Managing email signatures in Microsoft 365 sits at the crossroads of several domains: Outlook administration, Microsoft Graph interfaces, email processing architecture and Quebec compliance. This glossary gathers the 11 essential terms to navigate the subject, each defined in a self-contained, quotable way. It also acts as a gateway to our detailed guides.
Centralized signature management
Centralized signature management is the administration, from a single console, of the email signatures of every employee in an organization. Rather than letting each person compose their own in Outlook, an administrator defines templates, assigns them by group and updates the entire fleet instantly. It guarantees a consistent brand image and legal notices that are always current.
Go further: deploy a signature for the whole organization.
Event-based Outlook add-in
An event-based Outlook add-in is an extension that reacts to a mailbox event — such as composing a new message — to automatically insert the signature. It runs inside Outlook (desktop, web, Mac and mobile), at compose time, without the email ever leaving Microsoft 365. This is the approach used by ATOM Signatures.
See also: the no-routing email architecture.
Client-side vs server-side signature
A client-side signature is applied directly in the user's email application, while composing. A server-side signature is added in transit, after sending, by a server that relays every email. The distinction is decisive for confidentiality and data movement:
| Criterion | Client-side | Server-side |
|---|---|---|
| Insertion moment | At compose time, in Outlook | In transit, after sending |
| Email path | Stays within Microsoft 365 | Passes through a third-party server |
| Content exposed to the vendor | No | Yes |
| Preview before sending | Visible | Added afterwards |
Details: client-side vs server-side architecture.
Exchange transport rule
An Exchange transport rule (or mail flow rule) is a rule configured in Exchange Online that acts on emails while they are being routed. Used for signatures, it appends an HTML block to the message footer on the server side. Simple to deploy, it does not, however, show the signature in Outlook before sending and handles threaded replies poorly.
Full comparison: signatures via an Exchange transport rule.
Microsoft Graph
Microsoft Graph is Microsoft 365's unified programming interface (API) that provides authorized access to the organization's data: user profiles, groups and the Entra ID directory. A signature solution queries it to retrieve an employee's name, title, phone number or department in real time, then automatically fill in the corresponding signature fields.
Microsoft 365 group targeting
Microsoft 365 group targeting is the method of assigning a signature based on a user's membership in a security group or distribution list. The sales team gets one template, leadership another, with no individual management. Because the groups already exist in the directory, the assignment stays automatic when an employee changes role or team.
Dedicated guide: signatures by Microsoft 365 group.
Outlook on the web (OWA)
Outlook on the web (OWA, for Outlook Web App) is the browser version of Outlook included in Microsoft 365, usable without installing any software. A signature deployed through an event-based add-in must work there just as on desktop and mobile Outlook, so the user gets exactly the same signature regardless of the device or platform used.
Cross-platform coverage: Outlook signatures on Mac and mobile.
Confidentiality notice / disclaimer
A confidentiality notice (or disclaimer) is the legal text added to an email footer: a confidentiality clause, environmental note or legal warning. Managed centrally, it applies uniformly across the whole organization and updates in a single action, which avoids stale or inconsistent versions from one employee to the next.
Learn more: the email confidentiality notice.
Law 25
Law 25 is Quebec's reform of personal information protection, phased in from 2022 to 2024 and administered by the Commission d'accès à l'information (CAI). It governs the collection, hosting and communication outside Quebec of personal information — including that contained in an email signature — and notably provides a right to erasure.
Complete guide: email signatures and Law 25.
Data sovereignty
Data sovereignty is the principle that data is subject to the laws of the country where it is physically hosted. For a Quebec organization, hosting signature data in Canada shields it from foreign access laws (such as the US CLOUD Act) and simplifies demonstrating Law 25 compliance.
HTML signature
An HTML signature is an email signature block built in HTML rather than plain text, which enables formatting: a logo, brand colours, clickable links, social media icons and structured contact details. For reliable rendering in Outlook, it relies on table-based markup and inline styles compatible with Microsoft's rendering engine.
See: email signature templates and the Microsoft 365 signature guide.
Frequently asked questions
What is a centrally managed email signature?
It is a signature administered from a single console for all employees, rather than composed individually in Outlook. An administrator defines templates, assigns them by Microsoft 365 group and updates the whole fleet in one action, ensuring a consistent brand and up-to-date legal notices.
What is the difference between a client-side and a server-side signature?
A client-side signature is inserted in Outlook while composing by an add-in; the email never leaves Microsoft 365. A server-side signature is added in transit by a server that relays every message, exposing the email content to the vendor and possibly routing it out of the country.
Why do these terms matter for Law 25 compliance?
Because a signature contains personal information and the technical architecture determines where that data travels. Understanding client-side processing, transport rules, data sovereignty and Canadian hosting helps a Quebec organization assess its exposure under Law 25.
Microsoft 365 signatures, hosted in Canada. ATOM Signatures applies your organization's signature in Outlook, client-side, with group targeting and real-time data via Microsoft Graph — CAD $1 per user per month, all included.
Go further: the Microsoft 365 signature guide and the best solution in Canada.
Sources
- Commission d'accès à l'information du Québec — cai.gouv.qc.ca
- Microsoft Graph documentation — learn.microsoft.com/graph
- Event-based Outlook add-ins — learn.microsoft.com
The definitions touching on Law 25 are provided for information purposes and do not constitute legal advice. To assess your situation, consult a legal advisor or the Commission d'accès à l'information.