A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
- The provided documentation does not state any minimum organization age or a three-year business history requirement for Public Trust organization identity validation in the UK. The documented prerequisites for Public Trust certificates list supported geographies, and the UK is included for organizations. For public identity validation, the documented requirement is that public records for the legal business entity are up to date.
- Documented failure and delay categories include:
- Missed or expired email verification for the primary email address. The verification link expires after seven days, and if it expires, a new identity validation request is required.
- Email delivery or filtering issues. The mailbox must accept messages and links from external senders. Junk/spam filtering, firewall rules, or email security policies can block the message.
- Insufficient validation evidence. If more documentation is required, the request status changes to Action Required and documents can be uploaded in the Azure portal. There are three attempts for documentation upload.
- Public records not current or not matching submitted details. For quicker onboarding, public records for the legal business entity should be up to date, and the submitted information must be correct.
- Primary email mismatch across requests. If identity validation already exists with one primary email address and another request is needed with a different primary email address, support must be contacted to continue onboarding.
- Validation team unable to determine legitimacy from submitted information. The FAQ states that even with additional documentation, onboarding can fail if the information cannot be validated.
- The documented escalation path is to create a support ticket in the Azure portal. Microsoft Q&A with the artifact-signing tag is also listed for assistance. For cases where another identity validation is needed for the same organization but with a different primary email address, support is specifically required to continue onboarding.
- Yes. Avoid creating additional in-progress requests for the same entity unless a documented retry condition applies. The FAQ explicitly states that creating more identity validation requests for the same entity that is already in progress does not help, and requests cannot be expedited. A new request is specifically required only in cases such as:
- the email verification link expired
- the verification email was not received and cannot be recovered
- email verification failed
- renewal validation errors occur or the identity validation is expired
- The documented evidence and matching requirements include:
- Official business documents such as a business registration form, business charter, or articles of incorporation that list the company name and address exactly as provided in the identity validation request.
- Domain registration or domain renewal invoice that lists the entity and contact name and all domains included in the request.
- Any additional documents requested must be current: issued within the previous 12 months, and if they have an expiration date, that date must be at least two months in the future.
- The website URL must belong to the legal business entity.
- The primary email must be a monitored address on a domain owned by the legal business entity.
- The secondary email must be different from the primary email, and for organizations its domain must match the primary email domain.
- The named representative must use the exact first and last name as shown on the government-issued identification document used for the individual identity validation step.
Additional practical guidance from the documented flow:
- Check the request status in Azure portal under the Artifact Signing account > Identity validations.
- If status changes to Action Required, follow the portal instructions and upload the requested documents.
- Processing time is documented as 1 to 20 business days, and longer if more documentation is needed.
- If the verification email was never received, check junk/spam, confirm external senders and links are allowed, and have the email administrator verify that filtering policies are not blocking the message.