Microsoft 365 email signature for the whole company, step by step

Setting one signature for everybody in a Microsoft 365 tenant sounds like an afternoon of admin, and then you discover there are two mechanisms, they do different things, and neither was designed for what you want. Here is the whole picture, in the order you will meet it.

On this page
  1. The two mechanisms
  2. The three do-it-yourself approaches, and where each one ends
  3. The company-wide way
  4. Five details worth knowing before the first rollout
  5. What company-wide actually requires

The two mechanisms

Organisation-wide disclaimers, the server-side route

In the Exchange admin centre you can create a mail flow rule that appends HTML to messages leaving the organisation. Exchange calls this a disclaimer, and for a legal footer that is exactly what it is.

What it does well: it applies to every message from every client, including phones and any device you do not manage, and the sender cannot remove it.

What it does not do:

  • The sender never sees it. The compose window and Sent Items show the message without the block, which generates its own support tickets from people who think their signature is missing.
  • It appends at the very bottom, under the quoted thread. Ten replies later the recipient scrolls past ten copies.
  • Personalisation is limited to a handful of directory attributes, and the formatting options are thin compared with a designed signature.
  • It is skipped on encrypted mail. In a regulated business that is often the mail that most needs the wording.
  • Because the block is inserted into an already composed message, images and layout are fragile.

Client-side signatures, the route people actually mean

This is the signature under the message, above the quoted text, with the person's name, title, phone and the company logo. Historically it lived on each person's computer, which is why it disappeared with every new laptop. Roaming signatures changed that: the signature travels with the mailbox, so the new Outlook, Outlook on the web and classic Outlook all show the same thing.

That is the mechanism worth building a company standard on. The problem is that Microsoft gives you no way to set it for everybody.

The three do-it-yourself approaches, and where each one ends

  • Email everyone the HTML with instructions. Roughly half the company does it, a quarter does it wrong, and the rest never gets to it. Six months after a rebrand you still have two logos in circulation.
  • Script it. Writing signature files into user profiles with a script works until someone gets a new machine, works badly for Mac users, does nothing for Outlook on the web and nothing at all for phones. It also becomes the one script nobody wants to inherit.
  • Put everything in a transport rule. It applies to everything, and it puts your brand under the quoted thread where nobody looks, invisible to the person who sent it.

None of these are bad instincts. They are just three ways of discovering that a signature is a per-mailbox setting and that a company needs it to be a central one.

The company-wide way

Set the template once and deploy it to the tenant

Central management writes the rendered signature to each mailbox, filled per person from the directory. The steps look like this:

  • Connect the tenant. A global administrator approves a scoped consent: read directory profiles, set signatures on the mailboxes in scope. Nothing is installed anywhere.
  • Map the fields. Name, job title, department, phone, mobile, office, photo and pronouns are mapped once to the tokens in the template. Missing values collapse their own line rather than leaving a gap.
  • Design the template. One layout, your brand, and the blocks you want: banner, disclaimer, social links, meeting link.
  • Preview per client. Outlook on Windows, the new Outlook, Outlook on the web, Apple Mail and mobile each treat HTML differently, so look at all of them before anyone else does.
  • Deploy by group. Department, office, country or entity. Start with one group, read the result, then widen.
  • Keep the history. Every rollout is a version, and rollback puts a group back the way it was in one click.

What to do about the disclaimer

If you already have a mail flow rule for the legal wording, you can keep it and let the managed signature own everything visible. Or you can move the wording into the template as a rule by country and entity, which puts it above the quoted thread where people read it, and retire the transport rule. Both are reasonable, and the comparison is on the Exchange email signature management page.

Five details worth knowing before the first rollout

  • Directory quality decides signature quality. If half the company has no job title in the directory, that shows up the moment you deploy. Do a read-only pass first and fix the records.
  • Phones need their own variant. A desktop signature squeezed into a phone screen is four lines of wrapped text. Deploy a short mobile block instead.
  • Replies need a short block. Otherwise a long thread collects the same logo fifteen times and every one of them is a downloaded image.
  • Images must be hosted and linked, at the right size and with alt text, because plenty of clients block images by default.
  • Dark mode. A dark logo on a transparent background disappears in a dark Outlook theme. Check it in the preview, not in production.

What company-wide actually requires

One template, filled from the directory, written to every mailbox, previewed per client, deployed per group and reversible. Microsoft gives you the mailbox and the directory. The management layer is what turns those into one correct signature per person.

AutoSignature does that for Microsoft 365 and for Google Workspace in the same account, for a flat price per company. The builder on the homepage renders a real signature without an account, so you can see the output before you connect anything.

Build your signature