A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
Backend failure reasons can’t be checked here, but the supported next steps are clear:
- Do not keep creating overlapping in-progress requests for the same entity. That does not help, and requests can’t be expedited.
- If the request is already Failed, create a new identity validation request.
- For the new request, verify these inputs before submitting:
- The Primary Email is a monitored mailbox on a domain owned by the legal business entity.
- The mailbox can receive messages and links from external senders.
- The Secondary Email is different from the primary email, and for organizations its domain matches the primary email domain.
- All organization and representative details exactly match the legal and identity documents.
- If the request reaches Action Required, complete the follow-up steps from the email promptly. The verification links expire after seven days.
- If Face Check or individual verification continues to fail with address/name mismatch or FaceCheck-related errors, delete the existing identity validation request, remove the associated Verified ID from Microsoft Authenticator, then submit a new identity validation request and create a new Verified ID. Ensure all information is accurate and complete the verification in adequate lighting.
- If more documents are requested, upload current documents in the Azure portal. Documents must be issued within the previous 12 months, and there are three attempts for documentation upload.
- For direct assistance with identity validation, use Azure Support or Microsoft Q&A with the artifact-signing tag.
Relevant service behavior:
- Identity validation is completed only in the Azure portal, not with Azure CLI.
- Processing can take 1–20 business days.
- If identity validation expires before renewal, certificate renewal stops and signing associated with those certificate profiles stops.
- Renewal can start 60 days before expiration. If renewal through Renew shows validation errors, or the identity validation is already expired, create a new Identity Validation.
Because the repeated failure is happening after the Verified ID/Face Check stage, the only documented self-service remediation is to remove the associated Verified ID, submit a new identity validation, and recreate the Verified ID with exact matching information and good verification conditions.
References: