Artifact Signing org identity validation: Verified ID face check fails with facecheckSessionFailure "Unexpected session payload"

c herring 0 Reputation points
2026-10-02T04:09:41.8833333+00:00

I'm completing Public Trust organization identity validation for Artifact Signing (New Zealand). During the representative verification step, Microsoft Authenticator (iOS) completes the AU10TIX ID and face check successfully (FaceCheckStatus=success in the Authenticator log), but the presentation response fails with HTTP 500:

internalServerError > claimValidationError > facecheckSessionFailure: "Unexpected session payload" (retryable: false)

I've deleted all Verified ID cards, fully restarted Authenticator, deleted the identity validation request and created a new one, and retried without VPN. Same result each time.

Request ID: d3f02aae-c8d1-4037-bb60-4aa862e7cd83 Correlation vector: AD9y6FMrSIqVSZtug7vWsA.3 Time: 2026-10-02 03:28:50 UTC

Could someone on the Artifact Signing team look into this? Happy to provide the full Authenticator log.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

0 comments No comments

1 answer

Sort by: Oldest
  1. Rukshan edirisinghe 910 Reputation points
    2026-10-02T04:31:54.5166667+00:00

    Hi @c herring

    You've done everything that's doable from your side, and the error itself backs that up. An HTTP 500 with facecheckSessionFailure marked retryable: false is thrown by the Verified ID service after your face check already succeeded, which means the problem is in how the service is matching the session, not in your phone, cards or request. Deleting and recreating things won't change it, so I'd stop retrying and save your attempts.

    Three things worth trying once each, since they avoid rather than repeat the failing path:

    • On the iPhone, turn off iCloud Private Relay (Settings > your name > iCloud > Private Relay) for the attempt. It routes traffic like a VPN and has broken verification sessions before.
    • Try the same-device flow: open the verification link in Safari on the phone instead of scanning a QR from the PC, so issuance and presentation happen in one session.
    • Wait about 24 hours before that attempt, so any stuck session on the backend expires first.

    If it fails again with the same payload error, it needs the Artifact Signing identity validation team. Reply on this thread with "still failing" so a moderator can take your Request ID and correlation vector by private message, and open a support request in parallel. Even on a Basic plan you can file it as Billing / subscription management and ask for routing to Artifact Signing identity validation. Keep the full Authenticator log ready, it's exactly what they'll want.

    If this helped, please click Accept Answer so others hitting this error can find it.

    Reference: https://learn.microsoft.com/en-us/entra/verified-id/using-facecheck

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.