A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
What is supported by the available documentation:
- SmartScreen reputation is not instant for Azure Artifact Signing, including Public Trust. New files can show SmartScreen warnings until sufficient reputation is built. Microsoft states that Artifact Signing does not provide instant SmartScreen trust, and that reputation accumulates over time based on download volume and behavior.
- For a new publisher, the behavior described is ordinary and expected. A valid signature, RFC 3161 timestamp, and a verified publisher name confirm signing and identity, but they do not by themselves suppress SmartScreen. Microsoft explicitly states that signed files can still show SmartScreen prompts until the file hash or publisher identity has enough reputation.
- The documented guidance is to keep signing releases with a consistent verified identity. Microsoft states that signing consecutive releases with the same publisher/signing identity allows publisher reputation to build over time so later releases can inherit trust, rather than starting from zero each time.
- There is limited published guidance on timing/volume. The only concrete guidance in the provided documentation is that this is expected for new publishers and can take typically several weeks and hundreds of clean installs before sufficient reputation is built.
- If SmartScreen prompts continue, Microsoft recommends submitting the signed file for review through Microsoft Security Intelligence.
What is not supported by the available documentation:
- No published confirmation is provided here about the specific status of reputation propagation for Microsoft ID Verified CS AOC CA 03.
- No published statement is provided here about whether any March 2026 intermediate CA propagation issue is fully restored or still in progress.
- No additional documented action is provided beyond normal distribution, consistent signing identity, and optional submission for review if prompts persist.
Practical answer to the three questions:
- AOC CA 03 restoration status: no supported public statement is available here.
- What to do beyond normal distribution: keep signing every release with the same verified profile/identity; if prompts persist, submit the signed file through Microsoft Security Intelligence for further review.
- Typical time/download volume: Microsoft documents only a broad expectation of several weeks and hundreds of clean installs for new publishers.