official logo of free email signature generator html company - SyncSignature

Team Signatures

How to troubleshoot Microsoft 365 signature installation

Almost every Microsoft 365 signature problem is one of three things: the Outlook add-in has not been pushed yet, only one of the two grants was approved, or the teammate is not in a group with a template. Work out which half of the setup is broken, the directory half or the stamping half, and the fix is usually one step away.

Microsoft 365 setup has two grants. The Microsoft Graph consent reads your directory and takes effect immediately. The Outlook add-in, approved in the Microsoft 365 admin center through Centralized Deployment, is what stamps the signature, and Microsoft takes 6 to 12 hours to push it.

Start here: which half is broken

What you see Which half Where to look
Teammates missing, or fields blank inside SyncSignature Directory, the Graph consent TEAMMATES, and the Entra ID group you scoped the import to
Signatures look right in SyncSignature but nothing appears in Outlook Stamping, the Outlook add-in Microsoft 365 admin center, Settings > Integrated apps
Signature appears in Outlook but shows old details Neither, this is propagation Allow 5 to 10 minutes after the change, then open a fresh compose window

The add-in has not appeared in Outlook

This is the most common report, and most of the time nothing is wrong. After you approve the add-in through Centralized Deployment, Microsoft pushes it to targeted Outlook installs within 6 to 12 hours. That window belongs to Microsoft, and no setting on either side shortens it.

Things worth checking while you wait:

  1. In Settings > Integrated apps, confirm the app shows as deployed rather than pending.
  2. Confirm the affected user is inside the Entra ID group you targeted, or that the deployment was targeted at all users.
  3. Have the user fully quit and reopen Outlook. On Outlook on the web, sign out and back in.
  4. If it is past 12 hours and nobody has it, re-check the assignment target. Deploying to a group that does not contain the test user is the usual cause.
Message or symptom What it means Fix
"Need admin approval" on the sign in screen The account connecting cannot grant tenant-wide consent A Global Administrator has to complete the connection from Integrations
Connection succeeds but no users import Consent was granted on a personal account or the wrong tenant Sign out of all Microsoft accounts, then reconnect with the work account for the correct tenant
The permission list looks longer than expected It should not be SyncSignature asks for four Graph permissions, User.Read.All, Directory.Read.All, User.Read, offline_access, plus the standard openid, profile, and email sign-in scopes. All are sign-in or read-only directory access, with no mailbox scopes
Directory stopped updating after working fine Consent was revoked under Entra ID enterprise applications Reconnect from Integrations and grant consent again

Users missing from the Entra ID sync

Work down this list in order:

  • Scope. If the import was pointed at one Entra ID group, anyone outside it will not appear. Widen the scope or add them to that group.
  • Timing. A user created in Entra ID minutes ago has not synced yet. Allow 5 to 10 minutes, plus Microsoft's own delay on directory changes.
  • Primary email. The account needs a primary email address, either its UPN or its primary SMTP address, for the teammate record to be built.
  • No group assignment. Being imported is not the same as having a signature. Add them to a group in GROUPS and the signature is generated on assignment.
  • On-premises accounts. There is no on-premises Active Directory or on-premise Exchange support. The account has to exist in Entra ID, which Microsoft's Entra Connect handles.

A newly synced teammate never got a signature

Auto install is an option on the Microsoft 365 connection under Integrations, set once for the integration rather than per group, and it is off by default. With it on, a teammate who syncs in from Entra ID has their signature installed without anyone clicking Install signature. With it off, that install is a manual step, which is the usual reason recent hires are the only people missing signatures.

Check in this order:

  1. The teammate is in a group with a template assigned. Without that there is no signature to install. On Entra ID, adding them to a group is a manual step.
  2. Auto install is on for the Microsoft 365 connection under Integrations. If it is off, install that teammate from inside their group, then turn it on so the next hire is covered.
  3. The teammate is inside the Entra ID group the add-in deployment targeted. An installed signature still needs the add-in in order to stamp anything.

This is not the explanation for a stale template edit. The add-in stamps client-side at compose time and picks up the current signature, so a template change reaches Outlook without a per-user reinstall. An old job title or an old logo is propagation: allow 5 to 10 minutes plus Microsoft's delay, then open a new compose window.

New Outlook, classic Outlook, and Outlook on the web

The add-in renders in Outlook for Windows, Outlook for Mac, Outlook on the web, Outlook for iOS, and Outlook for Android.

  • New Outlook for Windows and Outlook on the web run on the same engine. If the signature appears in one and not the other, the difference is nearly always which account is signed in.
  • Classic Outlook for Windows loads add-ins on its own schedule. A full restart is the first thing to try when everyone else in the tenant is fine.
  • Account, not client. The add-in only loads for the Microsoft 365 account the deployment targeted. A personal Microsoft account, or a mailbox from a different tenant added to the same Outlook profile, will not receive it.
  • Compose time, not send time. The signature is inserted into the draft while the person is writing. If it was never visible in the draft, it was not stamped, and the fix is on the add-in side.

Mobile behavior

Outlook for iOS and Outlook for Android are supported, and both receive the add-in through the same Centralized Deployment.

Other mobile apps will not stamp. The native iOS Mail app, the Gmail app pointed at a Microsoft account, and third-party clients do not run Outlook add-ins, and because SyncSignature stamps client-side there is no server-side rule to catch those messages. Someone who must send from one of those apps can paste their signature into the app's own signature setting, but it will not update when the template changes.

Common issues and fixes

Issue Cause Fix
Add-in is not in Outlook yet Microsoft is still pushing it Wait out the 6 to 12 hour window, then have the user restart Outlook
Teammates import, but nothing stamps Graph consent was granted, the add-in never was Approve the add-in under Settings > Integrated apps in the Microsoft 365 admin center
Consent is blocked for the person setting it up They cannot grant tenant-wide consent Have a Global Administrator connect from Integrations
One user has no signature, everyone else is fine They are in the workspace but not in a group Add them to a group in GROUPS, the signature generates on assignment
Recent hires are the only people without signatures Auto install is off, which is the default Turn on Auto install for the Microsoft 365 connection under Integrations, and install the affected teammates from inside their group
Signature shows an old job title The directory change has not propagated Allow 5 to 10 minutes plus Microsoft's delay, then open a new compose window
Works on desktop, not on a phone The phone is using a mail app that does not run the add-in Switch that user to Outlook for iOS or Outlook for Android

Still stuck? Email support@syncsignature.com and include your tenant domain, one affected user's email address, the Outlook client and platform they use, and the date the add-in was deployed.