A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
SmartScreen still shows "unrecognized app" for Trusted Signing-signed installer under AOC CA 04 after the June 2026 reputation fix
We sign our Windows desktop installer with Azure Trusted Signing (Artifact Signing). The Authenticode signature is valid and timestamped, chaining through Microsoft ID Verified CS AOC CA 04 -> Microsoft ID Verified Code Signing PCA 2021 -> Microsoft Identity Verification Root CA 2020, subject CN=Loreo Inc., O=Loreo Inc., L=Tiburon, S=California, C=US. Despite this, Microsoft Defender SmartScreen shows "Windows protected your PC / unrecognized app" when users run the installer.
Example release: Loreo_1.9.41_x64-setup.exe, SHA-256 75e184b345b0ac20dfe1cb67247b28be44881121690f05e61153e6492d822616, leaf certificate serial 3300049FA866034CACD7038C07000000049FA8 (issued 2026-08-10), published at https://github.com/farrokh/loreo-releases/releases/download/v1.9.41/Loreo_1.9.41_x64-setup.exe (product: https://getloreo.com).
We are aware of the March 26, 2026 intermediate CA rotation (EOC CA 02 -> EOC/AOC CA 03/04) that dropped SmartScreen publisher reputation for Trusted Signing customers, and of the June 18, 2026 confirmation that reputation propagation for the new intermediate CAs was corrected with no changes required to the signing account, profile, or workflow. Our releases are signed under AOC CA 04 after that date and still trigger the warning.
What we have already done: submitted the signed installer to Microsoft Security Intelligence as a software developer (submission ID 9cf50c70-298e-4868-b2f1-861387a3068d, 2026-08-18, currently Pending). We have kept the same signing identity and profile throughout.
Questions:
- Can you verify that SmartScreen publisher reputation is propagating correctly for our Trusted Signing durable identity under AOC CA 04?
- Is any pre-rotation publisher reputation carry-over still missing for publishers like us, and is there anything a publisher should do beyond the WDSI submission?
- Is there an expected timeline for a new-ish Trusted Signing publisher with consistent releases to stop seeing the prompt?