Artifact Signing organization identity validation shows "You need permission" despite matching primary email and confirmed Azure roles

리얼링크 인증 담당 0 Reputation points
2026-10-07T10:16:33.6766667+00:00

I am completing Public organization identity validation for a South Korean business in an existing Azure Artifact Signing account in Korea Central.

The existing request is displayed as Action Required in the validation list. Its details pane displays In Progress and a "Please complete your verification here" link. The current link redirects to credentials.microsoft.com/verify/noPermission before the ID-verification workflow opens.

The primary email stored in the validation request exactly matches the Microsoft account used to sign in. We tested the current link after signing out the administrator's account. The error page explicitly shows the matching primary email, but still says "You need permission" and shows the personal Microsoft-account tenant rather than the Azure resource tenant.

The primary-email Microsoft account is a personal Microsoft account invited as an Entra guest into the resource tenant. The guest invitation has been accepted. The Azure role-assignment list was checked directly and confirms:

  • Reader at subscription scope.
  • Artifact Signing Identity Verifier on the signing account.

The credentials portal offers Sign out but no tenant or organization selector. Repeated sign-outs, guest redemption, and tenant-specific Azure portal sign-in have not resolved the access error. We have not deleted or recreated the existing identity-validation request, created another tenant, moved the subscription, or created a certificate profile.

The "Contact us to request access" button opens the Windows mail application, which is not configured. The alternative Azure technical-support workflow requires a paid support plan at the Additional information step, so no technical ticket has been submitted.

Could a Microsoft Artifact Signing moderator advise the supported account and authentication flow for this organization representative verification? In particular:

  1. Is a personal Microsoft account invited as an Entra guest supported when it exactly matches the request's primary email?
  2. Can the authorized contact/account mapping for the existing validation gateway request be checked or repaired?
  3. What is the correct identity-validation onboarding support route if Azure technical support requires a paid support plan?

I can provide the identity-validation ID, gateway request ID, subscription ID, and tenant IDs through an official private support channel. I have intentionally omitted those identifiers, contact email addresses, legal-entity names, authentication tokens, and identity documents from this public question.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.