Since March 26, 2026, Azure Trusted Signing is issuing certificates from two new intermediate CAs: Microsoft ID Verified CS
AOC CA 03 and Microsoft ID Verified CS EOC CA 04 (both created 2026-03-26). Every build signed with these new CAs triggers a
Windows Defender SmartScreen "unrecognized app" warning.
All previous versions of our app signed with older CAs (AOC CA 01, AOC CA 02, EOC CA 01, EOC CA 02) passed SmartScreen without any warning since December 2025. The certificate chain is valid, timestamped, Public Trust profile. Only the intermediate CA
changed.
This appears to be a propagation issue: Microsoft deployed new CAs without updating SmartScreen reputation. Has anyone else
encountered this? Is there a known fix or timeline?