You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/trusted-signing/faq.yml
-10Lines changed: 0 additions & 10 deletions
Original file line number
Diff line number
Diff line change
@@ -40,16 +40,6 @@ sections:
40
40
- Currently, an organization that has a year-founded date of less than three years can't be onboarded, and identity validation fails.
41
41
- If your organization has a year-founded date of more than three years, ensure that you didn't miss an email verification link that was sent to the primary email address you entered when you created your identity validation request. The link expires after seven days. If you overlooked the email or if you didn't select the link in the email within seven days, create a new identity validation request.
42
42
- If identity validation fails, but not because of a missed email verification, the Microsoft validation team wasn't able to make a determination about your request based on the information that you provided. Even if you provide more documentation when we request it, if we can't validate the information, we can't onboard you to Trusted Signing. In this scenario, we recommend that you delete your Trusted Signing account so that you aren't billed for unused resources.
43
-
- question: For Individual identity validation, I see an error - "You do not have permission to access this page".
44
-
answer: |
45
-
- If you see the error, it is because the email address entered during the individual identity validation is different from the one being used to sign in to access the link. Make sure both the email addresses match.
46
-
:::image type="content" source="media/trusted-signing-indie-validation-email-mismatch.png" alt-text="Screenshot of email mismatch when access link to verify individual developer." lightbox="media/trusted-signing-indie-validation-email-mismatch.png":::
47
-
- question: For Individual identity validation, what if I don’t have an address on a bank statement or utility bill?
48
-
answer: |
49
-
- Be sure to use a government issued ID with address on it, in order to successfully go through the process.
50
-
- question: What if I already have a VID?
51
-
answer: |
52
-
- Follow the steps to present your existing VID for Trusted Signing. For this process, VIDs must include your address in addition to your name. Ensure that your VIDs have your address on them before using them for Trusted Signing.
53
43
- question: What if I need assistance with identity validation?
54
44
answer: |
55
45
- For questions about identity validation in Trusted Signing, contact us via Azure Support or by using [Microsoft Q&A](https://learn.microsoft.com/answers/tags/509/trusted-signing) (use the tag **Azure Trusted Signing**).
|`az trustedsigning list -g MyResourceGroup`| Lists all accounts that are in a resource group. |
203
203
204
-
---
205
204
206
205
## Create an identity validation request
207
206
@@ -210,7 +209,7 @@ You can complete your own identity validation by filling in the request form wit
210
209
> [!NOTE]
211
210
> You can't create an identity validation request if you aren't assigned the appropriate role. If the **New identity** button on the menu bar appears dimmed in the Azure portal, ensure that you are assigned the Trusted Signing Identity Verifier role to proceed with identity validation.
212
211
> [!NOTE]
213
-
> At this time Trusted Signing can only onboard organizations that were incorporated more than 3 years ago.
212
+
> At this time Trusted Signing can only onboard organizations that were incorporated more than 3 years ago and were incorporated in USA and Canada.
@@ -261,88 +260,7 @@ To create an identity validation request for an Organization:
261
260
| Failed email verification | If email verification fails, you must initiate a new identity validation request. |
262
261
| Identity validation status | You're notified through email when there's an update to the identity validation status. You can also check the status in the Azure portal at any time. |
263
262
| Processing time | Processing your identity validation request takes from 1 to 7 business days (possibly longer if we need to request more documentation from you). |
264
-
| More documentation | If we need more documentation to process the identity validation request, you're notified through email. You can upload the documents in the Azure portal. The documentation request email contains information about file size requirements. Ensure that any documents you provide are the most current. <br>- All documents submitted must be issued within the previous 12 months or where the expiration date is a future date that is at least two months away. <br> - If it isn't possible to provide additional documentation, update your account information to match any legal documents already provided or your official Company registration details. <br> - When providing official business document, such as business registration form, business charter, or articles of incorporation that list the company name and address as it is provided at the time of Identity Validation request creation. <br> - Ensure the domain registration or domain invoice from registration or renewal that lists the entity/contact name and domain as it is state on the request.|
To create an Individual identity validation request for an Individual Developer:
269
-
270
-
1. In the Azure portal, go to your new Trusted Signing account.
271
-
2. Confirm that you're assigned the Trusted Signing Identity Verifier role.
272
-
273
-
To learn how to manage, access by using role-based access control (RBAC), see [Tutorial: Assign roles in Trusted Signing](tutorial-assign-roles.md).
274
-
3. On the Trusted Signing account **Overview** pane or on the resource menu under **Objects**, select **Identity validations**.
275
-
4. Select **Organization**, in the dropdown select **Individual** and then select **Public**.
276
-
277
-
- Public identity validation applies to these certificate profile types: Public Trust, Public Trust Test, VBS Enclave.
278
-
- Private identity validation is only for Organizations.
279
-
5. On **New identity validation**, provide the following information:
280
-
281
-
| Fields | Details |
282
-
| :------------------- | :------------------- |
283
-
|**First Name**| Use the exact name as it appears on your government-issued identification document for the Identity Validation process. |
284
-
|**Last Name**| Use the exact name as it appears on your government-issued identification document for the Identity Validation process. |
285
-
|**Primary Email**| Enter the email address that is going to receive the Identity Validation link. Make sure to this same email address when logging into the Microsoft Account to access the Identity Validation link. |
286
-
|**Street, City, Country, State, Postal code**| Enter the address as it appears on your government issued identification document or utility bill or bank statement. The city, state, and country from the address entered here's displayed on the certificate. |
287
-
288
-
6. Select **Certificate subject preview** to see the preview of the information that appears in the certificate.
289
-
- Your email address and street address aren't included in the certificate by default.
290
-
7. Select **I accept Microsoft terms of use for trusted signing services**. You can download the Terms of Use to review or save them.
291
-
8. Select the **Create** button.
292
-
9. When the request is successfully created, the identity validation request status changes to **In Progress**.
293
-
10. When the status changes to **Action Required**. Click on your name, a blade opens on the right-hand side. Click on the link under “Please complete your verification here”.
294
-
11. Follow the link to complete the Identity Validation process. Use the email address provided at the time of request creation to create a Microsoft account. Enter the credentials when prompted, and you'll be navigated to the next screen.
295
-
12. Click on **Start** under our Trusted Partner > Au10tix to begin the validation process. You will be navigated to a 3rd party website.
296
-
13. You need to switch to your mobile device to complete the process and present the relevant documentation when prompted.
297
-
14. On your mobile device, open the Authenticator app, select Verified IDs, on bottom right you’ll see the QR code in blue. Click on that.
298
-
15. In Azure portal, click on the link that you used to perform identity validation, scan the QR code under Present Verified ID from your mobile device, this completes the process.
299
-
For successful completion it says: **Verification Successful**
300
-
301
-
:::image type="content" source="media/trusted-signing-indie-identity-validation-onevet.png" alt-text="Screenshot that shows the indie successful on onevet." lightbox="media/trusted-signing-indie-identity-validation-onevet.png":::
302
-
303
-
16. It takes a couple of minutes for the Identity Validation status on Azure portal to update. For a successful Verified ID the status on Azure portal changes to **Completed**.
304
-
305
-
:::image type="content" source="media/trusted-signing-identity-validation-indie.png" alt-text="Screenshot that shows the indie successful on Azure portal." lightbox="media/trusted-signing-identity-validation-indie.png":::
306
-
307
-
### Important information for public identity validation for individuals
308
-
309
-
1. Minimum Requirements for Mobile OSes and supported Browsers:
310
-
311
-
:::image type="content" source="media/trusted-signing-au10tix-mobileOS-supported.png" alt-text="Screenshot that shows the mobile OSes supported for indie." lightbox="media/trusted-signing-au10tix-mobileOS-supported.png":::
312
-
313
-
:::image type="content" source="media/trusted-signing-au10tix-browser-supported.png" alt-text="Screenshot that shows the browsers supported for indie." lightbox="media/trusted-signing-au10tix-browser-supported.png":::
314
-
315
-
2. Types of ID Accepted:
316
-
- Government-issued IDs such as passports, driving licenses, or ID cards.
317
-
- Photo IDs (or a US Social Security Card).
318
-
- Official government-issued IDs such as a passport, driver’s license, or state ID.
319
-
- Do not submit privately issued IDs such as library cards, school IDs, club membership cards, etc.
320
-
321
-
3. Visibility/Low Light/Bright Light:
322
-
- Do not use flash.
323
-
- Do not place the ID in direct sunlight.
324
-
- Hold the camera or mobile device steady while taking the picture.
325
-
326
-
4. Best Practices for Supplemental Docs:
327
-
- Utility Bills: Electricity, water, gas, or telephone bills (should be recent, typically within the last three months).
328
-
- Bank Statements: Official statements from banks or credit card companies that show the individual’s address.
329
-
- The POA document must have the address, name, and date appear on the main page (first page), so multiple pages are not required.
330
-
331
-
5. General best practices:
332
-
- Single picture per file, if two-sided, create one file per side.
333
-
- Handwritten documents are not accepted.
334
-
- Do not crop the image (cut corners, miss parts) try to have margins on all sides of the captured image prior to capturing.
335
-
- Do not use Photoshop or other editing software; do not alter the document in any way.
336
-
- Do not use flash.
337
-
- Take the photo from directly above the document while it is on a flat surface.
338
-
- Avoid colored and noisy background.
339
-
- Do not obstruct the ID (no fingers covering part of the document).
340
-
- Use color images not lower than 200 DPI. The ideal image size is 500Kb. AU10TIX best practice is to accept images with 400 DPI and above.
341
-
- The minimum threshold for the image size for an OK result is 600 W X 370 H pixels.
342
-
- Accepted file types: .bmp .jpg .gif .tif .pdf.
343
-
- Users cannot upload images smaller than 30kb or larger than 5MB.
344
-
345
-
---
263
+
| More documentation | If we need more documentation to process the identity validation request, you're notified through email. You can upload the documents in the Azure portal. For documentation upload, there are 3 attempts. The documentation request email contains information about file size requirements. Ensure that any documents you provide are the most current. <br>- All documents submitted must be issued within the previous 12 months or where the expiration date is a future date that is at least two months away. <br> - If it isn't possible to provide additional documentation, update your account information to match any legal documents already provided or your official Company registration details. <br> - When providing official business document, such as business registration form, business charter, or articles of incorporation that list the company name and address as it is provided at the time of Identity Validation request creation. <br> - Ensure the domain registration or domain invoice from registration or renewal that lists the entity/contact name and domain as it is state on the request.|
0 commit comments