A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
Artifact Signing (Trusted Signing): organization identity validation fails — tenant callback returns 403 (surfaced as HTTP 500)
Problem description
Trusted Signing (Artifact Signing) organization identity validation will not complete. It stays in "In Progress" even though the Verified ID step succeeds on the device. The backend fails during PostPresentationResponseOperation, returning an HTTP 500 that wraps a 403 Forbidden on the tenant callback, so the validation never reaches Completed.
Environment
- Trusted Signing – Preview, Artifact Signing account, organizational (Public) identity validation
- Validation initiated from the Azure portal; Verified ID presented via Microsoft Authenticator
- U.S.-based organization, standard paid Azure Plan subscription (not Free Trial / Azure for Students)
The error
On the device the Face Check and presentation succeed (FaceCheckStatus=success, DIDPresentationAllowed). Then PostPresentationResponseOperation fails with:
internalServerError (500)
caused by callback_failure: "Error while calling tenant callback."
caused by http_client.response_error: "Forbidden", statusCode 403
What I've already tried / ruled out
- Role: the user completing verification already has the Artifact Signing Identity Verifier role (scoped to the signing account) plus Owner. Nothing was missing.
- Fresh record: created a brand-new organization validation with identical (correct) details — it fails at the exact same step with the exact same 500 → callback_failure → 403.
- Subscription: standard paid Azure Plan, not a Free Trial or Students offer.
- Not client-side: same failure in a private/incognito browser window; the Verified ID issuance and Face Check always succeed. The break is purely in the service-side callback after presentation.
Question
Since the role is present, the subscription is paid, and a fresh validation fails identically, this looks like a service-side issue in the Trusted Signing identity-validation tenant callback rather than anything configurable on the customer side. Has anyone seen this callback_failure / 403 on PostPresentationResponseOperation, and what resolved it? If a Microsoft engineer can pick this up, I have an open private Azure support case and can share the specific validation IDs and correlation IDs there.