official logo of free email signature generator html company - SyncSignature

Team Signatures

How to connect your Microsoft Entra ID directory

Connecting Microsoft Entra ID is the directory half of Microsoft 365 setup. You grant SyncSignature four read-only Microsoft Graph permissions, and your users arrive in the workspace with their job titles, phone numbers, office locations, photos, and group memberships already attached. Signatures then fill themselves in from those fields instead of being typed by hand.

The connection is server to server. Nothing is installed on anyone's machine, and this grant on its own does not put a signature in Outlook. The SyncSignature Outlook add-in does that, and it is approved separately in the Microsoft 365 admin center through Centralized Deployment. Directory data is available immediately, but Microsoft takes 6 to 12 hours to push the add-in to targeted Outlook installs.

What the directory connection covers

  • It reads, it does not write. All four permissions are read-only on directory data. SyncSignature does not request mailbox read or send permissions and does not see message content.
  • It feeds the merge tags. {{name}}, {{title}}, {{department}}, {{phone}}, and {{photo}} resolve per teammate from their Entra ID profile.
  • It reuses the groups you already maintain. Import can be scoped to an Entra ID security group or Microsoft 365 group rather than the whole tenant.

Two things it is not. It is not SCIM: SyncSignature is not a SCIM-provisioned app. And it is not SAML single sign-on. Signing in with your Microsoft account works, but SAML and OIDC single sign-on are not shipped.

It is also Entra ID only. There is no on-premises Active Directory or Exchange support. If your source of truth is on-premises AD, Microsoft's own Entra Connect mirrors it into Entra ID, and SyncSignature reads that copy.

Before you start

Requirement Where it lives Notes
An admin who can grant tenant-wide consent Entra ID A Global Administrator. Consent is a tenant-level action
Owner or Manager role Your SyncSignature workspace Teammates cannot connect integrations
Accurate profile fields Entra ID user profiles A signature is only as good as the directory behind it. Fix titles and phone numbers before you import
A security group or Microsoft 365 group Entra ID Optional, but it is how you scope the import to a pilot team

The four permissions you approve

Permission What SyncSignature reads with it
User.Read.All Every user profile in the tenant: name, email, job title, department, office location, phone numbers, manager, photo
Directory.Read.All Directory structure, so you can scope by security group or Microsoft 365 group
User.Read The profile of the admin completing the connection
offline_access A durable connection, so the directory keeps syncing without someone signing in again

If the consent screen shows anything beyond these four, stop and email support before accepting.

How to connect Entra ID

  1. Open Integrations in SyncSignature and choose Microsoft 365.
  2. Sign in with a Microsoft account that can grant admin consent for the tenant.
  3. Review the four permissions and accept. Directory data is available right away, with no waiting window.
  4. Open TEAMMATES and import users. Pull in the whole directory, or pick a single Entra ID group.
  5. Assign the imported teammates to a group in GROUPS. Signatures are generated on assignment from the group's template.

What fields come across

Entra ID field Typical use in a signature
Display name {{name}}
Primary email, UPN or primary SMTP The teammate's identity in SyncSignature and the email line
Job title {{title}}
Department {{department}}, and often the basis for group structure
Office location Office or city line
Mobile phone and business phone {{phone}}
Manager Useful for working out who belongs in which group
Profile photo {{photo}}
Security group and Microsoft 365 group membership Scoping who imports and who gets targeted
extensionAttribute1 to extensionAttribute15 Custom values with no standard field: pronouns, license number, region, booking link

The extension attributes are the escape hatch. If you need something Entra ID has no native field for, write it to one of the 15 custom attributes and reference it from the template.

Scoping by security group or Microsoft 365 group

Most teams already keep their org structure in Entra ID groups, so mirror it rather than rebuild it. Import the Sales security group, create a Sales group in SyncSignature, and assign the sales template to it.

One difference to plan around: a teammate belongs to one SyncSignature group at a time, even if Entra ID has them in five. That limit guarantees exactly one current signature per person. When someone sits in two Entra ID groups, decide which one drives their signature.

What happens on a promotion, a move, or a departure

  • Promotion. Change the job title in Entra ID. On the next sync the signature regenerates with the new title: 5 to 10 minutes on the SyncSignature side, plus Microsoft's own delay.
  • Move between departments. Change the department in Entra ID. If their layout should change too, move them to the other group in GROUPS and the signature regenerates from that template.
  • Departure. Disable or delete the account in Entra ID, then remove the teammate in TEAMMATES. Because stamping happens client-side, an account that can no longer sign in to Outlook stops producing signatures regardless.
  • New hire. They appear in the import once the Entra ID account exists. Add them to a group and the signature is generated on assignment.

If your real source of truth is an HR system such as Workday, BambooHR, or an identity provider such as Okta, there is no direct connector. Those tools write into Entra ID, and SyncSignature reads Entra ID. The chain still works, it just has one more hop, and each hop adds its own delay.

Common issues and fixes

Issue Cause Fix
Consent screen says an administrator has to approve The signed in account cannot grant tenant-wide consent Have a Global Administrator complete the connection from Integrations
A user is missing from the import They are outside the Entra ID group the import was scoped to Widen the scope, or add them to that group in Entra ID
Titles or phone numbers are blank The field is empty on the Entra ID profile Fill it in Entra ID, or mark the field dynamic so the teammate fills it themselves
A directory change has not reached the signature Sync has not run yet Allow 5 to 10 minutes on the SyncSignature side, plus Microsoft's own directory delay
Directory stopped updating after weeks of working Consent was revoked in Entra ID enterprise applications Reconnect from Integrations and grant consent again
An on-premises AD user never appears Entra ID only, no on-premises AD support Confirm Entra Connect is syncing that account into Entra ID

Still stuck? Email support@syncsignature.com and include your tenant domain and the email address of one user who is not importing.