Code signing vs MS Artifact signing

MS Artifact signing is comparatively cheap, and various ‘references’ seem to imply they are effectively the same.

Yet, to me the ‘descriptions’ are quite different.

Does anyone have a reference that clearly states why you need code signing over artifact signing?

Cost vs Convenience? What will the Azure way cost in total (apparently you can’t get MS Artifact signing unless you’re already paying for Azure?)

It’s the same thing, it’s just that your certificate lives on Azure and when you sign, signtool sends the digest to azure to sign instead of to the token on your machine.

You need a business that has existed for 3 yrs, and you need to be based in the US/Canada/EU/UK - not available in Australia - it will probably be available eventually I haven’t found any info on it yet.

I’m not a fan - but it’s a better option that other cloud based signing services like ssl.com or certum - those services provide very few “signings” in their monthly fee.

Of course if you have your certificate on a token, you can sign as many files as you want, and it’s faster ( no cloud latency).

“Artifact Signing” was a “Trusted Signing” code-signing service renamed.

$10/month and you can sign 5,000 times using one cert profile. I got setup in a few hours as my company was previously validated.