A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
- A specific failure reason is generally not exposed in the Azure portal for Public identity validation. The documented guidance only states that if validation fails, the Microsoft validation team could not determine the request from the information provided. The portal does show status changes such as In Progress, Action Required, Completed, and Failed, and status updates are also sent by email. If the failure was caused by missing the email verification link sent to the Primary Email, that link expires after seven days, and a new identity validation request must be created.
- Public identity validation requirements and common rejection causes are:
- Correct role assignment: the account used to create the request must have the Artifact Signing Identity Verifier role.
- Correct identity type: Public identity validation is only for these certificate profile types: Public Trust, Public Trust Test, and VBS Enclave.
- Organization details must match the legal business entity:
- Organization Name must be the legal business entity for public validation.
- Website URL must belong to that legal business entity.
- Primary Email must be a monitored mailbox on a domain owned by the legal business entity, must accept links from external senders, and the verification link expires in seven days.
- Secondary Email must be different from the primary email, and for organizations the domain must match the primary email domain.
- Business address must be the legal business entity’s address.
- First Name and Last Name must exactly match the representative’s government-issued ID.
- Accuracy matters: for public identity validation, if changes are needed after creation, a new identity validation request is required.
- Public records should be current for faster onboarding.
- Additional documentation may be requested. If so:
- documents are uploaded in the Azure portal,
- there are three attempts,
- submitted documents must be issued within the previous 12 months,
- if they have an expiration date, it must be at least two months in the future,
- official business documents should list the company name and address as provided in the request,
- domain registration or renewal documentation should list the entity, contact name, and all domains mentioned in the request.
- Processing time is documented as 1 to 20 business days, possibly longer if more documentation is required.
- Correct remediation and resubmission path:
- Check whether the Primary Email received the verification email and whether the link was used within seven days. If not, create a new Public identity validation request.
- Review every submitted field against the organization’s legal records and public records. For Public validation, the documentation explicitly says that if changes are needed after creation, a new request is required.
- If the request went to Action Required, respond through the Azure portal with the requested documentation. Ensure the documents are current and match the submitted legal entity details exactly.
- If validation failed for reasons other than missed email verification, the documented guidance says the validation team could not determine the request from the information provided. If repeated failures continue, use the documented support path by creating a support ticket in the Azure portal.
- If another identity validation already exists for the same organization but with a different primary email address, the documented guidance is to contact support to continue onboarding.
For the specific question about portal, activity log, or CLI/API visibility: the available guidance only confirms status tracking in the Azure portal and by email. It does not document a CLI or API method to retrieve a detailed failure reason for Public identity validation. It also explicitly states that identity validation itself can be completed only in the Azure portal, not through Azure CLI.
References:
- Quickstart: Set up Artifact Signing
- Artifact Signing FAQ
- Artifact Signing resources and roles
- Trusted Signing - Identity Validation failed - Microsoft Q&A I have submitted a Trusted Signing Identity validation and it failed without any information two days after. How can I see more information?
- Trusted Signing identity validation status failed - Microsoft Q&A I have tried to do identity validation for my company but it failed (identity validation id: 43fe566e-c45b-497e-805b-338ca315664b) .
- Identity validation request failed. - Microsoft Q&A To whom it may concern,