Artifact Signing identity validation - Verification fails

softwaremaniac 0 Reputation points
2026-07-22T22:44:40.1+00:00

I'm setting up identity validation for Artifact Signing (individual/company account, EU - Croatia) and it fails at the Face Check step. The portal shows "Face Check failed - we could not verify your identity." In Microsoft Authenticator, the request reports "missing permissions to fulfill this request; failed Face Check liveness."

The portal shows the error on the screenshot above.

What I've already checked:

  • My account holds Artifact Signing Identity Verifier and Owner, so this does not appear to be the missing-role cause seen in other threads.
  • Retried the Face Check in good lighting with a front-facing camera and on a different device.
  • Authenticator is updated; camera and notification permissions are granted to the app.

Questions:

  1. Does the "missing permissions" message point at a tenant-level Verified ID / Face Check capability that must be enabled separately, beyond the RBAC roles above?
  2. Is the correct recovery to delete the identity-validation request, remove the Verified ID from Authenticator, and resubmit — or does that risk locking the request?

Happy to provide the request ID privately.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)


1 answer

Sort by: Most helpful
  1. AI answer

    2026-07-22T22:45:03.46+00:00

    The RBAC roles listed are required to create the identity validation request, but the Face Check failure described is not documented here as being caused by missing Artifact Signing roles. The documented recovery for individual identity validation errors such as FaceCheck fail is to:

    1. Delete the existing identity validation request.
    2. Remove the associated Verified ID from the Microsoft Authenticator app.
    3. Submit a new identity validation request.
    4. Create a new Verified ID.
    5. Ensure all information is accurate.
    6. Complete the verification in an environment with adequate lighting.

    For the specific "missing permissions" wording in Authenticator, no separate tenant-level Verified ID or Face Check enablement requirement for Artifact Signing is documented here. Only the Artifact Signing Identity Verifier role is documented as required to create the request.

    A few checks from the documented guidance:

    • Identity validation can only be completed in the Azure portal, not Azure CLI.
    • If the New identity button is dimmed, that indicates the required role is missing.
    • For individual identity validation, if the email used in the request differs from the email used to sign in to access the validation link, the process can fail with a permissions-related page access error. Those email addresses must match.
    • If Face Check or document matching fails, the documented reset path is to delete the request and remove the Verified ID before retrying.

    If the issue continues after a clean retry, the documented assistance path is Azure Support or Microsoft Q&A with the artifact-signing tag.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.