- Adobe Acrobat Sign User's Guide
- What's New
- Get Started
-
Recipient experiences
- Email options
-
E-signing page options
- The recipient's e-signing page
- Open a view to read the agreement
- Decline to sign the agreement as a recipient
- Delegate your authority in the agreement to another person
- Restart the agreement from the first recipient
- Download a PDF of the agreement
- View the events in the agreement history
- View the agreement messages from the sender
- Convert an agreement to be printed and manually signed
- Convert a written signature process back to electronic signature
- Navigate through the form fields of the agreement
- Recipient e-signing experience when using Mobile Focus
- Clear the data you have entered into the agreement fields
- E-sign page magnification and navigation
- Change the language of the page controls
- Review the Legal Notices for Adobe Acrobat Sign
- Adjust your Cookie Preferences
-
Users
- Profile and preferences
- Sharing user content
- Address book
- Home page
-
Send agreements
- Send page overview
- Recipient signing order - signature cycle
- Compose a hybrid recipient workflow
- Send an agreement with only yourself as a signer
- Request signatures from others
- Send an agreement using e-Witnesses
- Use templates to send agreements
- Obtain a written signature
- Compose an agreement for in-person signing in Acrobat Sign
- Set a completion deadline in Adobe Acrobat Sign
- Add a password to protect viewing of the PDF
- Use clickable links in message fields
- Sign agreements
-
Manage agreements
- Overview of the Manage page
- Create a copy of an agreement
- Replace a recipient in an active agreement
- Cancel an agreement in Adobe Acrobat Sign
- Add and edit reminders from the Manage page
- Review an agreement's reminders
- Cancel a reminder for an agreement
- Text search in Adobe Acrobat Sign
- Open and View an agreement
- Create a template from an agreement
- Hide or Unhide an agreement from view on the Manage page
- Upload a signed copy of the agreement
- Modify a sent agreement's documents or fields
- How to edit a recipient's authentication method after the agreement has been sent
- Add, edit, or remove the Expiration Date (Completion Date)
- Add a note to a signing transaction
- Share an individual agreement
- Unshare an agreement
- Download the PDF of an agreement
- Download the individual files of an agreement
- Export the field data for an individual agreement
- Remove a recipient from an in-progress agreement
- Resume a paused agreement
- Bulk actions
- Audit reports
-
Reporting and Exporting data
- Reports and Data Exports
- Edit an existing Report chart
- Transaction consumption reports
- Agreement reports
- Create a new report chart
- Download the content of a data export
- Refresh the content in an existing data export
- Edit an existing data export
- Web form data export
- Create a new data export
- Rename an export or chart report
- Duplicate an export or chart report
- Schedule an export or chart report
- Delete an export or chart report
-
Form field authors
- In-app authoring environment
- Create forms with text tags
- Create forms with Acrobat
- Form field reference
- Setting form field show/hide conditions
- Add calculated fields to a form
- Verified forms
- Adobe Acrobat Sign Authoring - FAQ
-
Advanced users
- Send in Bulk
- Webforms
- Reusable templates
- Custom workflows
-
Power Automate Workflows
- Overview and entitlements included with the Microsoft Power Automate integration
- Enable the Power Automate integration
- In-Context Actions for Power Automate on the Manage Page
- Track your Power Automate usage
- Create a new Power Automate flow in the Acrobat Sign environment
- Triggers for Power Automate flows
- Import external Power Automate flows into Acrobat Sign
- Access and manage your Power Automate flows
- Edit Power Automate flows within the Acrobat Sign environment
- Share Power Automate flows to other users in your Acrobat Sign organization
- Disable Power Automate flows
- Delete Power Automate flows
-
Useful PA Templates for Admins
- Save all completed documents to SharePoint
- Save all completed documents to OneDrive for Business
- Save all completed documents to Google Drive
- Save all completed documents to DropBox
- Save all completed documents to Box
- Save your completed documents to SharePoint
- Save your completed documents to One Drive for Business
- Save your completed documents to Google Drive
- Save your completed documents to Box
- Save completed webform documents to SharePoint Library
- Extract field data from your signed document and update Excel sheet
- Get your Adobe Acrobat Sign notifications in a Teams Channel
- Generate doc from Power App form and Word template, send for signature
-
Administers
- Set up your Acrobat Sign company account
-
User provisioning
- Authenticate your signers using your SSO solution (and optionally entitle them to use the Acrobat Sign product)
- Enable SSO for direct Acrobat Sign access
- Provision Acrobat Sign users with SSO
- Configure user auto-assignment rules
- Move a user from one Admin Console organization to another
- Create Technical Accounts to send agreements via API
- Create Service Accounts to send agreements under a functional entity
-
User management
- Change your email or name in Acrobat Sign
- Edit a user's group membership
- Grant users access to reporting data
- Set authority levels for admins and users
- Edit a user’s Admin Console roles
- Promote users to privacy admin status
- Manage user and group content shares
- Log in to your Adobe Acrobat Sign account
- Group management
- Asset management
- Admin reports
-
Settings configuration
- Configuring the Adobe Acrobat Sign environment
-
Global Settings
- Enable the modern Recipient Experience
- Configure Self Signing Workflows
- Configure access to Send in Bulk
- Configure Web Forms
- Enable Custom Send Workflows
- Configure access to Power Automate workflows
- Configure access to create reusable library templates
- Collect form data with agreements
- Limit document visibility for agreement participants
- Attach a PDF copy of the signed document in emails sent to
- Suppress the email link to the online signed agreement
- Suppress the image of the first page of the agreement in emails
- Files attached to email will be named as
- Attach audit report to emails and downloads in Acrobat Sign
- Merge multiple documents into one document after signing
- Allow recipients to download individual files
- Empower senders to upload physically signed documents
- Adobe Acrobat Sign delegation settings for internal users
- Set a default time zone to use for agreements
- Configure the default date format to use for agreements and signatures
- Upgrade your account to allow Users in Multiple Groups (UMG)
- Assign users to multiple groups
- Group Administrator Permissions
- Configure the option to replace a recipient on an agreement
- Configure the content of your Audit Reports
- Verify agreement validity
- Include view events in the audit report
- Include page counts in the audit report
- Add the transaction ID and document name to each page of the agreement
- Enable in-product messaging and guidance
- Enforce PDF/A workflows for long-term archiving
- Enable the Acrobat Sign Smart Assistant Chatbot
- Configure the New request signature experience
- Enable the New custom workflow experience
- Enable the modern Create Template experience
- Account Setup / Branding Settings
-
Signature Preferences
- Configure well-formatted signatures
- Configure how you will allow recipients to sign and initial agreements
- Capture signature on mobile device
- Configure Terms of Use and Consumer Disclosure acceptance
- Hiding Guided Navigation While Signing
- Allow recipients to restart agreements
- Configure Decline options for recipients
- Allow Stamp Images and Signatures
- Allow signers to print, place written signatures and upload the agreem
- Set up Mandatory Mobile Signature Capture
- Request IP address from recipients for the audit report
- Enable drawn signature scaling
-
Digital Signatures
- Overview of Digital Signatures in Adobe Acrobat Sign
- Download and sign with an Acrobat certificate
- Enable cloud-based digital signatures
- Configure bulk digital signatures from Manage in Acrobat Sign
- Require digital signatures for specific recipients
- Send metadata to the cloud signature provider
- Configure a restricted Identity Provider
- Configure auto-provisioning for partner applications
- Create electronic seals in Adobe Acrobat Sign
- Digital Identity
- Report Settings
-
Security Settings
- Restrict user access to Acrobat Sign using allowed IP address ranges
- Administrator managed sharing
- Configure Account Sharing Permissions
- Agreement sharing controls
- Signer Identity Verification
- Define the complexity of user-applied passwords
- Block signers within a specific geography
- Allow page extraction from agreement PDFs
- Document link expiration
- Stand-alone timestamp certificates for electronic signatures
- Block iframe embedding in Acrobat Sign
-
Send Settings
- Configure document editing during authoring
- Agreement creation experiences
- Require recipient name when configuring an agreement or web form
- Lock Name values for known users when authenticating
- Allow various recipient roles
- Configure the e-Witness role for recipients
- Configure in-person signing in Acrobat Sign
- Enable recipient groups
- Configure CC notifications as part of a recipient record
- Configure OneDrive file upload
- Automatically "flatten" PDF documents when uploaded
- Allow User to Modify Agreements
- Remove recipients from in-flight agreements
- Enable private messages to recipients
- Allowed signature types
- Set reminders for the agreement recipients
- Allow senders to add passwords to protect viewing the agreement PDF
- Send notifications through SMS or WhatsApp in Adobe Acrobat Sign
- Adobe Acrobat Sign Identity Authentication Methods
- Signing Password
- Knowledge-based authentication
- Configure phone authentication
- WhatsApp authentication
- Configure one-time password via email authentication
- Acrobat Sign Authentication
- Cloud-based digital signatures
- Digital Identity Provider authentication
- Government ID authentication
- Signer Identity Report
- Configure Content Protection
- Configure Automatic Document Expiration (Completion deadline)
- Signature order options
- Configure hybrid recipient routing
- Configure internal recipient restrictions in Acrobat Sign
- Configure the Download agreement link
- Form Field Borders
- Liquid Mode for Mobile Web Signing Experience
- Enable Template-Defined Signature Placement in Custom Workflows
- Enable Acrobat Sign to tag uploaded PDFs for accessibility
- Restricted access to agreements
- Message Templates
- Bio-Pharma Settings
- Notarize integration with Acrobat Sign
- Set up online payments
- SAML Settings
- Data Governance
- Set up an archive for your agreements
-
Email Settings
- Email header and footer images
- Enable and configure the user's personal email footer
- Adobe Acrobat Sign - Suppress email addresses in agreement notifications
- Adobe Acrobat Sign - Suppress email addresses in To and CC fields of the email header
- Enable linkless notifications
- Use customized email templates
- Understand the Acrobat Sign tracking pixel
- Migrating from echosign.com to adobesign.com
- Customize the Options for Recipients on the e-sign page
-
Guidance for regulatory demands
- Accessibility
- HIPAA configurations in Adobe Acrobat Sign Solutions
- GDPR
- 21 CFR part 11 and EudraLex Annex 11
- EU/UK considerations
- Comply with IVES
- Report Abuse links
-
Integrations
- Adobe Acrobat Sign Integrations
- Product versions and lifecycle
- Integration keys
-
Acrobat Sign for Salesforce
- Acrobat Sign for Salesforce: Install the package (v24)
- Acrobat Sign for Salesforce: Configure the package
- Adobe Acrobat Sign for Salesforce: Upgrade Guide
- Adobe Acrobat Sign for Salesforce: Release notes
- Adobe Acrobat Sign for Salesforce (Lightning profile): User Guide
- Acrobat Sign for Salesforce Mobile
- Enable authentication with digital identity providers
- Adobe Acrobat Sign for Salesforce: Mappings and Templates Guide
- Using Acrobat Sign Document Builder for Salesforce
- Configure Large Documents and Push Agreements Service
- Adobe Acrobat Sign for Salesforce: Customization Guide
- Adobe Acrobat Sign for Salesforce: Developer Guide
- Acrobat Sign for Salesforce: Other Guides
- Adobe Acrobat Sign for Salesforce: FAQs
- Acrobat Sign for Salesforce: Troubleshooting Guide
- Microsoft: Office
- Microsoft: Teams
-
Microsoft: Dynamics
- Acrobat Sign for Microsoft Dynamics
- Adobe Acrobat Sign for Microsoft Dynamics 365 Online: Installation Guide
- Adobe Acrobat Sign for Microsoft Dynamics Online: User Guide
- Adobe Acrobat Sign for Microsoft Dynamics 365 On-Premises: Installation Guide
- Adobe Sign for Microsoft Dynamics On-Premises: User Guide
- Adobe Acrobat Sign for Microsoft Dynamics Workflows: User Guide
- Adobe Acrobat Sign for Microsoft Dynamics 365 Talent
- Adobe Sign for Microsoft Dynamics: Upgrade Guide
- Adobe Acrobat Sign for Microsoft Dynamics 365: Release Notes
- Microsoft: Power Automate
- Microsoft: Search connector
- ServiceNow
- SAP SuccessFactors
- Workday
- NetSuite
- Adobe Acrobat Sign for SugarCRM
- VeevaVault
- Adobe Acrobat Sign for Coupa BSM Suite: Installation Guide
- Zapier
-
Developers
- REST APIs
- Webhooks
- Sandbox
- System-level resources
- Support
Understand customer-managed encryption in Acrobat Sign
This article contains prerelease information. Release dates, features, and other information are subject to change without notice.
Learn how Acrobat Sign uses your organization's encryption key to protect supported content at rest and what happens throughout the encryption lifecycle.
Customer-managed encryption lets your organization control the key used to protect supported Adobe Acrobat Sign content at rest.
Your organization provisions and controls the encryption key in AWS Key Management Service (KMS). Acrobat Sign uses that key as part of its encryption process while continuing to manage the storage, processing, and delivery of supported content.
This model gives your organization control over a critical part of the encryption chain without changing how senders and recipients normally work with agreements.
How customer-managed encryption works
Acrobat Sign uses a customer-specific encryption model for supported content.
At a high level:
- Your organization creates and controls a key in AWS KMS.
- An account administrator configures Acrobat Sign to use that key.
- Acrobat Sign validates that it can access the key.
- Supported content is encrypted using the customer-managed encryption configuration.
- When protected content must be accessed, Acrobat Sign must be able to use the configured key.
The AWS KMS key remains under your organization's control. Acrobat Sign does not take ownership of the key.
Customer-managed encryption protects data at rest
Customer-managed encryption applies to supported content while it is stored by Acrobat Sign.
It does not replace the encryption Acrobat Sign already uses to protect information while it is transmitted. Existing protections for data in transit continue to apply.
Not every type of data stored by Acrobat Sign is currently protected by the customer-managed key.
For the current protection scope, see Customer-managed encryption considerations and limitations.
What happens when customer-managed encryption is enabled
After customer-managed encryption is configured and enabled, supported newly created content is protected using the configured customer-managed key.
This includes supported content created as part of normal agreement and template workflows.
Senders do not choose an encryption key when creating an agreement. Encryption is applied automatically according to the account-level configuration.
Recipients likewise do not need to take any additional action because customer-managed encryption does not change the normal signing experience.
Existing content can be migrated
Enabling customer-managed encryption does not require existing content to remain permanently under Adobe-managed encryption.
Account administrators can start a background migration that re-encrypts eligible existing content using the configured customer-managed key.
While migration is underway, the account can contain both:
- content already protected using the customer-managed key; and
- content that remains protected using Adobe-managed encryption.
Both states are supported during the transition, and agreements remain available while the migration proceeds.
For instructions on migrating existing content and monitoring the operation, see Manage customer-managed encryption keys.
Acrobat Sign must retain access to the key
Because your organization controls the AWS KMS key, continued access to that key becomes part of the availability model for protected content.
Acrobat Sign maintains cached key-encryption information for a configurable period. The Time to Live (TTL) setting determines how long that cached information remains usable before Acrobat Sign must access AWS KMS again.
The supported TTL is 5 to 60 minutes.
If Acrobat Sign loses access to the AWS KMS key, previously cached information can allow access to continue temporarily. After the TTL expires, content that depends on the unavailable key can no longer be accessed until key access is restored.
This means changes such as disabling the key, revoking credentials, or removing the required IAM permissions can affect access to protected Acrobat Sign content.
For key-access failures and recovery steps, see Troubleshoot customer-managed encryption.
AWS key rotation does not necessarily change the Acrobat Sign configuration
AWS KMS can rotate the underlying cryptographic material for a customer-managed key while retaining the same key ARN.
When AWS rotates the key material and the key ARN remains unchanged, Acrobat Sign continues to reference the same configured key.
This differs from replacing the configured AWS KMS key with another key. See Manage customer-managed encryption keys for supported key-management operations.
You can verify how an agreement is currently protected
During a migration, individual agreements can be at different stages of the encryption transition.
The Protection Information action on the agreement's Manage page lets users with access to the agreement check whether its documents are currently protected using:
- the organization's customer-managed encryption key; or
- Adobe-managed encryption.
This provides a direct way to verify the protection state of a specific agreement without relying on the status of an account-wide migration.
What happens when customer-managed encryption is disabled
Customer-managed encryption can be disabled without permanently making previously protected content dependent on the customer key.
When an administrator disables customer-managed encryption, Acrobat Sign starts a background operation that returns eligible customer-key-protected content to Adobe-managed encryption.
The customer-managed AWS KMS key must remain accessible while this operation is running because Acrobat Sign still needs it to read content that has not yet been migrated.
During the transition, some content can remain protected by the customer-managed key while other content has already returned to Adobe-managed encryption.
Once the migration is complete, the migrated content no longer depends on the customer-managed key.
Customer-managed encryption does not change agreement workflows
Customer-managed encryption operates as an account-level security capability.
It does not require senders to:
- select encryption when creating agreements;
- choose an AWS KMS key;
- change recipient configuration; or
- modify normal sending workflows.
Recipients do not see a different signing workflow because an agreement uses customer-managed encryption.
The primary operational responsibility belongs to the administrators responsible for the Acrobat Sign account and the organization's AWS KMS resources.