How to Stop Employees Changing Their Signature in Outlook
Drafted with AI assistance and reviewed before publishing. How we write and source articles →
TL;DR: You sent everyone the approved signature template. Within a few weeks, half the company has quietly changed it back, added a personal quote, or reverted to something three years out of date. Microsoft 365 has no clean, single answer to actually stopping this — what exists is an all-or-nothing Outlook on the web policy toggle (Set-OwaMailboxPolicy -SignaturesEnabled $false) and a classic-Outlook-only registry key or Group Policy setting, and neither of them enforces your signature, they only disable the ability to have one at all. This article is honest about that gap, walks through both mechanisms, and explains why it’s the point at which most IT admins discover a dedicated tool exists for exactly this problem.
Someone in IT sends a company-wide email: “Please copy the attached HTML into your Outlook signature settings.” For about a week, it works. Then someone in sales adds their mobile number back in a different font. Someone in finance never applied it in the first place. Someone who joined in the meantime never got the email. Six months later, the “standardised” signature is standardised for maybe sixty percent of the company, and nobody remembers whose job it was to check.
If you’ve already read How to Manage Email Signatures Across a Company, you know why this happens — distributed self-management always drifts, because there’s no mechanism forcing consistency. This article answers the much more specific, much more mechanical question that admin ends up asking next: okay, I sent the template — how do I actually stop people from overwriting it?
The honest answer: native M365 doesn’t really let you
There is no Microsoft 365 setting called “lock the company signature.” What exists are two separate, partial mechanisms, targeting two different Outlook surfaces, and neither one enforces a specific signature — both of them only take away the ability to have a self-managed signature at all.
Outlook on the web: the OWA mailbox policy toggle
Exchange Online has a genuine, documented setting for this surface: the SignaturesEnabled parameter on an OWA mailbox policy. Setting it to $false on a policy, then assigning that policy to a mailbox via Set-CASMailbox, disables the signature-editing UI in Outlook on the web entirely for anyone on that policy.
The catch: it’s a blunt on/off switch, not a lock. SignaturesEnabled disables the signature feature — it doesn’t let you pre-load a signature and then prevent it from being edited. A user on a policy with signatures disabled simply has no signature options at all in OWA; you still need a separate mechanism to actually get your branded signature into their outgoing mail.
Classic Outlook for Windows: a registry key or Group Policy setting
On the classic Windows desktop client, the equivalent is a Group Policy Administrative Template setting — “Do not allow signatures for e-mail messages,” under Outlook’s Mail Format options — or, for organisations not using GPO, the same effect via a registry DWORD (disablesignatures, under the version-specific Common\MailSettings key in HKEY_CURRENT_USER\Software\Microsoft\Office). Both require the Outlook ADMX/ADML administrative template files to be present, or manual registry deployment via your existing endpoint management tooling.
This has the identical limitation to the OWA toggle: it turns off the ability to edit or add a signature. It doesn’t inject one.
What this doesn’t cover — and why that matters
Two honest gaps, worth stating plainly rather than discovering them after rollout:
New Outlook for Windows, Outlook for Mac, and Outlook Mobile aren’t covered by the classic-Outlook mechanism. The registry key and GPO setting are classic-Outlook-specific administrative template controls — they don’t reach the modern, web-based Outlook clients at all. Given that new Outlook for Windows is Microsoft’s actual direction of travel, a lockdown strategy built entirely on the classic-Outlook registry key is already going stale.
Neither mechanism personalises anything. Even in the (rare) case where an organisation is happy to simply disable signatures everywhere and rely on a server-side disclaimer instead, that path — Exchange mail flow rules — applies one static block of text to everyone. There’s no native way to disable self-managed signatures and have Microsoft 365 supply each person’s own name, title, and phone number in their place.
Put together: native M365 can take away an employee’s ability to touch their signature. It cannot give them back a correct one in its place. That’s the actual gap a reader hits at this point — not a missing setting, but a missing category of functionality.
What this looks like in practice
If you’re going down the native route anyway — smaller organisations, or ones with a hard requirement to avoid any third-party tooling, sometimes are — here’s the realistic combination:
- Disable self-managed signatures via the OWA policy toggle and, for any classic-Outlook holdouts, the registry key or GPO setting.
- Apply a static company disclaimer via an Exchange mail flow rule, accepting that it can’t be personalised per employee and won’t appear in the compose window or the sender’s Sent Items.
- Accept the personalisation gap, or maintain per-person transport rules — which most organisations abandon within the first dozen employees, since each rule change requires an admin, and departures/joiners/role changes need to be tracked manually.
This is the point where the “just lock it down” instinct runs out of native runway. Personalised, centrally enforced signatures that update automatically when someone’s job title changes are what the dedicated tool category in this space exists to solve — see the buying checklist for what to evaluate once you’re at that point.
Frequently asked questions
Can I lock a specific signature so employees can see it but not edit it?
Not with anything native to Microsoft 365. The OWA policy toggle and the classic-Outlook registry key both disable the signature feature outright — there’s no setting that pre-loads a fixed signature into the compose window in a read-only state. A read-only, centrally managed signature that’s still visible and personalised per employee is a dedicated-tool capability, not a native one.
Does disabling signature editing work the same way in OWA, classic Outlook, and new Outlook?
No, and this is the part most admins don’t discover until they’ve already rolled something out. The OWA mailbox policy toggle and the classic-Outlook registry key/GPO setting are two separate mechanisms covering two separate surfaces. New Outlook for Windows, Outlook for Mac, and Outlook Mobile aren’t reached by either one specifically — verify actual behaviour in your own tenant before treating either mechanism as company-wide coverage, rather than assuming parity across clients.
If I disable signatures everywhere, will Microsoft 365 apply my company signature automatically instead?
No. Disabling the self-managed signature feature only removes the employee’s ability to have one — it doesn’t add a replacement. To get any company-controlled content into outgoing mail, you need a separate mechanism: an Exchange mail flow rule (static, unpersonalised, applied after sending) or a dedicated signature management tool.
Is there a way to do this per-department rather than for the whole organisation?
Yes, for the OWA toggle specifically — mailbox policies can be created and assigned per group of users, so you could disable OWA signature editing for one department while leaving it enabled for another. The classic-Outlook registry/GPO route is typically applied via whatever OU or device-group structure your Group Policy already uses, so per-department targeting depends on how your existing GPO scoping is organised.
SigHQ is building an add-in-first email signature management tool for Microsoft 365 organisations of 50–250 employees — a centrally managed, personalised signature employees see but can’t override, without email routing through third-party infrastructure. Join the waitlist to follow progress.