A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.
For certificate signing of a Windows app via Azure Artifact Signing, ID validation must succeed before certificates can be issued. When identity validation fails, the service does not provide a detailed public reason, but there are specific common causes and remediation steps.
To understand and fix the failure:
- Check for missed email verification
After submitting an identity validation request, an email with a verification link is sent to the primary email address provided. The link expires after seven days. If the link was missed or not selected in time, the validation fails. In that case, create a new identity validation request and complete the email verification promptly. - Confirm email delivery and filtering
If the verification email was never received:- Check Junk/Spam folders.
- Ensure the email address can receive messages from external senders and that messages containing links are not being filtered or blocked.
- Ask the email administrator to confirm that firewall, security, or email filtering policies are not blocking the message. If the email still cannot be located, delete the current identity validation request and submit a new one.
- Understand organization identity validation failure
If validation fails even after email verification, the Microsoft validation team was unable to confirm the organization based on the information and documents provided. Even if additional documentation is requested and submitted, if the information cannot be validated, onboarding to Artifact Signing cannot proceed. In that scenario:- Review the organization details and documents used (legal name, address, registration documents) to ensure they are accurate and consistent.
- If all three attempts with extra documents have been exhausted and validation still fails, the guidance is to delete the Artifact Signing account to avoid being billed for unused resources.
- Name formatting issues on ID vs. account
ID validation can fail if the name on the ID does not match the name in the billing or account profile (for example, due to a middle name mismatch). A practical workaround reported by users is:- Do not use the middle name field in the billing account.
- Instead, change the first name field to include the middle name with a space (for example,
First Middle). This can help align the account name with the ID and allow validation to pass.
- If further assistance is needed
For questions specifically about identity validation in Artifact Signing, use Azure Support or Microsoft Q&A (with theartifact-signingtag). Identity validation requests cannot be expedited, and creating multiple parallel requests for the same entity does not help.
Following these steps—verifying email completion, ensuring account name matches the ID (including middle name handling), and resubmitting the identity validation request—provides the best path to getting validation approved so certificates can be issued for signing the Windows app.
References: