A community member has associated this post with a similar question:
Azure Artifact Signing Organization Identity Validation fails after successful Face Check – HTTP 500 / Unexpected session payload

Only moderators can edit this content.

Azure Artifact Signing Organization Identity Validation fails after successful Face Check – HTTP 500 / Unexpected session payload

玉置卓也 5 Reputation points
2026-09-23T03:24:29.19+00:00

We are blocked while completing an Organization / Public identity validation for Azure Artifact Signing in Japan.

The AU10TIX identity verification completed successfully and a Verified ID was issued.

Microsoft Authenticator then performs the required Face Check. The Authenticator diagnostic log shows:

FaceCheckStatus=success AppIntegrityStatus=success DIDPresentationAllowed

However, immediately after the successful Face Check, the Verified ID presentation fails in:

PostPresentationResponseOperation

with HTTP 500.

The error chain is:

internalServerError -> claimValidationError -> facecheckSessionFailure -> Unexpected session payload

The diagnostic log also reports:

FailureStage=response retryable=false

Therefore, the identity-document verification, Face Check, and app-integrity checks appear to complete successfully. The failure occurs afterward while the presentation response is being processed.

Our Azure subscription currently uses Basic support, so the Azure portal does not allow us to open a private technical support case.

Could a Microsoft Artifact Signing / Entra Verified ID engineer please advise:

  1. Is facecheckSessionFailure: Unexpected session payload a known presentation/session processing issue?
  2. Can the current Organization identity-validation request be reset or repaired without deleting it and repeating the entire AU10TIX verification?
  3. Should we retry with a new presentation session, or wait for Microsoft investigation?
  4. Can a Microsoft moderator initiate a private message so that we can securely provide the Request-ID, MS-CV, Flow ID, Identity Validation ID, subscription information, screenshots, and full Authenticator diagnostic log?

For safety, we have not deleted the current identity validation, deleted the issued Verified ID, created another duplicate identity-validation request, created a certificate profile, or performed any signing operation.

A very similar public report describes the same sequence: Face Check succeeds, followed by HTTP 500 and claimValidationError -> facecheckSessionFailure -> Unexpected session payload.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

0 comments No comments