Packaging Store Signing Errors

Common Symptoms

SymptomLikely causeFix
Store upload rejectedPackage format, manifest, version, or capability issueRecheck MSIX package requirements and WACK output
Signing error outside StoreNo trusted cert or wrong certificate chainChoose Azure Artifact Signing, CA cert, or enterprise trust path
SmartScreen warningNew or unsigned public binaryPrefer Store MSIX or signed distribution with reputation plan
Store MSI/EXE blockedInstaller not signed or not hosted as requiredFollow Store MSI/EXE requirements, not MSIX assumptions
Privacy policy requiredApp collects/transmits personal informationProvide accurate privacy policy URL before submission

Store MSIX Rules

  • Store re-signs MSIX after certification.
  • WACK is recommended before upload.
  • Package versioning and architecture bundles matter.
  • Restricted capabilities need review notes.

Non-Store Rules

  • Non-Store MSIX needs publisher signing.
  • MSI/EXE needs Authenticode signing for public distribution.
  • Self-signed certs only work when the target environment trusts them.