A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
Open a private Azure Support case and request repair or reset of the enrollment authorization bound to the existing identity validation request; do not delete it or create another request while Microsoft investigates.
Open the private support case
- Sign in to the Azure portal with an identity that can access the affected subscription.
- Open Help + support using the Azure support blade: https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade
- Select Create a support request and route it to Artifact Signing / identity validation. Microsoft lists Azure Support as the private support channel for Artifact Signing identity-validation assistance.^1^
- State that this is an existing Organization/Public Trust request in Action Required, and ask the Artifact Signing identity-validation or vetting team to:
- Inspect which tenant and identity type the enrollment application associated with the verification link.
- Confirm whether the link expects the primary email as a Microsoft Entra work account, a Microsoft consumer account, or another bound identity.
- Repair or reset the authorization binding without deleting the Artifact Signing account or validation request.
- Issue a replacement link only if the existing link cannot be repaired.
A related case involving an unusable validation link required intervention by Microsoft’s internal team, rather than another client-side sign-in attempt.^2^
Provide these items only in the private case:
- Subscription and Microsoft Entra tenant IDs
- Artifact Signing account name, resource group, region, and SKU
- Identity validation request ID
- Primary email entered in the request
- UTC timestamp of the latest failure
- Screenshot showing “You need permission”
- Tenant identifier shown on that page
- Confirmation that the resource is in the intended Entra directory
- Confirmation of the administrator’s Azure RBAC assignments
- Browser/network trace or correlation/request ID, if displayed
Do not include the verification URL, tokens, identity documents, or those identifiers in Microsoft Q&A.
What the public documentation establishes
For Organization validation, Microsoft requires the Primary Email to be a monitored address on a domain owned by the legal business entity. The Verified Credentials and email-verification links are sent to that address and expire after seven days. The named representative must use the exact first and last name on their government-issued identification.^3^
The available Organization-validation documentation does not specify that the verification link must authenticate as either:
- a personal Microsoft account, or
- a work/school account in the Artifact Signing resource’s Entra tenant.
The FAQ attributes a similar permission error to an email/sign-in mismatch only for Individual identity validation.^1^ That guidance should not be extrapolated to this Organization request—especially since matching the primary email has already failed and the error identifies the consumer tenant. Microsoft must inspect the enrollment binding for the definitive account-type requirement in this request.
Conditional RBAC check
Azure RBAC controls management of the validation resource in the Azure portal; it does not by itself establish authorization inside the Verified Credentials enrollment link.
The managing identity requires:
- Artifact Signing Identity Verifier for the validation request; and
- at least Reader at subscription scope.
Owner assigned only on the Artifact Signing account does not replace the documented subscription-scope Reader prerequisite. Check Subscription → Access control (IAM) → Check access and verify that the same Entra identity has Reader or higher at subscription scope.^4^
If that prerequisite is already satisfied, do not change roles or repeat the email-selection attempt; proceed with the private support case. Microsoft also advises that creating more requests for the same entity while one is in progress does not help.^1^
References