Team Signatures
How to install email signatures to Microsoft 365
Installing signatures to Microsoft 365 takes two separate approvals. The first is a Microsoft Graph consent that lets SyncSignature read your Entra ID directory. The second is the SyncSignature Outlook add-in, approved through Centralized Deployment in the Microsoft 365 admin center. The Graph consent gives you directory data immediately. The add-in is the part that actually puts a signature in the compose window, and Microsoft controls how quickly it lands.
Nothing in this setup touches mail flow. There are no transport rules, no mail flow connectors, no MX record changes, and no mail rerouting through SyncSignature.
The two grants, and why there are two
| Grant | What it does | Where you approve it | When it takes effect |
|---|---|---|---|
| Microsoft Graph consent | Reads Entra ID users, groups, and profile fields so signatures fill themselves in | Integrations in SyncSignature | Immediately |
| SyncSignature Outlook add-in | Stamps the signature into the compose window in Outlook | Microsoft 365 admin center, via Centralized Deployment | 6 to 12 hours, controlled by Microsoft |
This is the step people get wrong. They approve the Graph consent, watch teammates import, and assume the job is done. Directory data and signature delivery are two different systems: without the add-in, signatures exist in SyncSignature but never reach Outlook.
Before you start
| Requirement | Where it lives | Notes |
|---|---|---|
| An admin who can grant tenant-wide consent | Microsoft 365 and Entra ID | A Global Administrator. Both the Graph consent and the add-in deployment are tenant-level actions |
| Owner or Manager role | Your SyncSignature workspace | Teammates cannot connect integrations or deploy |
| At least one saved template | TEMPLATES | A group with no template produces no signatures |
| A group with that template assigned | GROUPS | Signatures are generated as teammates join the group |
Useful but optional: an Entra ID security group holding a few pilot users, so you can check the result before the whole company sees it.
Step 1: Grant Microsoft Graph consent
- In SyncSignature, open Integrations and choose Microsoft 365.
- Sign in with a Microsoft account that can grant admin consent for the tenant.
- Review the permissions. SyncSignature asks for exactly four, and no more:
| Permission | What it covers |
|---|---|
User.Read.All |
User profiles across the tenant: name, job title, department, phone numbers, office location, photo |
Directory.Read.All |
Directory structure, including security groups and Microsoft 365 groups |
User.Read |
The profile of the admin who is signing in |
offline_access |
Keeps the connection alive so the directory stays in sync without repeated logins |
- Accept. This grant is server to server. Nothing is installed on anyone's machine at this step.
- Open TEAMMATES and import users from the directory, either all of them or a specific Entra ID group.
All four permissions are read-only on directory data. SyncSignature does not request mailbox read or send permissions and never sees message content.
Step 2: Approve the Outlook add-in
The add-in is listed on Microsoft AppSource and approved through Centralized Deployment, which lives under Integrated apps in the admin center.
- Open the Microsoft 365 admin center and go to Settings > Integrated apps.
- Choose Get apps and search for SyncSignature.
- Choose who receives it: all users, or a specific Entra ID group. A group is the safer first move.
- Review the permissions Microsoft shows you and accept them.
- Deploy.
Microsoft now pushes the add-in out to every targeted Outlook install. This takes 6 to 12 hours. That window is Microsoft's, not SyncSignature's, and neither side can speed it up, so plan the rollout around it.
Step 3: Build the template and group your teammates
- Create the template. In TEMPLATES, build your branded layout or save an existing signature as a template. There are 100 to start from.
- Create a group and assign the template. In GROUPS, name the group after how signatures actually differ, by department, office, or role.
- Add teammates to the group. Signatures are generated automatically, filled with each person's Entra ID data.
- Check one signature before you scale. Open a teammate's generated signature and confirm the title, phone number, and photo came across correctly.
Once the add-in is live and a teammate has a generated signature, Outlook picks up the current version at compose time. Edits reach signatures in 5 to 10 minutes, plus whatever delay Microsoft adds to directory changes.
What the add-in actually does
The add-in stamps the signature client-side, at compose time, inside Outlook. It renders in Outlook for Windows, Outlook for Mac, Outlook on the web, Outlook for iOS, and Outlook for Android.
Because stamping happens in the client, your mail never routes through SyncSignature. That is deliberate, and it has one honest tradeoff: a message sent from somewhere the add-in is not running, such as a native phone mail app or a third-party client, will not be stamped, and there is no server-side rule to catch it. The upside is that no message content ever passes through us.
Common issues and fixes
| Issue | Cause | Fix |
|---|---|---|
| Teammates imported, but no signature appears in Outlook | Only the Graph consent was granted, the add-in was never deployed | Approve the add-in under Settings > Integrated apps in the Microsoft 365 admin center |
| Add-in deployed hours ago and still not in Outlook | Microsoft is still pushing it | Wait out the 6 to 12 hour window, then have the user fully close and reopen Outlook |
| Consent screen says an administrator has to approve | The signed in account cannot grant tenant-wide consent | Have a Global Administrator complete the connection from Integrations |
| Some users did not import | They sit outside the Entra ID group the import was scoped to | Widen the scope, or add them to the targeted group in Entra ID |
| Signature renders with blank gaps | The teammate has no job title or phone number in Entra ID | Fill the field in Entra ID, or make that field dynamic so the teammate can fill it |
| Mail sent from a phone has no signature | The message came from a client that does not run the add-in | Send from Outlook for iOS or Outlook for Android, both of which are supported |
Related articles
- Connect your Microsoft Entra ID directory covers the four Graph permissions and every field that syncs.
- Troubleshoot Microsoft 365 signature installation covers the add-in window, consent errors, and missing users.
- What are groups explains the template to group to teammate mechanic behind every signature.
- Office 365 signature management is the product overview for Microsoft 365 teams.
Still stuck? Email support@syncsignature.com and include your Microsoft 365 tenant domain and the date you deployed the add-in.
