Artifact Signing Identity Verifier role is effective, but Identity validations shows “Unable to fetch data”

Hiren Desai 0 Reputation points
2026-08-31T21:25:40.2933333+00:00

I am setting up Azure Artifact Signing organisation identity validation. The Identity validations page keeps the “New identity” button disabled and displays:

“Please ensure you have the ‘Artifact Signing Identity Verifier’ role assigned.”

“Unable to fetch data.”

Access Control (IAM) and “View my access” confirm that:

The built-in Artifact Signing Identity Verifier role is assigned directly to my user at the Artifact Signing account scope.

I have inherited access at the subscription level.

There are no deny assignments.

The Artifact Signing account is in East US.

The required tsvettinggateway.portal.codesigning.azure.net endpoint is reachable directly.

The organisation is based in New Zealand, which Microsoft lists as a supported country for Public Trust organisation identity validation.

I have refreshed the page and signed out and back in, but the problem remains.

Could Microsoft please confirm whether this is a backend role-mapping or Identity Validation API problem and advise how to restore access without recreating the account?

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)


1 answer

Sort by: Newest
  1. Mohammad Wasi Haider 165 Reputation points
    2026-09-01T12:12:49.88+00:00

    Hi Hiren,

    Based on what you have already verified, this does not look like a normal RBAC configuration issue. The Artifact Signing Identity Verifier role is the correct built-in role for managing identity validation, and New Zealand is supported for Public Trust signing.

    Since IAM recognizes the assignment but the Identity validations blade still returns “Unable to fetch data” and keeps “New identity” disabled, I would treat this as an Artifact Signing portal/backend validation issue rather than recreate the account.

    Please open an Azure support request for Artifact Signing and include the Artifact Signing account resource ID, tenant ID, UTC timestamp of the failure, screenshot, and any correlation/request ID shown in the browser or Activity Log. Microsoft support can check the backend identity-validation request and role evaluation.

    I would not delete or recreate the Artifact Signing account at this stage.

    Thank you, and feel free to respond back for more assistance.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.