Forum Discussion
SmartScreen reputation issue for EV Code Signed Windows application
An EV certificate no longer guarantees SmartScreen reputation. Microsoft evaluates publisher reputation and the file hash, so a new installer can show an unrecognized-app warning even when its signature is valid.
Verify that the downloaded file retains a valid Authenticode signature, trusted timestamp, expected publisher name, and unchanged hash. Sign every executable with the same publisher identity, timestamp each signature, and never modify the package afterward.
Submitting the file through Microsoft Security Intelligence is the correct escalation for a suspected false warning. Confirm that Microsoft Defender SmartScreen was selected and keep the submission ID. No public reputation threshold or guaranteed review time exists, so seven days alone does not indicate a decision.
Also confirm whether the message comes from SmartScreen, Smart App Control, or enterprise policy, since those controls can produce different blocks. If it remains unresolved, escalate through Microsoft support with the signed file hash and submission ID.