Artifact Signing organization identity validation failed with no reason shown — guidance before resubmitting

Engin Cakaloglu 0 Reputation points
2026-08-13T11:15:36.46+00:00

Our Azure Artifact Signing (formerly Trusted Signing) organization identity validation has status Failed, but the Azure portal does not show a failure reason.

The identity validation details only show the submitted organization data, the uploaded documents, and the Failed status. The Activity Log also contains no information explaining the validation failure.

Before submitting a new identity validation request, I would like to understand what could not be verified and what, if anything, needs to be corrected.

Setup:

  • Product: Azure Artifact Signing (formerly Trusted Signing)
  • Validation type: Organization / Public Trust
  • Country: Germany
  • SKU: Basic
  • Region: West Europe
  • Organization: recently incorporated German GmbH with an official commercial register (Handelsregister) entry
  • All three requested supporting documents were uploaded successfully and are shown with a green check mark in the Azure portal:
    • assignment letter from an authorized representative
      • DENIC domain ownership record
        • company website imprint (Impressum) showing the organization's name, address and contact information
        • The registered primary email address is a real mailbox capable of receiving external email and is not a distribution list.
        • I have checked this mailbox, including spam/junk, and there is no outstanding or overlooked Artifact Signing verification email.
        • The requester is signed in with the corresponding organizational account.
        • The required Artifact Signing roles are assigned.
        • The Verified ID / Face Check step was completed successfully during the validation process.

Questions:

  1. Is it possible for Microsoft to determine the specific reason why this organization identity validation failed? I can provide the Identity Validation ID, Subscription ID, Tenant information and any other identifiers privately to a Microsoft employee.
  2. Since the portal provides no failure details, how can I determine which organization information or verification source could not be validated? In particular, is there any additional public business record, registry information, or supporting documentation that Microsoft recommends checking for a recently incorporated German GmbH before resubmitting?
  3. Should I avoid submitting a new identity validation request until this failure has been investigated, or can I simply use "+ New identity" after a validation has reached the Failed state?
  4. If tenant-specific investigation is required, what is the recommended way to have the Artifact Signing team or Azure Support review this failed validation?

I would prefer to understand and correct the underlying issue before using another validation attempt rather than resubmitting the same information without knowing what caused the failure.

I am happy to provide all relevant IDs and organization details privately to a Microsoft engineer.

Thank you.Our Azure Artifact Signing (formerly Trusted Signing) organization identity validation has status Failed, but the Azure portal does not show a failure reason.

The identity validation details only show the submitted organization data, the uploaded documents, and the Failed status. The Activity Log also contains no information explaining the validation failure.

Before submitting a new identity validation request, I would like to understand what could not be verified and what, if anything, needs to be corrected.

Setup:

  • Product: Azure Artifact Signing (formerly Trusted Signing)
  • Validation type: Organization / Public Trust
  • Country: Germany
  • SKU: Basic
  • Region: West Europe
  • Organization: recently incorporated German GmbH with an official commercial register (Handelsregister) entry
  • All three requested supporting documents were uploaded successfully and are shown with a green check mark in the Azure portal:
    • assignment letter from an authorized representative
      • DENIC domain ownership record
        • company website imprint (Impressum) showing the organization's name, address and contact information
        • The registered primary email address is a real mailbox capable of receiving external email and is not a distribution list.
        • I have checked this mailbox, including spam/junk, and there is no outstanding or overlooked Artifact Signing verification email.
        • The requester is signed in with the corresponding organizational account.
        • The required Artifact Signing roles are assigned.
        • The Verified ID / Face Check step was completed successfully during the validation process.

Questions:

  1. Is it possible for Microsoft to determine the specific reason why this organization identity validation failed? I can provide the Identity Validation ID, Subscription ID, Tenant information and any other identifiers privately to a Microsoft employee.
  2. Since the portal provides no failure details, how can I determine which organization information or verification source could not be validated? In particular, is there any additional public business record, registry information, or supporting documentation that Microsoft recommends checking for a recently incorporated German GmbH before resubmitting?
  3. Should I avoid submitting a new identity validation request until this failure has been investigated, or can I simply use "+ New identity" after a validation has reached the Failed state?
  4. If tenant-specific investigation is required, what is the recommended way to have the Artifact Signing team or Azure Support review this failed validation?

I would prefer to understand and correct the underlying issue before using another validation attempt rather than resubmitting the same information without knowing what caused the failure.

I am happy to provide all relevant IDs and organization details privately to a Microsoft engineer.

Thank you.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)


1 answer

Sort by: Most helpful
  1. AI answer

    2026-08-13T11:16:14.3333333+00:00

    Yes. The documented path for tenant-specific investigation is to contact Azure Support. For Artifact Signing identity validation questions, support can be engaged through Azure Support, and Microsoft Q&A is also listed as a support option for Artifact Signing questions.

    From the documented behavior, the Azure portal does not expose a detailed failure reason. If organization identity validation fails for reasons other than a missed email verification, the validation team was not able to make a determination based on the information provided. If more documentation was requested, there are only three upload attempts for that request.

    Before resubmitting, the supported checks are:

    1. Verify the primary email path again.
      • The verification link sent to the primary email expires after seven days.
      • The mailbox must accept messages with links from external senders.
      • If the email was missed or not selected within seven days, a new identity validation request is required because the link cannot be resent on the same request.
    2. Recheck the submitted organization data for exact accuracy.
      • For public identity validation, the organization information must be correct when the request is created.
      • If changes are needed after creation, a new identity validation request must be completed.
      • For quicker onboarding, public records for the legal business entity should be up to date.
    3. Recheck document suitability.
      • If additional documentation is requested, documents must be current.
      • Submitted documents must be issued within the previous 12 months, and any expiration date must be at least two months in the future.
      • If official business documents are used, they should list the company name and address exactly as provided in the identity validation request.
      • Domain registration or renewal documentation should list the entity, contact name, and all domains mentioned in the request.
    4. Confirm the request prerequisites in the portal.
      • The requester must have the Artifact Signing Identity Verifier role.
      • Public Trust organization validation is supported for organizations in Germany because Public Trust certificates are available to organizations in the European Union.

    On whether to resubmit now: if the current request is already in Failed state, the documented self-service action is to create a new identity validation request when correction is needed, when the email verification was missed, or when the previous request cannot proceed. Also, creating more identity validation requests for the same entity while one is still in progress does not help. That warning applies to requests still in progress, not a request already marked Failed.

    On what to do first in this case:

    1. Review whether any submitted organization details need correction.
    2. Confirm that public records for the GmbH are fully up to date.
    3. Confirm the uploaded documents match the request details exactly and meet the recency requirements.
    4. If the failed request still leaves the cause unclear, open an Azure Support ticket and provide the identity validation details privately there for investigation.
    5. If support identifies a data mismatch or an expired/missed verification path, submit a new identity validation request with corrected information.

    One additional case is documented: if identity validation already exists for the same organization but another request is needed with a different primary email address, support must be contacted to continue onboarding.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.