Azure Artifact Signing Public Trust returns HTTP 403 Forbidden when submitting digest

Sandra Wolff 0 Reputation points
2026-09-18T02:30:53.3333333+00:00

(Yes, I work with an AI, and I just asked it to concisely put all this together. I just want to be able to sign my own apps that I develop in Visual Studio, as a way of claiming my work.)


I am unable to sign a Windows EXE using Azure Artifact Signing Public Trust. The signing client successfully reaches the Artifact Signing service and begins submitting the digest, but the service returns HTTP 403 Forbidden.

**Configuration**

- Artifact Signing account: `SandraWolffCodeSigning`

- Certificate profile: `SandraWolffPublicSigning`

- Profile type: Public Trust

- Region: West US

- Endpoint: `https://wus.codesigning.azure.net`

- Certificate profile status: Active

- Identity validation: Completed

- `Microsoft.CodeSigning` resource provider: Registered

**RBAC**

The Azure identity performing the signing has:

- `Artifact Signing Certificate Profile Signer`

- `Artifact Signing Identity Verifier`

Both role assignments are on the `SandraWolffCodeSigning` Artifact Signing account scope. I verified through Azure CLI that the authenticated Azure user is the same identity to which these roles are assigned.

**Signing methods tested**

I initially tested with Microsoft's Artifact Signing Dlib and Windows SDK SignTool. I then reproduced the problem using the Microsoft `ArtifactSigning` PowerShell module version `0.1.20` and `Invoke-ArtifactSigning`.

The PowerShell module successfully loads, finds the EXE, invokes the Artifact Signing client, and reaches the Artifact Signing service. The failure occurs specifically at:

`Submitting digest for signing...`

The resulting exception is:

`Azure.RequestFailedException: Service request failed.` `Status: 403 (Forbidden)`

followed by:

`SignerSign() failed. (-2147467259/0x80004005)`

The failed request occurred at approximately **2026-09-18 02:01:59 UTC**.

**Troubleshooting already completed**

I have verified:

- Correct Artifact Signing account and certificate profile names

- Correct West US Artifact Signing endpoint

- Public Trust certificate profile is Active

- Identity validation is Completed

- `Microsoft.CodeSigning` is Registered

- `Artifact Signing Certificate Profile Signer` is assigned to the authenticated signing identity at the Artifact Signing account scope

- Current Windows SDK SignTool installed

- Current Artifact Signing client/Dlib installed

- .NET 8 runtime installed

- Required Visual C++ x64 runtime installed

- Azure CLI authentication and subscription selection verified

- The failure is reproducible through Microsoft's `Invoke-ArtifactSigning` PowerShell integration

Since the client reaches the Artifact Signing service and the service itself returns HTTP 403 despite the above configuration, this appears potentially to be a service-side authorization/provisioning issue.

My Azure subscription does not include paid technical support. Could a Microsoft Artifact Signing engineer or moderator please advise why the signing service is returning 403 or provide an appropriate escalation path? If server-side logs can be checked, the failed request timestamp above may help identify the request.I am unable to sign a Windows EXE using Azure Artifact Signing Public Trust. The signing client successfully reaches the Artifact Signing service and begins submitting the digest, but the service returns HTTP 403 Forbidden.

**Configuration**

-  Artifact Signing account: `SandraWolffCodeSigning` 

-  Certificate profile: `SandraWolffPublicSigning` 

-  Profile type: Public Trust 

-  Region: West US 

-  Endpoint: `https://wus.codesigning.azure.net` 

-  Certificate profile status: Active 

-  Identity validation: Completed 

- `Microsoft.CodeSigning` resource provider: Registered 

**RBAC**

The Azure identity performing the signing has:

- `Artifact Signing Certificate Profile Signer` 

- `Artifact Signing Identity Verifier` 

Both role assignments are on the `SandraWolffCodeSigning` Artifact Signing account scope. I verified through Azure CLI that the authenticated Azure user is the same identity to which these roles are assigned.

**Signing methods tested**

I initially tested with Microsoft's Artifact Signing Dlib and Windows SDK SignTool. I then reproduced the problem using the Microsoft `ArtifactSigning` PowerShell module version `0.1.20` and `Invoke-ArtifactSigning`.

The PowerShell module successfully loads, finds the EXE, invokes the Artifact Signing client, and reaches the Artifact Signing service. The failure occurs specifically at:

`Submitting digest for signing...`

The resulting exception is:

`Azure.RequestFailedException: Service request failed.`  
 `Status: 403 (Forbidden)`

followed by:

`SignerSign() failed. (-2147467259/0x80004005)`

The failed request occurred at approximately **2026-09-18 02:01:59 UTC**.

**Troubleshooting already completed**

I have verified:

-  Correct Artifact Signing account and certificate profile names 

-  Correct West US Artifact Signing endpoint 

-  Public Trust certificate profile is Active 

-  Identity validation is Completed 

- `Microsoft.CodeSigning` is Registered 

- `Artifact Signing Certificate Profile Signer` is assigned to the authenticated signing identity at the Artifact Signing account scope 

-  Current Windows SDK SignTool installed 

-  Current Artifact Signing client/Dlib installed 

-  .NET 8 runtime installed 

-  Required Visual C++ x64 runtime installed 

-  Azure CLI authentication and subscription selection verified 

-  The failure is reproducible through Microsoft's `Invoke-ArtifactSigning` PowerShell integration 

Since the client reaches the Artifact Signing service and the service itself returns HTTP 403 despite the above configuration, this appears potentially to be a service-side authorization/provisioning issue.

My Azure subscription does not include paid technical support. Could a Microsoft Artifact Signing engineer or moderator please advise why the signing service is returning 403 or provide an appropriate escalation path? If server-side logs can be checked, the failed request timestamp above may help identify the request.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)


1 answer

Sort by: Oldest
  1. AI answer

    2026-09-18T02:31:10.5466667+00:00

    For HTTP 403 from Artifact Signing, the supported checks are these:

    1. Verify the signing identity has Artifact Signing Certificate Profile Signer.
    2. Verify the Artifact Signing account name and certificate profile name in metadata.json exactly match the Azure resource names.
    3. Verify the identity validation status is Completed.
    4. Verify the certificate profile status is Active.
    5. Verify the dlib and dlib path.
    6. Verify the .NET version, dlib version, and Windows SDK version are compatible.
    7. Install the Microsoft Visual C++ Redistributable (x64).
    8. Verify the machine can reach the Artifact Signing endpoint; if needed, try the same signing operation from a different VM or computer because 403 can indicate a network issue.
    9. For authentication-chain issues, exclude unwanted credentials in the manifest/JSON. A documented mitigation for Azure authentication and a moderator-recommended fix for 403 cases is to add ExcludeCredentials entries so the client does not pick the wrong cached identity.

    Since the same 403 occurs with both SignTool+dlib and Invoke-ArtifactSigning, and the failure happens at Submitting digest for signing..., that narrows the issue to service authorization, identity selection, endpoint access, or profile/account state rather than the EXE itself.

    A focused next pass is:

    1. In the signing JSON, add ExcludeCredentials to eliminate cached or unintended identities, especially if multiple Azure sign-in methods exist on the machine.
    2. Reconfirm the exact Artifact Signing account name is the resource name, not a user name or app registration name.
    3. Reconfirm the signing identity has the Artifact Signing Certificate Profile Signer role on the Artifact Signing account.
    4. Test from a different machine or VM to rule out local network or endpoint-access issues.
    5. If using service principal with certificate-based authentication, verify the required environment variables.

    If the issue is specifically a wrong credential being selected, excluding credentials such as EnvironmentCredential, ManagedIdentityCredential, SharedTokenCacheCredential, VisualStudioCredential, VisualStudioCodeCredential, AzurePowerShellCredential, and AzureDeveloperCliCredential has resolved 403 cases.

    Also verify the local tooling prerequisites because silent or misleading failures can occur when dependencies are missing:

    • Use the matching x64 SignTool with the corresponding x64 Azure.CodeSigning.Dlib.dll.
    • Use the recommended Windows SDK version.
    • Ensure x64 .NET 8 or later is installed.
    • Ensure the VC++ x64 redistributable is installed.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.