Additional Microsoft Defender tools and services that provide security across various platforms and environments
Hello @Oleksii ,
You have already followed the correct process. SmartScreen evaluates both the reputation of the individual file hash and the signing certificate/publisher. Therefore, a valid signature and a clean malware scan do not automatically prevent the “unrecognized app” warning. Since unchanged older builds were also affected, it is reasonable to suspect a certificate or publisher-reputation issue, although only Microsoft can confirm this
There is currently no public self-service process to reset publisher reputation or add a developer to a trusted publisher list. Microsoft specifically states that it does not accept requests for a known-list or false-positive-prevention program.
The Microsoft Security Intelligence submission portal is the correct channel, and an Azure subscription is not required. The file should be submitted as a Software developer, with Microsoft Defender SmartScreen selected, exactly as you have done. The initial “No malware detected” result does not necessarily resolve the SmartScreen reputation warning because SmartScreen reputation is separate from Defender Antivirus detection.
The next step is to wait for the final determination. If the warning remains or the final response does not address the wider publisher-level issue, use the developer contact form included with the submission results to request further investigation. Microsoft identifies this as the escalation path when a developer is not satisfied with the final determination
When escalating, include the submission ID, certificate thumbprint and serial number, SHA-256 hashes for the current installer and at least one previously trusted older build, the exact download URL, and the dates when the change was observed. It would also help to state clearly that multiple unchanged files signed with the same certificate were affected at approximately the same time.