My subscription was paused and re-enabled today (18 Sep 2026). Since then, every signing request to my Artifact Signing account (East US, Basic) fails:
Azure.RequestFailedException: Service request failed.
{"operationId":"f48ac4d2-c7da-4859-9a57-82dd8b1b039c","status":"Failed","signature":null,...}
SignTool Error: SignerSign() failed (0x80004005)
Authentication succeeds, and the failure comes at "Submitting digest for signing".
Everything I can check looks okay:
- The subscription is Enabled, with no unpaid invoices.
- Microsoft.CodeSigning is Registered.
- The account provisioning state is Succeeded.
- The identity validation and the certificate profile (PublicTrust) are both Active.
- A new short-lived certificate was issued today, after the re-enable.
- The app registration still has "Artifact Signing Certificate Profile Signer".
The same GitHub Actions pipeline (artifact-signing-action v2.0.0, client 1.0.128) signed successfully on 26 Aug. Nothing has changed except the pause and re-enable.
Has anyone seen the signing service keep refusing after a subscription is reactivated? Is there a way to clear it without a paid support plan?
Other failed operation IDs: 965304d7-000a-40f1-a5a4-924a2aab563f, 108d9cfa-3c16-4d5d-adf8-f2c6061d46f8
Update: I reproduced it outside the pipeline. Calling the data-plane sign API directly (api-version=2023-06-15-preview) from a different machine, with a different identity that holds the Certificate Profile Signer role, returns 202 Accepted, then the operation ends "status":"Failed" with errorResponse: null (operation ID ba9d6fa8-f613-4f0d-80cc-665b4b7b31fa). A fresh CI run later also failed the same way. So the pipeline, the credential and the network are ruled out: the account fails every sign operation, whoever submits it. Could someone from the Artifact Signing team check whether the account is still held after the subscription was re-enabled?