-27T05:40:38.0233333+00:00

    Trusted Signing (Artifact Signing) does not expose detailed failure reasons for identity validation in the Azure portal. When an Organization/Public identity validation fails, the documented guidance is:

    1. Check for missed or failed email verification
      • A verification link is sent to the Primary Email entered in the identity validation request.
      • The link expires in seven days.
      • If the email verification is missed or the link expires, the validation fails and a new identity validation request is required.
      • If email verification shows as Failed or the link was never used within seven days, submit a new identity validation request with a primary email that can reliably receive external messages with links.
    2. Understand non-email-related failures
      • If the failure is not due to email verification, the Microsoft validation team could not make a determination based on the information and documentation provided.
      • Even if additional documentation was uploaded, if the team cannot validate the information (for example, public records, business identifiers, or domain ownership do not align with the submitted details), the request is marked Failed and onboarding for that request cannot proceed.
      • If three documentation-upload attempts were used for that request, the process cannot continue for that identity validation.
    3. Required next steps after a Failed status
      • Once an Organization identity validation is Failed, it cannot be “fixed” in place; a new identity validation request must be created.
      • Creating multiple concurrent identity validations for the same entity that are still In Progress does not help and cannot be expedited.
      • If repeated attempts fail and the validation team still cannot validate the organization, the documented recommendation is to delete the Artifact Signing account to avoid being billed for unused resources.
    4. How to proceed in this scenario
      • Create a new Public identity validation for the same organization, carefully ensuring:
        • The organization name, address, and business identifier exactly match current official business records and public listings.
        • The website URL and email domains clearly belong to the same legal entity and can receive external verification emails with links.
      • Monitor the status and email inbox for:
        • The email verification link (must be completed within seven days).
        • Any request for additional documentation; respond within the three allowed upload attempts, using documents that:
          • Were issued within the last 12 months.
          • Have an expiration date at least two months in the future.
          • Show the same company name and address as in the identity validation request.
          • Demonstrate domain registration or invoices that clearly tie the domain to the legal entity.
      • If the new request fails again without a visible reason, use one of the supported escalation paths:
        • Open an Azure Support case for Artifact Signing.
        • Or post on Microsoft Q&A with the artifact-signing tag, referencing the Identity Validation ID (which can be copied from the Identity Validation details pane) so the support team can investigate the backend validation result.
    5. Impact on signing and certificate profiles
      • A Completed identity validation is a prerequisite for creating and using certificate profiles.
      • If identity validation is Failed or later expires and is not renewed, certificate renewal and associated signing processes stop for the affected certificate profiles.
      • To continue signing, a new identity validation must be created and associated with the relevant certificate profiles once it reaches Completed status.

    Because the service does not surface the exact match rule that failed, the only supported way to obtain case-specific details is through Azure Support or Microsoft Q&A escalation with the Identity Validation ID.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.