Azure Artifact Signing organization identity validation failed twice with no visible reason

lloyds 5 Reputation points
2026-09-20T09:27:18.84+00:00

We are trying to onboard an organization for Azure Artifact Signing Public Trust code signing.

The organization identity validation failed twice in the Azure portal, but the portal only shows "Failed" and does not

provide a specific reason or remediation guidance.

Context:

  • Service: Azure Artifact Signing / Microsoft.CodeSigning
  • Identity type: Organization / Public
  • Country/region: United Kingdom
  • The primary and secondary email addresses are on the organization's own domain
  • The website/domain is controlled by the organization
  • The organization details submitted match the public company registry records

The Azure portal support flow showed recommended articles about Azure DevOps XML/process template validation, which

seems unrelated to Artifact Signing identity validation.

We also saw conflicting guidance about whether Azure Artifact Signing Public Trust organization validation requires at

least three years of verifiable business history. The current Artifact Signing documentation does not appear to list a

minimum organization age requirement.

Could someone from Microsoft Artifact Signing please clarify:

  1. Does Azure Artifact Signing Public Trust organization identity validation currently require a minimum organization

age or three years of business history for UK organizations?

  1. If not, what are the common backend validation categories that can cause an organization validation to fail with no

visible reason?

  1. Is there a private escalation path for Basic support customers where we can securely provide the subscription ID,

tenant ID, validation IDs, and company documents?

  1. Should we avoid creating another identity validation request until Microsoft confirms the backend failure reason?
  2. What exact evidence is accepted to prove the relationship between the legal entity, the website/domain, and the

authorized representative?

We can provide the subscription ID, tenant ID, validation IDs, company registration documents, domain registration or

renewal invoice, and screenshots privately to verified Microsoft staff if requested.

Please route this question to the Azure Artifact Signing identity validation/onboarding team if possible.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

0 comments No comments

3 answers

Sort by: Oldest
  1. AI answer

    2026-09-20T09:27:49.08+00:00
    1. The provided documentation does not state any minimum organization age or a three-year business history requirement for Public Trust organization identity validation in the UK. The documented prerequisites for Public Trust certificates list supported geographies, and the UK is included for organizations. For public identity validation, the documented requirement is that public records for the legal business entity are up to date.
    2. Documented failure and delay categories include:
      1. Missed or expired email verification for the primary email address. The verification link expires after seven days, and if it expires, a new identity validation request is required.
      2. Email delivery or filtering issues. The mailbox must accept messages and links from external senders. Junk/spam filtering, firewall rules, or email security policies can block the message.
      3. Insufficient validation evidence. If more documentation is required, the request status changes to Action Required and documents can be uploaded in the Azure portal. There are three attempts for documentation upload.
      4. Public records not current or not matching submitted details. For quicker onboarding, public records for the legal business entity should be up to date, and the submitted information must be correct.
      5. Primary email mismatch across requests. If identity validation already exists with one primary email address and another request is needed with a different primary email address, support must be contacted to continue onboarding.
      6. Validation team unable to determine legitimacy from submitted information. The FAQ states that even with additional documentation, onboarding can fail if the information cannot be validated.
      The documentation also states that the portal may not expose the backend reason, and support is the documented path for investigation.
    3. The documented escalation path is to create a support ticket in the Azure portal. Microsoft Q&A with the artifact-signing tag is also listed for assistance. For cases where another identity validation is needed for the same organization but with a different primary email address, support is specifically required to continue onboarding.
    4. Yes. Avoid creating additional in-progress requests for the same entity unless a documented retry condition applies. The FAQ explicitly states that creating more identity validation requests for the same entity that is already in progress does not help, and requests cannot be expedited. A new request is specifically required only in cases such as:
      • the email verification link expired
      • the verification email was not received and cannot be recovered
      • email verification failed
      • renewal validation errors occur or the identity validation is expired
    5. The documented evidence and matching requirements include:
      • Official business documents such as a business registration form, business charter, or articles of incorporation that list the company name and address exactly as provided in the identity validation request.
      • Domain registration or domain renewal invoice that lists the entity and contact name and all domains included in the request.
      • Any additional documents requested must be current: issued within the previous 12 months, and if they have an expiration date, that date must be at least two months in the future.
      • The website URL must belong to the legal business entity.
      • The primary email must be a monitored address on a domain owned by the legal business entity.
      • The secondary email must be different from the primary email, and for organizations its domain must match the primary email domain.
      • The named representative must use the exact first and last name as shown on the government-issued identification document used for the individual identity validation step.

    Additional practical guidance from the documented flow:

    • Check the request status in Azure portal under the Artifact Signing account > Identity validations.
    • If status changes to Action Required, follow the portal instructions and upload the requested documents.
    • Processing time is documented as 1 to 20 business days, and longer if more documentation is needed.
    • If the verification email was never received, check junk/spam, confirm external senders and links are allowed, and have the email administrator verify that filtering policies are not blocking the message.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. lloyds 5 Reputation points
    2026-09-20T09:30:56.9233333+00:00

    Thank you, but this appears to be a documentation summary rather than a backend review.

    Could a Microsoft Artifact Signing moderator or engineer confirm whether there is any private escalation path for Basic

    support customers? We need a Microsoft-owned private channel where we can provide the subscription ID, tenant ID,

    validation IDs, screenshots, and company/domain evidence securely.

    We do not need expedited processing. We only need to know which validation category failed before submitting another

    identity validation request.

    Was this answer helpful?

    0 comments No comments

  3. Rukshan edirisinghe 910 Reputation points
    2026-09-20T13:02:25.66+00:00

    Hi @lloyds

    Community contributor here, not Microsoft staff. Short answers:

    1. Yes, treat the 3-year rule as real. It's not in the docs, but Microsoft moderators have confirmed it repeatedly in 2026, including for a UK Ltd: Public Trust needs 3+ years of verifiable operating history (Companies House, tax records, D-U-N-S), and it's a hard threshold. Check your incorporation date first. If under 3 years, that's your answer, and no documents fix it. Options: Private Trust (no age rule) or wait it out, and delete the account meanwhile so it doesn't bill monthly.
    2. Common hidden failure reasons: under 3 years old, entity not findable in third-party sources (get a D-U-N-S), name/address not matching the registry exactly, or whois privacy masking hiding the link between domain and entity.
    3. Private path on Basic: there's no dedicated channel. Secure document upload only exists inside an Azure support case. If the case gets auto-bounced as "needs paid support", reply asking for reclassification as an identity verification issue. Guaranteed route: add a Developer plan (~$29) for one month, file the ticket with your validation IDs, cancel after. Keep this thread open too, the Artifact Signing team does pick cases up from this tag, and they'll take IDs by private message, never post them here.
    4. Yes, stop submitting. Attempts are limited, repeat requests don't change the outcome, and a third try fails the same gate. Confirm the reason first.
    5. Accepted evidence: registration documents issued within the last 12 months matching the legal entity exactly, D-U-N-S number, domain invoice in the company's name, public whois showing the org, and the representative using an email on the company domain.

    Reference: https://learn.microsoft.com/en-us/azure/artifact-signing/quickstart

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.