Un service de bout en bout entièrement géré pour signer numériquement du code, des documents et des applications. (anciennement Signatures de confiance)
Azure Trusted Signing persistent SmartScreen "unrecognized app" warnings on VSTO installer signed under Microsoft ID Verified
We use Azure Trusted Signing to sign the .exe installer for our VSTO Excel add-in (B2B product distributed to accounting professionals). Our publisher identity has been validated by Microsoft, and the signing pipeline produces signatures that validate cleanly in every standard check. Despite this, every signed installer triggers the "Windows protected your PC unrecognized app" SmartScreen prompt on first download and execution, regardless of build number or signing date. Signing configuration - Publisher (Subject): VIPER HOLDING - Issuing CA: Microsoft ID Verified CS EOC CA 03 - Certificate validity: 3 days (as expected for Trusted Signing) - Timestamping: Microsoft Trusted Signing RFC 3161 endpoint - signtool verify /pa /v: passes, no errors or warnings - Certificate chain: SHA-256, chains to a Microsoft root - Zone.Identifier ZoneId=3 confirmed on the downloaded file (downloaded over HTTPS from our official domain) - All deployed binaries signed (installer .exe, MSI, all add-in DLLs) - VSTO manifests (.dll.manifest and .vsto) signed with mage.exe using the same Trusted Signing identity The signature is structurally valid; SmartScreen simply does not recognize the publisher or the file hash. **
Context and what I already know** I understand that: - SmartScreen reputation is per-publisher and per-file-hash and builds organically through download volume - EV certificates no longer bypass SmartScreen instantly since the March 2024 policy change - First-download warnings are expected for new publishers However, the pattern I'm seeing matches several recently reported cases on this forum and on GitHub (issue Azure/artifact-signing-action#128), where Trusted Signing profiles were silently migrated to recently introduced intermediate CAs (AOC CA 03 in March 2026, EOC CA 04 shortly after), and signed binaries under those CAs trigger SmartScreen warnings even though identical files signed under the previous EOC CA 02 did not.**
Questions**
- Is Microsoft ID Verified CS EOC CA 03 a recently introduced intermediate CA, in the same rollout family as AOC CA 03 and EOC CA 04?
- If so, is there any expected timeline for when SmartScreen reputation will stabilize for binaries chained under EOC CA 03? 3. Is there any supported way to verify whether our profile has been pinned to a newly introduced intermediate CA, or to influence which CA is assigned to a signing request?
- Is there any official guidance for ISVs distributing VSTO/Office add-ins through Trusted Signing during the reputation buildup phase, beyond "wait for organic adoption"? Happy to share the file hash, signature details, or account identifiers privately if that helps the investigation. Thank you.