#Rules
Rules decide who gets which signature, and with which organization's data. Open Rules in the sidebar.
#How rules are evaluated
For each request the server goes through the enabled rules from the lowest priority number upwards. The first rule that
- is active (enabled and inside its validity period),
- whose audience matches the person, and
- whose signature has a published, enabled version
wins. If no rule matches, the default signature applies. Because evaluation stops at the first match, put specific rules first (low numbers) and general rules last.
| Priority | Audience | Signature |
|---|---|---|
| 10 | Group Executives | Executive card |
| 20 | Department = Sales | Sales card |
| 30 | E-mail ends with @subsidiary.example.com |
Subsidiary card |
| 1000 | Everyone | Default |
The table in the portal lists the rules with their priority, audience, signature, organization data and state.
#Creating a rule
Click New rule (Admins and Owners).
| Field | Meaning |
|---|---|
| Organization | Whose data (org.*: name, address, logo …) is used in the signature. Only organizations you administer are offered. |
| Signature | The signature to use. Signatures from this organization and its parents are offered; ones without a published version are marked (not published). |
| Who gets it | The audience — see below. |
| More options → Priority | Lower = earlier. Empty puts the rule at the end. |
| More options → Enabled | Switch a rule off without deleting it. |
| More options → Campaign | Optional validity period (Valid from / Valid until) in your local time. |
| More options → Description | Free-text note. |
You can also start from the signature editor: Who gets this signature → Assign to groups or people… opens this dialog with the signature already chosen.
#Audiences
The Who gets it selector has four modes.
| Mode | Matches |
|---|---|
| Everyone | Every user in the directory (that no earlier rule caught). |
| Groups and people | Users who are members of any selected Entra group, or who are one of the selected people. Membership is read from Entra right after saving and then at every directory sync. |
| By attributes | Users whose directory data fits all filled-in fields: Company (companyName), Department, E-mail ends with (for example @example.com). Empty fields are ignored. |
| Combined | Groups/people and attributes together. |
Note. Group-based audiences require the
Group.Read.AllandGroupMember.Read.Allapplication permissions (Entra setup). If the group list shows an error, fix the permissions and restart the server.
Matching on attributes is exact (case-insensitive) for company and department, and a suffix match for the e-mail ending.
#Time-limited rules (promotions)
Set Valid from and/or Valid until to limit a rule to a period, for example a seasonal signature.
- Before the start the state is Scheduled; the rule is ignored.
- During the period it is Active.
- When it ends it switches itself off (Ended), the audit log records "Campaign ended, rule switched off", and those users get the next matching signature again — usually the default.
Times are entered in your browser's time zone (shown in the hint) and stored in UTC.
For banners inside the regular signature, use Campaigns instead; they are easier to manage and have statistics.
#Rule states
| State | Meaning |
|---|---|
| Active | Enabled and within its period. |
| Scheduled | Starts in the future. |
| Ended | Its period has passed. |
| Disabled | Switched off manually. |
#Checking the result
Use Who gets which signature (Administration). Enter a person; the result states the signature and the organization used. This evaluates the same rules the add-in and agent use, so it is the best test before and after changing rules.
#Deleting rules
Deleting a rule sends its audience to the next matching rule. The confirmation text spells out the audience affected. Deletions are recorded in the audit log.
#Design tips
- Keep few rules; prefer groups over lists of people.
- Leave gaps in priorities (10, 20, 30 …) so you can insert rules later.
- Always keep a catch-all rule with the highest number so nobody is left without a signature.
- After changing rules, run the check for one person from each affected group.