We recently created an Azure Artifact Signing account and submitted a Public organization identity validation request.
The request was successfully submitted and initially showed "In Progress." We then received an email titled "Action required: Complete your Artifact Signing identity validation."
However, clicking the verification link redirects to credentials.microsoft.com/verify/noPermission with the following error:
"You need permission. To access this page, you must be logged in as an authorized user of the Entra Azure tenant which was used for the enrollment application or change."
What we've confirmed:
- Our Azure subscription and Artifact Signing account were created successfully.
The organization validation now shows "Action Required" in Azure.
The account has the Owner role on the Azure subscription.
The Artifact Signing Identity Verifier role has been assigned at the signing account scope.
The verification page authenticates our account against a different Entra tenant than the directory associated with the Azure subscription and signing resource.
We've tried opening the verification link in a fresh Incognito session, but receive the same error.
The Microsoft account is also represented as a guest user in the Azure resource tenant.
Questions:
How can we complete identity verification using the correct Entra tenant?
Does the use of a guest account or an account associated with multiple tenants require a different authentication process?
Can Microsoft correct the verification link or issue a new one without requiring us to recreate the existing organization validation request?
We're preparing to launch publicly distributed Windows software on October 18, so resolving the identity verification promptly would be greatly appreciated.
Thank you for any guidance!We recently created an Azure Artifact Signing account and submitted a Public organization identity validation request.
The request was successfully submitted and initially showed "In Progress." We then received an email titled "Action required: Complete your Artifact Signing identity validation."
However, clicking the verification link redirects to credentials.microsoft.com/verify/noPermission with the following error:
"You need permission. To access this page, you must be logged in as an authorized user of the Entra Azure tenant which was used for the enrollment application or change."
What we've confirmed:
Our Azure subscription and Artifact Signing account were created successfully.
The organization validation now shows "Action Required" in Azure.
The account has the Owner role on the Azure subscription.
The Artifact Signing Identity Verifier role has been assigned at the signing account scope.
The verification page authenticates our account against a different Entra tenant than the directory associated with the Azure subscription and signing resource.
We've tried opening the verification link in a fresh Incognito session, but receive the same error.
The Microsoft account is also represented as a guest user in the Azure resource tenant.
Questions:
How can we complete identity verification using the correct Entra tenant?
Does the use of a guest account or an account associated with multiple tenants require a different authentication process?
Can Microsoft correct the verification link or issue a new one without requiring us to recreate the existing organization validation request?
We're preparing to launch publicly distributed Windows software on October 18, so resolving the identity verification promptly would be greatly appreciated.
Thank you for any guidance!