What the admin console gives you
The append footer
In the admin console you can append a footer to outbound mail for the domain or an org unit. It is useful for a single legal line and it applies regardless of which client someone uses.
Its limits are the same as any server-side approach:
- It is the same text for everyone in scope, with no per-person data.
- It lands at the bottom of the thread rather than under the message the person wrote.
- The sender does not see it while writing, so people ask why their signature is missing.
- Formatting options are basic, and it is not where you put a designed signature with a logo.
The signature in Gmail settings
This is the signature people mean. It lives in each user's Gmail settings, it can differ per send-as address, it sits under the message and above the quoted text, and it holds a real layout with a hosted logo. It is also, by default, set by each user individually, which is the whole problem.
Managing it centrally
One template written into every account
Central management writes the rendered signature into each user's Gmail signature settings, filled from their directory profile. In practice that means:
- Connect the tenant. An administrator authorises the connection and confirms which org units are in scope. The authorisation is listed with your other connected applications and revocable from your own console.
- Map the profile fields. Name, job title, department, phone, office and photo come from the directory, so the lines that change most are the ones nobody retypes.
- Design one template, with the blocks you want: logo, banner, disclaimer, meeting link.
- Group by org unit, because your directory already reflects how the company is organised.
- Include the send-as addresses. Someone answering from a shared support address should sign as support, not as themselves, and that is a separate template on the same account.
- Deploy, preview and keep the history, so a mistake is one click to undo rather than an email to everyone.
The mobile app
The Gmail app on a phone uses the account signature when it is set to do so. A desktop signature there becomes several wrapped lines, so the mobile variant is shorter by design: name, title, company, one number. Preview it before deploying, because that is the version most of your replies will carry.
Questions that come up
Can people still change their own signature?
Gmail lets them, and the next rollout restores the managed one. If a team genuinely needs something different, give the team its own group and its own template rather than leaving it to individuals.
What about people who joined last week?
A joiner in the right org unit is signed correctly on the first message they send, from their directory profile. That is the single biggest reason companies stop handling signatures by email instructions.
Do we need a service account or a Cloud project?
No. The authorisation happens in the admin console, and that is the whole setup on your side.
We also have Microsoft mailboxes.
Common after an acquisition, and it works in one account: the Microsoft side is described on the Office 365 email signature management page, sharing the same template sets. The Google side in full is on the Google Workspace email signature management page, and the client itself on the Gmail signature management page.