Deploying Sigil through Microsoft 365 Integrated apps
From admin consent to an organisation-wide rollout you can prove, in nine steps. The detail is in the docs; this is the order to do things in and what to expect at each stage.
1. Prerequisites
- Microsoft 365 with Exchange Online. Centralised deployment does not reach on-premises mailboxes (Microsoft Learn: determine if centralised deployment works for your organisation).
- An account that can grant admin consent and deploy add-ins. Microsoft recommends Global Administrator for the add-in lifecycle (Microsoft Learn: centralised deployment FAQ).
- Clean directory data for the people in your pilot: job title, department, phone. The signature is only as good as Entra ID.
- A decision on who owns the template. Marketing usually does; IT owns deployment. Sigil has separate roles for each.
2. Grant admin consent
Sign in to the portal with an administrator account and connect your organisation. Sigil asks for three read-only Microsoft Graph application permissions: User.Read.All, Organization.Read.All and GroupMember.Read.All. Nothing that can write to your tenant or send mail is requested; the security overview explains each one. Docs: Connect your organisation.
3. Deploy the add-in through Integrated apps
In the Microsoft 365 admin centre, go to Settings, then Integrated apps, and add the Sigil add-in. Assign it to a group for now rather than to everyone (step 6). A green tick in the admin centre means Microsoft has accepted the deployment, not that every client has it: Microsoft says a new add-in can take up to 24 hours to appear for all users, and up to 72 hours for later add-in updates, and users may need to restart Outlook (Microsoft Learn: centralised deployment FAQ). Docs: Deploy the Outlook add-in.
4. Create the first template
Sigil ships with a ready-made template. Use it as it is, or recreate your current signature in the drag-and-drop designer or the HTML editor, with placeholders for the directory fields. Preview it against real people, including someone with an empty field, to check the conditional sections hide what should be hidden. Docs: Templates.
5. Set assignment rules
Assignment rules pick a template per person by department, office, email domain or Entra group membership. They are ordered and the first match wins; everyone else gets the organisation-wide default. For a pilot, one rule that targets the pilot group is enough. Docs: Assignment rules.
6. Pilot with a group
Microsoft’s recommended rollout for any add-in is stakeholders and IT first, then a wider group, then everyone (Microsoft Learn: recommended rollout strategy). Do the same here: assign the add-in to a pilot group in Integrated apps, and use Sigil’s staged rollout to publish the template to that group first. Ask the pilot to send a new message, a reply and a message from a shared mailbox, on desktop and on the phone. Docs: Staged rollouts.
7. Roll out organisation-wide
Change the Integrated apps assignment from the pilot group to everyone (or to the groups you want covered), then publish the template organisation-wide. Allow the same 24 hours for Microsoft to push the add-in to the rest of the tenant. From here on, template changes are a Sigil publish and reach the next message each person writes; there is nothing to redeploy.
8. Verify with the adoption report
The Activity view in the portal lists every mailbox with its last applied signature and template version, and a never-applied list of mailboxes that have not applied one yet. Work that list: it is usually a client that has not restarted, a user outside the assignment, or a mailbox Outlook does not run add-ins in. The attribute coverage report shows which directory fields are still empty. Docs: Activity, Troubleshooting.
9. Rolling back
- A bad template change: every publish is versioned; roll back to the previous version in one click and the next message carries it.
- Pausing for a group: narrow the assignment rule or the staged rollout; those users fall back to the default or to their own Outlook signature.
- Removing Sigil entirely: turn the add-in off or delete it in Integrated apps. Microsoft says removal can take up to 24 hours to reach every user (Microsoft Learn: centralised deployment FAQ). Because Sigil never touched mail flow, there is nothing else to unwind.
Coming from another product? The migration guides for Exclaimer and CodeTwo cover running both in parallel during the pilot. For the background on why client-side deployment works the way it does, read managing Outlook signatures across Microsoft 365.