A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
Artifact Signing organization validation blocked: matching sign-in email, but Verified Credentials returns "You need permission"
We are completing Public Trust organization identity validation for Longsurf, Inc. so we can sign OpenChart for Windows.
The existing validation remains "Action Required" in the Azure portal. Its details pane says "In Progress" and provides a "Please complete your verification here" link. Opening that link successfully signs in to Microsoft, but redirects to https://credentials.microsoft.com/verify/noPermission and displays "You need permission."
The primary email on the validation request exactly matches the email displayed on the error page. I reproduced this again on October 10, 2026 (America/Vancouver).
Checks already completed and documented in my October 9 email to the verification support team:
- The Azure user has Artifact Signing Identity Verifier on the signing account and Owner inherited from the subscription; the effective access view showed no deny assignments.
- A fresh password sign-in and an Incognito session reproduced the failure.
- The verification flow returned HTTP 401 from the OneVet /ov/verifiablecredentials/v1/vc/auth endpoint. The response body was {"errorMessage":{"RequestType":2}}.
- The Microsoft sign-in account is a personal Microsoft account. The error page displays Microsoft's consumer-account tenant. I understand that a different tenant ID alone does not prove the enrollment is bound incorrectly.
I emailed the verification support team on October 9 with the identity validation ID, gateway request ID, UTC timestamps, and response correlation IDs. I have not received a reply as of October 10.
This appears similar to the issue Microsoft staff are investigating here:
I am opening a separate question as requested by Microsoft staff in that discussion. Could the Artifact Signing / identity validation team please:
- Confirm whether a personal Microsoft account is supported for this organization representative verification flow.
- Investigate authorization or enrollment mapping for the existing request and advise whether Microsoft needs to repair or reissue workflow access.
- Provide a private channel for the validation ID and correlation IDs, and associate this report with the existing email investigation.
The failure occurs before I can reach the representative ID-verification steps. I have not deleted or recreated the validation, changed its primary email, moved the subscription, or changed role assignments while awaiting a supported correction.
I can provide the request identifiers privately. This public post intentionally omits email addresses, subscription and tenant IDs, identity-validation and correlation IDs, signed verification links, tokens, cookies, and identity documents.