Artifact Signing organization verification: "You need permission" due to Entra tenant mismatch

Corridor Digital 0 Reputation points
2026-10-08T23:59:34.7033333+00:00

We recently created an Azure Artifact Signing account and submitted a Public organization identity validation request.

The request was successfully submitted and initially showed "In Progress." We then received an email titled "Action required: Complete your Artifact Signing identity validation."

However, clicking the verification link redirects to credentials.microsoft.com/verify/noPermission with the following error:

"You need permission. To access this page, you must be logged in as an authorized user of the Entra Azure tenant which was used for the enrollment application or change."

What we've confirmed:

  • Our Azure subscription and Artifact Signing account were created successfully.

The organization validation now shows "Action Required" in Azure.

The account has the Owner role on the Azure subscription.

The Artifact Signing Identity Verifier role has been assigned at the signing account scope.

The verification page authenticates our account against a different Entra tenant than the directory associated with the Azure subscription and signing resource.

We've tried opening the verification link in a fresh Incognito session, but receive the same error.

The Microsoft account is also represented as a guest user in the Azure resource tenant.

Questions:

How can we complete identity verification using the correct Entra tenant?

Does the use of a guest account or an account associated with multiple tenants require a different authentication process?

Can Microsoft correct the verification link or issue a new one without requiring us to recreate the existing organization validation request?

We're preparing to launch publicly distributed Windows software on October 18, so resolving the identity verification promptly would be greatly appreciated.

Thank you for any guidance!We recently created an Azure Artifact Signing account and submitted a Public organization identity validation request.

The request was successfully submitted and initially showed "In Progress." We then received an email titled "Action required: Complete your Artifact Signing identity validation."

However, clicking the verification link redirects to credentials.microsoft.com/verify/noPermission with the following error:

"You need permission. To access this page, you must be logged in as an authorized user of the Entra Azure tenant which was used for the enrollment application or change."

What we've confirmed:

Our Azure subscription and Artifact Signing account were created successfully.

The organization validation now shows "Action Required" in Azure.

The account has the Owner role on the Azure subscription.

The Artifact Signing Identity Verifier role has been assigned at the signing account scope.

The verification page authenticates our account against a different Entra tenant than the directory associated with the Azure subscription and signing resource.

We've tried opening the verification link in a fresh Incognito session, but receive the same error.

The Microsoft account is also represented as a guest user in the Azure resource tenant.

Questions:

How can we complete identity verification using the correct Entra tenant?

Does the use of a guest account or an account associated with multiple tenants require a different authentication process?

Can Microsoft correct the verification link or issue a new one without requiring us to recreate the existing organization validation request?

We're preparing to launch publicly distributed Windows software on October 18, so resolving the identity verification promptly would be greatly appreciated.

Thank you for any guidance!

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)


2 answers

Sort by: Most helpful
  1. Meha-MSFT 2,460 Reputation points Microsoft Employee Moderator
    2026-10-09T22:06:18.34+00:00

    we are looking into this, thank you for this detail - "The verification page authenticates our account against a different Entra tenant than the directory associated with the Azure subscription and signing resource.

    We've tried opening the verification link in a fresh Incognito session, but receive the same error.

    The Microsoft account is also represented as a guest user in the Azure resource tenant."

    Was this answer helpful?

    0 comments No comments

  2. Rukshan edirisinghe 1,320 Reputation points
    2026-10-09T02:52:15.1466667+00:00

    Hi @Corridor Digital

    Your own diagnosis matches what the error says. The verification page checks your sign-in against the tenant that holds the Artifact Signing account, and a guest Microsoft account authenticates in its own home tenant, so it gets rejected even with the right roles. I couldn't find any Microsoft doc saying guest accounts are supported for this step.

    What I'd do with the time you have:

    1. In the resource tenant, use (or create) a regular member user, not a guest, whose email is on your company's domain. The quickstart asks for the primary email to be a monitored address on a domain owned by the business anyway.
    2. Give that user the Artifact Signing Identity Verifier role on the signing account.
    3. Open the verification link from a fresh private window while signed in only as that member user.
    4. If the request is tied to the guest's email and the link still fails, open a support request and ask them to update the primary contact on the existing validation. The FAQ says a second validation with a different primary email has to go through support, so this avoids starting over.

    Is the primary email on the validation request your company domain, or the personal Microsoft account that's the guest?

    If this resolved your issue, please consider accepting it as the answer. If the link still says you need permission, let me know and I'll be happy to keep helping.

    Reference:

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.