Artifact Signing Account is giving SmartScreen at each release since march this year.

Dennis Lerche 10 Reputation points
2026-06-24T18:53:22.29+00:00

Hi

We have been using the Azure Artifiact Signing for our releases for well over a year without any problems. However, since March it seems we are having problems like many other with our releases triggering the SmartScreen. Monday the latest where a hotfix was made for a release in May. It seems like the reputation has to be build up after each release (which uses a new certificate as they are only valid for some days), this poses a major problem for us, as our enterprise customers has strict security policies so they cannot do a "run anyways".

The result for the signtool verify /pa /v for the exe in question is shown below.

Verifying: ------
Signature Index: 0 (Primary Signature)
Hash of file (sha256): 16FC5EFD61BCE1A7715372AEF51D8FF84A205D33FA90240B0DBC93C28D7B8A57
Signing Certificate Chain:
    Issued to: Microsoft Identity Verification Root Certificate Authority 2020
    Issued by: Microsoft Identity Verification Root Certificate Authority 2020
    Expires:   Sun Apr 16 20:44:40 2045
    SHA1 hash: F40042E2E5F7E8EF8189FED15519AECE42C3BFA2
        Issued to: Microsoft ID Verified Code Signing PCA 2021
        Issued by: Microsoft Identity Verification Root Certificate Authority 2020
        Expires:   Tue Apr 01 22:15:20 2036
        SHA1 hash: 8E750F459DAF9A79D6370DB747AD2226866AD818
            Issued to: Microsoft ID Verified CS AOC CA 04
            Issued by: Microsoft ID Verified Code Signing PCA 2021
            Expires:   Wed Mar 26 20:11:29 2031
            SHA1 hash: 4C07413E5DA89A259A127E1D76F792AF239CD9D9
                Issued to: Suzlon Energy A/S
                Issued by: Microsoft ID Verified CS AOC CA 04
                Expires:   Wed Jun 24 07:15:13 2026
                SHA1 hash: 4BEE2295F4D823618C9FABB1BA8E5E6563D6C74E
The signature is timestamped: Mon Jun 22 16:32:19 2026
Timestamp Verified by:
    Issued to: Microsoft Identity Verification Root Certificate Authority 2020
    Issued by: Microsoft Identity Verification Root Certificate Authority 2020
    Expires:   Sun Apr 16 20:44:40 2045
    SHA1 hash: F40042E2E5F7E8EF8189FED15519AECE42C3BFA2
        Issued to: Microsoft Public RSA Timestamping CA 2020
        Issued by: Microsoft Identity Verification Root Certificate Authority 2020
        Expires:   Mon Nov 19 22:42:31 2035
        SHA1 hash: 27F0ABAC2877BA255F62B389B43FF539A0FB598E
            Issued to: Microsoft Public RSA Time Stamping Authority
            Issued by: Microsoft Public RSA Timestamping CA 2020
            Expires:   Thu Jan 07 20:59:03 2027
            SHA1 hash: 7587C337A84BB5BF291A58191AD102FFCDCF36BF
Successfully verified: -------
Number of files successfully Verified: 1
Number of warnings: 0
Number of errors: 0

I also submitted the file for scanning, but it didn't help the SmartScreen is still being shown. We cannot deploy this application to the Microsoft Store to avoid this. What else can be done, besides discarding the use of Azure Artifact Signing and reverting back to buying a certificate each year from a vendor ?

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.