A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
The RBAC roles listed are required to create the identity validation request, but the Face Check failure described is not documented here as being caused by missing Artifact Signing roles. The documented recovery for individual identity validation errors such as FaceCheck fail is to:
- Delete the existing identity validation request.
- Remove the associated Verified ID from the Microsoft Authenticator app.
- Submit a new identity validation request.
- Create a new Verified ID.
- Ensure all information is accurate.
- Complete the verification in an environment with adequate lighting.
For the specific "missing permissions" wording in Authenticator, no separate tenant-level Verified ID or Face Check enablement requirement for Artifact Signing is documented here. Only the Artifact Signing Identity Verifier role is documented as required to create the request.
A few checks from the documented guidance:
- Identity validation can only be completed in the Azure portal, not Azure CLI.
- If the New identity button is dimmed, that indicates the required role is missing.
- For individual identity validation, if the email used in the request differs from the email used to sign in to access the validation link, the process can fail with a permissions-related page access error. Those email addresses must match.
- If Face Check or document matching fails, the documented reset path is to delete the request and remove the Verified ID before retrying.
If the issue continues after a clean retry, the documented assistance path is Azure Support or Microsoft Q&A with the artifact-signing tag.
References: