A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
The portal and documentation do not expose backend failure reasons for a specific Identity Validation ID, and backend lookups cannot be performed. Only the behaviors and options documented for Artifact Signing identity validation can be described.
Based on the documented behavior:
- How to find the Identity Validation ID and status
- The Identity Validation ID is shown as Id in the details pane when selecting the identity validation on the Identity validations page of the Artifact Signing account.
- Status values such as In Progress, Action Required, Completed, and Failed are surfaced in the portal, but detailed failure reasons are not documented as being exposed.
- Email verification behavior
- For organization identity validation, a verification link is sent to the primary email entered in the request. The link expires after seven days.
- If email verification is missed or the link expires, the guidance is to create a new identity validation request; a new link cannot be resent for the same request.
- If email validation shows Failed and the email was not received, the guidance is to create another identity validation request and ensure the primary email is not a distribution list and can receive external emails with links.
- What happens when identity validation fails
- If identity validation fails and it is not due to a missed email verification, the documentation states that the Microsoft validation team could not make a determination based on the provided information. Even with additional documentation, if the information cannot be validated, onboarding to Artifact Signing cannot proceed.
- In that scenario, the recommendation is to delete the Artifact Signing account to avoid being billed for unused resources.
- In cases where extra documents were required and all three documentation attempts are exhausted, onboarding cannot proceed further.
- Number of attempts and blocking behavior
- When additional documentation is requested, there are three attempts to upload documents that meet the requirements (issued within the last 12 months, with an expiration at least two months in the future, matching the legal entity details, etc.).
- After those three attempts are exhausted, the documentation states that onboarding cannot continue. It does not describe a separate numeric limit on how many full identity validation requests can be created before an organization is “blocked,” only that creating more identity validation requests for the same entity that is already in progress does not help and cannot be expedited.
- When identity validation expires or must be recreated
- Identity validation has an expiration date; if it is not renewed before expiration, certificate renewal stops and signing associated with those certificate profiles stops.
- If renewal via the Renew button fails or the identity validation is already Expired, a new identity validation must be created.
- Expected flow and where to get help
- For organization identity validation, the documented flow is:
- Create the organization identity validation request in the Azure portal.
- Status goes to In Progress.
- When Action Required, follow the instructions (including individual identity validation via the link sent to the primary email).
- If more documents are needed, an email is sent and status is Action Required; up to three documentation upload attempts are allowed.
- Final status becomes Completed or Failed.
- Identity validation can only be completed in the Azure portal; it cannot be completed via Azure CLI.
- For assistance beyond what the portal shows, the documentation directs to:
- Open a support ticket in the Azure portal (Azure Support), or
- Use Microsoft Q&A with the artifact-signing tag.
Given this, the documented options for a failed identity validation are:
- Create a new identity validation request if email verification failed or the link was missed/expired.
- If identity validation fails even after providing requested documentation (or after exhausting three documentation attempts), onboarding cannot proceed and the recommendation is to delete the Artifact Signing account to avoid charges.
- For specific case investigation (such as why a given Identity Validation ID failed, whether an email was sent, or which field mismatched), the only documented path is to contact Azure Support or ask on Microsoft Q&A with the
artifact-signingtag so the engineering/support team can review the case.
References: