Microsoft Azure Trusted Signing
Set up Azure Trusted Signing
To sign Windows builds with a Microsoft-issued certificate, Deskifier needs credentials from Azure Trusted Signing. This guide walks you through creating a signing account, verifying an identity, and generating the app credentials Deskifier uses to sign your builds.
- Navigate to azure.microsoft.com/products/artifact-signing and click Get started with Azure.

- After signing up or logging in, navigate to the Artifact Signing Accounts service in the Azure portal.

- Click Create and enter a resource group name (recommended:
<appName>Resource).

- Select an account name & pricing plan (recommended:
<appName>Account). Take note of the Account name — you'll enter it in the Deskifier dashboard as Azure Signing Account Name.

- Once inside your new signing account, navigate to Access control (IAM) to set account permissions.

- Search for "Artifact Signing Identity Verifier" and select it.

- Select your user account under "Members".

- Once you've selected the role and your account, click "Review + assign". Then go to "Overview" and click "Identity validation".

- Click New identity → Public.

- Enter all details as required.

- Your identity is now pending verification. In the meantime, we can move on to the next step. Search for "Microsoft Entra ID".

- Press Add → App registration.

- Enter any name for your application.

- Take note of these two values — you'll enter them into the Deskifier dashboard as Application Tenant ID & Application Client ID.

- Head to "Certificates & secrets" and click "New client secret". Enter a description and click Add.

- Take note of the Client secret value — you'll enter it as Application Client Secret.

- Head back to the Artifact Signing service, into Access control (IAM), and click "Add" again.

- Search "Artifact Signing Certificate Profile Signer" and select it.

- Go to Select members, search your newly-created application, and assign it.

- Head back to Overview and click Certificate profile. Take note of the account URI — you'll enter it as Azure Signing Endpoint.
The next section assumes that your Identity validation from step 10 is complete.

- Click Create → Public Trust.

- Enter a Certificate Profile Name and select your identity. Take note of your Certificate Profile Name & Common Name — you'll enter them as Azure Certificate Profile Name & Azure Signing Publisher Name.

You should now have all the values Deskifier needs.

Where each value goes
| Deskifier field | From step |
|---|---|
| Application Tenant ID & Application Client ID | 14 |
| Application Client Secret | 16 |
| Azure Signing Account Name | 4 |
| Azure Certificate Profile Name & Azure Signing Publisher | 22 |
| Azure Signing Endpoint | 20 |