How to use EV Code Signing Certificates in Azure DevOps pipelines?
18:47 15 Nov 2025

need to sign .NET assemblies, VSTO add-ins, and a setup installer during CI/CD in Azure DevOps.

I have an EV Code Signing certificate, stored on a hardware token. The private key cannot be exported, and the hardware token cannot be accessed directly by Microsoft-hosted agents.

Is there a supported way to sign binaries in an Azure DevOps pipeline using an EV certificate?

I'm looking for a solution that remains compliant with current CA requirements: no key export, no manual token interaction during the build.

azure-pipelines