A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
A community member has associated this post with a similar question:
Azure Artifact Signing Organization Identity Validation fails after successful Face Check – HTTP 500 / Unexpected session payload
Only moderators can edit this content.
Azure Artifact Signing Organization Identity Validation fails after successful Face Check – HTTP 500 / Unexpected session payload
We are blocked while completing an Organization / Public identity validation for Azure Artifact Signing in Japan.
The AU10TIX identity verification completed successfully and a Verified ID was issued.
Microsoft Authenticator then performs the required Face Check. The Authenticator diagnostic log shows:
FaceCheckStatus=success AppIntegrityStatus=success DIDPresentationAllowed
However, immediately after the successful Face Check, the Verified ID presentation fails in:
PostPresentationResponseOperation
with HTTP 500.
The error chain is:
internalServerError -> claimValidationError -> facecheckSessionFailure -> Unexpected session payload
The diagnostic log also reports:
FailureStage=response retryable=false
Therefore, the identity-document verification, Face Check, and app-integrity checks appear to complete successfully. The failure occurs afterward while the presentation response is being processed.
Our Azure subscription currently uses Basic support, so the Azure portal does not allow us to open a private technical support case.
Could a Microsoft Artifact Signing / Entra Verified ID engineer please advise:
- Is
facecheckSessionFailure: Unexpected session payloada known presentation/session processing issue? - Can the current Organization identity-validation request be reset or repaired without deleting it and repeating the entire AU10TIX verification?
- Should we retry with a new presentation session, or wait for Microsoft investigation?
- Can a Microsoft moderator initiate a private message so that we can securely provide the Request-ID, MS-CV, Flow ID, Identity Validation ID, subscription information, screenshots, and full Authenticator diagnostic log?
For safety, we have not deleted the current identity validation, deleted the issued Verified ID, created another duplicate identity-validation request, created a certificate profile, or performed any signing operation.
A very similar public report describes the same sequence: Face Check succeeds, followed by HTTP 500 and claimValidationError -> facecheckSessionFailure -> Unexpected session payload.