Artifact Signing organization identity validation: “You need permission” with the correct primary email

Cosmin Lupsan 0 Reputation points
2026-10-10T09:14:16.78+00:00

Our existing Azure Artifact Signing Basic account is in East US, on an active Azure subscription. Organization identity validation remains in Action Required.

The Azure administrator can access the signing account and has Owner plus Artifact Signing Identity Verifier. Opening the existing validation link leads to Microsoft Verified Credentials. We explicitly selected and authenticated the Microsoft account matching the validation request's primary corporate email, but the page still displays “You need permission” and requires an authorized user of the Entra tenant used for the enrollment application.

The error page reports the Microsoft consumer tenant, while the Azure signing resource belongs to our existing Microsoft Entra directory. Selecting the correct primary email did not resolve the error. We have not established whether the authorization failure is caused by the account type, the request binding, or another service issue.

No Public Trust certificate profile exists yet. We want to preserve the existing tenant, subscription, signing account and identity validation request rather than recreate them.

Could the Artifact Signing identity validation team advise how to repair authorization for the existing request and confirm which Microsoft account type/identity is expected by its verification link? Please provide a private Microsoft channel if you need our validation ID, tenant/subscription IDs or screenshots. We will not post those identifiers, verification links, tokens or identity documents publicly.

This concerns Public Trust Authenticode signing for Windows software distributed on our own websites, not Microsoft Store enrollment.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)


1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-10T09:15:18.3366667+00:00

    Open a private Azure Support case and request repair or reset of the enrollment authorization bound to the existing identity validation request; do not delete it or create another request while Microsoft investigates.

    Open the private support case

    1. Sign in to the Azure portal with an identity that can access the affected subscription.
    2. Open Help + support using the Azure support blade: https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade
    3. Select Create a support request and route it to Artifact Signing / identity validation. Microsoft lists Azure Support as the private support channel for Artifact Signing identity-validation assistance.^1^
    4. State that this is an existing Organization/Public Trust request in Action Required, and ask the Artifact Signing identity-validation or vetting team to:
      • Inspect which tenant and identity type the enrollment application associated with the verification link.
      • Confirm whether the link expects the primary email as a Microsoft Entra work account, a Microsoft consumer account, or another bound identity.
      • Repair or reset the authorization binding without deleting the Artifact Signing account or validation request.
      • Issue a replacement link only if the existing link cannot be repaired.

    A related case involving an unusable validation link required intervention by Microsoft’s internal team, rather than another client-side sign-in attempt.^2^

    Provide these items only in the private case:

    • Subscription and Microsoft Entra tenant IDs
    • Artifact Signing account name, resource group, region, and SKU
    • Identity validation request ID
    • Primary email entered in the request
    • UTC timestamp of the latest failure
    • Screenshot showing “You need permission”
    • Tenant identifier shown on that page
    • Confirmation that the resource is in the intended Entra directory
    • Confirmation of the administrator’s Azure RBAC assignments
    • Browser/network trace or correlation/request ID, if displayed

    Do not include the verification URL, tokens, identity documents, or those identifiers in Microsoft Q&A.

    What the public documentation establishes

    For Organization validation, Microsoft requires the Primary Email to be a monitored address on a domain owned by the legal business entity. The Verified Credentials and email-verification links are sent to that address and expire after seven days. The named representative must use the exact first and last name on their government-issued identification.^3^

    The available Organization-validation documentation does not specify that the verification link must authenticate as either:

    • a personal Microsoft account, or
    • a work/school account in the Artifact Signing resource’s Entra tenant.

    The FAQ attributes a similar permission error to an email/sign-in mismatch only for Individual identity validation.^1^ That guidance should not be extrapolated to this Organization request—especially since matching the primary email has already failed and the error identifies the consumer tenant. Microsoft must inspect the enrollment binding for the definitive account-type requirement in this request.

    Conditional RBAC check

    Azure RBAC controls management of the validation resource in the Azure portal; it does not by itself establish authorization inside the Verified Credentials enrollment link.

    The managing identity requires:

    • Artifact Signing Identity Verifier for the validation request; and
    • at least Reader at subscription scope.

    Owner assigned only on the Artifact Signing account does not replace the documented subscription-scope Reader prerequisite. Check Subscription → Access control (IAM) → Check access and verify that the same Entra identity has Reader or higher at subscription scope.^4^

    If that prerequisite is already satisfied, do not change roles or repeat the email-selection attempt; proceed with the private support case. Microsoft also advises that creating more requests for the same entity while one is in progress does not help.^1^


    References

    1. Artifact Signing FAQ | Microsoft Learn
    2. Azure Artifact Signing identity validation stuck in Pending for 4 weeks — email verification link returns "The request is blocked - Microsoft Q&A
    3. Quickstart: Set up Artifact Signing
    4. Tutorial: Assign roles in Artifact Signing | Microsoft Learn
    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.