Team Signatures
How to troubleshoot Microsoft 365 signature installation
Almost every Microsoft 365 signature problem is one of three things: the Outlook add-in has not been pushed yet, only one of the two grants was approved, or the teammate is not in a group with a template. Work out which half of the setup is broken, the directory half or the stamping half, and the fix is usually one step away.
Microsoft 365 setup has two grants. The Microsoft Graph consent reads your directory and takes effect immediately. The Outlook add-in, approved in the Microsoft 365 admin center through Centralized Deployment, is what stamps the signature, and Microsoft takes 6 to 12 hours to push it.
Start here: which half is broken
| What you see | Which half | Where to look |
|---|---|---|
| Teammates missing, or fields blank inside SyncSignature | Directory, the Graph consent | TEAMMATES, and the Entra ID group you scoped the import to |
| Signatures look right in SyncSignature but nothing appears in Outlook | Stamping, the Outlook add-in | Microsoft 365 admin center, Settings > Integrated apps |
| Signature appears in Outlook but shows old details | Neither, this is propagation | Allow 5 to 10 minutes after the change, then open a fresh compose window |
The add-in has not appeared in Outlook
This is the most common report, and most of the time nothing is wrong. After you approve the add-in through Centralized Deployment, Microsoft pushes it to targeted Outlook installs within 6 to 12 hours. That window belongs to Microsoft, and no setting on either side shortens it.
Things worth checking while you wait:
- In Settings > Integrated apps, confirm the app shows as deployed rather than pending.
- Confirm the affected user is inside the Entra ID group you targeted, or that the deployment was targeted at all users.
- Have the user fully quit and reopen Outlook. On Outlook on the web, sign out and back in.
- If it is past 12 hours and nobody has it, re-check the assignment target. Deploying to a group that does not contain the test user is the usual cause.
Consent errors
| Message or symptom | What it means | Fix |
|---|---|---|
| "Need admin approval" on the sign in screen | The account connecting cannot grant tenant-wide consent | A Global Administrator has to complete the connection from Integrations |
| Connection succeeds but no users import | Consent was granted on a personal account or the wrong tenant | Sign out of all Microsoft accounts, then reconnect with the work account for the correct tenant |
| The permission list looks longer than expected | It should not be | SyncSignature asks for exactly four: User.Read.All, Directory.Read.All, User.Read, offline_access. All are read-only on directory data, with no mailbox scopes |
| Directory stopped updating after working fine | Consent was revoked under Entra ID enterprise applications | Reconnect from Integrations and grant consent again |
Users missing from the Entra ID sync
Work down this list in order:
- Scope. If the import was pointed at one Entra ID group, anyone outside it will not appear. Widen the scope or add them to that group.
- Timing. A user created in Entra ID minutes ago has not synced yet. Allow 5 to 10 minutes, plus Microsoft's own delay on directory changes.
- Primary email. The account needs a primary email address, either its UPN or its primary SMTP address, for the teammate record to be built.
- No group assignment. Being imported is not the same as having a signature. Add them to a group in GROUPS and the signature is generated on assignment.
- On-premises accounts. There is no on-premises Active Directory or on-premise Exchange support. The account has to exist in Entra ID, which Microsoft's Entra Connect handles.
New Outlook, classic Outlook, and Outlook on the web
The add-in renders in Outlook for Windows, Outlook for Mac, Outlook on the web, Outlook for iOS, and Outlook for Android.
- New Outlook for Windows and Outlook on the web run on the same engine. If the signature appears in one and not the other, the difference is nearly always which account is signed in.
- Classic Outlook for Windows loads add-ins on its own schedule. A full restart is the first thing to try when everyone else in the tenant is fine.
- Account, not client. The add-in only loads for the Microsoft 365 account the deployment targeted. A personal Microsoft account, or a mailbox from a different tenant added to the same Outlook profile, will not receive it.
- Compose time, not send time. The signature is inserted into the draft while the person is writing. If it was never visible in the draft, it was not stamped, and the fix is on the add-in side.
Mobile behavior
Outlook for iOS and Outlook for Android are supported, and both receive the add-in through the same Centralized Deployment.
Other mobile apps will not stamp. The native iOS Mail app, the Gmail app pointed at a Microsoft account, and third-party clients do not run Outlook add-ins, and because SyncSignature stamps client-side there is no server-side rule to catch those messages. Someone who must send from one of those apps can paste their signature into the app's own signature setting, but it will not update when the template changes.
Common issues and fixes
| Issue | Cause | Fix |
|---|---|---|
| Add-in is not in Outlook yet | Microsoft is still pushing it | Wait out the 6 to 12 hour window, then have the user restart Outlook |
| Teammates import, but nothing stamps | Graph consent was granted, the add-in never was | Approve the add-in under Settings > Integrated apps in the Microsoft 365 admin center |
| Consent is blocked for the person setting it up | They cannot grant tenant-wide consent | Have a Global Administrator connect from Integrations |
| One user has no signature, everyone else is fine | They are in the workspace but not in a group | Add them to a group in GROUPS, the signature generates on assignment |
| Signature shows an old job title | The directory change has not propagated | Allow 5 to 10 minutes plus Microsoft's delay, then open a new compose window |
| Works on desktop, not on a phone | The phone is using a mail app that does not run the add-in | Switch that user to Outlook for iOS or Outlook for Android |
Related articles
- Install email signatures to Microsoft 365 walks through both grants in the right order.
- Connect your Microsoft Entra ID directory covers the four permissions and every field that syncs.
- What are groups explains why a teammate without a group has no signature.
- Office 365 signature management is the product overview for Microsoft 365 teams.
Still stuck? Email support@syncsignature.com and include your tenant domain, one affected user's email address, the Outlook client and platform they use, and the date the add-in was deployed.
