- Adobe Acrobat Sign User's Guide
- What's New
- Get Started
-
Recipient experiences
- Email options
-
E-signing page options
- The recipient's e-signing page
- Open a view to read the agreement
- Decline to sign the agreement as a recipient
- Delegate your authority in the agreement to another person
- Restart the agreement from the first recipient
- Download a PDF of the agreement
- View the events in the agreement history
- View the agreement messages from the sender
- Convert an agreement to be printed and manually signed
- Convert a written signature process back to electronic signature
- Navigate through the form fields of the agreement
- Recipient e-signing experience when using Mobile Focus
- Clear the data you have entered into the agreement fields
- E-sign page magnification and navigation
- Change the language of the page controls
- Review the Legal Notices for Adobe Acrobat Sign
- Adjust your Cookie Preferences
-
Users
- Profile and preferences
- Sharing user content
- Address book
- Home page
-
Send agreements
- Send page overview
- Recipient signing order - signature cycle
- Compose a hybrid recipient workflow
- Send an agreement with only yourself as a signer
- Request signatures from others
- Send an agreement using e-Witnesses
- Use templates to send agreements
- Obtain a written signature
- Compose an agreement for in-person signing in Acrobat Sign
- Set a completion deadline in Adobe Acrobat Sign
- Add a password to protect viewing of the PDF
- Use clickable links in message fields
- Sign agreements
-
Manage agreements
- Overview of the Manage page
- Create a copy of an agreement
- Replace a recipient in an active agreement
- Cancel an agreement in Adobe Acrobat Sign
- Add and edit reminders from the Manage page
- Review an agreement's reminders
- Cancel a reminder for an agreement
- Text search in Adobe Acrobat Sign
- Open and View an agreement
- Create a template from an agreement
- Hide or Unhide an agreement from view on the Manage page
- Upload a signed copy of the agreement
- Modify a sent agreement's documents or fields
- How to edit a recipient's authentication method after the agreement has been sent
- Add, edit, or remove the Expiration Date (Completion Date)
- Add a note to a signing transaction
- Share an individual agreement
- Unshare an agreement
- Download the PDF of an agreement
- Download the individual files of an agreement
- Export the field data for an individual agreement
- Remove a recipient from an in-progress agreement
- Resume a paused agreement
- Bulk actions
- Audit reports
-
Reporting and Exporting data
- Reports and Data Exports
- Edit an existing Report chart
- Transaction consumption reports
- Agreement reports
- Create a new report chart
- Download the content of a data export
- Refresh the content in an existing data export
- Edit an existing data export
- Web form data export
- Create a new data export
- Rename an export or chart report
- Duplicate an export or chart report
- Schedule an export or chart report
- Delete an export or chart report
-
Form field authors
- In-app authoring environment
- Create forms with text tags
- Create forms with Acrobat
- Form field reference
- Setting form field show/hide conditions
- Add calculated fields to a form
- Verified forms
- Adobe Acrobat Sign Authoring - FAQ
-
Advanced users
- Send in Bulk
- Webforms
- Reusable templates
- Custom workflows
-
Power Automate Workflows
- Overview and entitlements included with the Microsoft Power Automate integration
- Enable the Power Automate integration
- In-Context Actions for Power Automate on the Manage Page
- Track your Power Automate usage
- Create a new Power Automate flow in the Acrobat Sign environment
- Triggers for Power Automate flows
- Import external Power Automate flows into Acrobat Sign
- Access and manage your Power Automate flows
- Edit Power Automate flows within the Acrobat Sign environment
- Share Power Automate flows to other users in your Acrobat Sign organization
- Disable Power Automate flows
- Delete Power Automate flows
-
Useful PA Templates for Admins
- Save all completed documents to SharePoint
- Save all completed documents to OneDrive for Business
- Save all completed documents to Google Drive
- Save all completed documents to DropBox
- Save all completed documents to Box
- Save your completed documents to SharePoint
- Save your completed documents to One Drive for Business
- Save your completed documents to Google Drive
- Save your completed documents to Box
- Save completed webform documents to SharePoint Library
- Extract field data from your signed document and update Excel sheet
- Get your Adobe Acrobat Sign notifications in a Teams Channel
- Generate doc from Power App form and Word template, send for signature
-
Administers
- Set up your Acrobat Sign company account
-
User provisioning
- Authenticate your signers using your SSO solution (and optionally entitle them to use the Acrobat Sign product)
- Enable SSO for direct Acrobat Sign access
- Provision Acrobat Sign users with SSO
- Configure user auto-assignment rules
- Move a user from one Admin Console organization to another
- Create Technical Accounts to send agreements via API
- Create Service Accounts to send agreements under a functional entity
-
User management
- Change your email or name in Acrobat Sign
- Edit a user's group membership
- Grant users access to reporting data
- Set authority levels for admins and users
- Edit a user’s Admin Console roles
- Promote users to privacy admin status
- Manage user and group content shares
- Log in to your Adobe Acrobat Sign account
- Group management
- Asset management
- Admin reports
-
Settings configuration
- Configuring the Adobe Acrobat Sign environment
-
Global Settings
- Enable the modern Recipient Experience
- Configure Self Signing Workflows
- Configure access to Send in Bulk
- Configure Web Forms
- Enable Custom Send Workflows
- Configure access to Power Automate workflows
- Configure access to create reusable library templates
- Collect form data with agreements
- Limit document visibility for agreement participants
- Attach a PDF copy of the signed document in emails sent to
- Suppress the email link to the online signed agreement
- Suppress the image of the first page of the agreement in emails
- Files attached to email will be named as
- Attach audit report to emails and downloads in Acrobat Sign
- Merge multiple documents into one document after signing
- Allow recipients to download individual files
- Empower senders to upload physically signed documents
- Adobe Acrobat Sign delegation settings for internal users
- Set a default time zone to use for agreements
- Configure the default date format to use for agreements and signatures
- Upgrade your account to allow Users in Multiple Groups (UMG)
- Assign users to multiple groups
- Group Administrator Permissions
- Configure the option to replace a recipient on an agreement
- Configure the content of your Audit Reports
- Verify agreement validity
- Include view events in the audit report
- Include page counts in the audit report
- Add the transaction ID and document name to each page of the agreement
- Enable in-product messaging and guidance
- Enforce PDF/A workflows for long-term archiving
- Enable the Acrobat Sign Smart Assistant Chatbot
- Configure the New request signature experience
- Enable the New custom workflow experience
- Enable the modern Create Template experience
- Account Setup / Branding Settings
-
Signature Preferences
- Configure well-formatted signatures
- Configure how you will allow recipients to sign and initial agreements
- Capture signature on mobile device
- Configure Terms of Use and Consumer Disclosure acceptance
- Hiding Guided Navigation While Signing
- Allow recipients to restart agreements
- Configure Decline options for recipients
- Allow Stamp Images and Signatures
- Allow signers to print, place written signatures and upload the agreem
- Set up Mandatory Mobile Signature Capture
- Request IP address from recipients for the audit report
- Enable drawn signature scaling
-
Digital Signatures
- Overview of Digital Signatures in Adobe Acrobat Sign
- Download and sign with an Acrobat certificate
- Enable cloud-based digital signatures
- Configure bulk digital signatures from Manage in Acrobat Sign
- Require digital signatures for specific recipients
- Send metadata to the cloud signature provider
- Configure a restricted Identity Provider
- Configure auto-provisioning for partner applications
- Create electronic seals in Adobe Acrobat Sign
- Digital Identity
- Report Settings
-
Security Settings
- Restrict user access to Acrobat Sign using allowed IP address ranges
- Administrator managed sharing
- Configure Account Sharing Permissions
- Agreement sharing controls
- Signer Identity Verification
- Define the complexity of user-applied passwords
- Block signers within a specific geography
- Allow page extraction from agreement PDFs
- Document link expiration
- Stand-alone timestamp certificates for electronic signatures
- Block iframe embedding in Acrobat Sign
-
Send Settings
- Configure document editing during authoring
- Agreement creation experiences
- Require recipient name when configuring an agreement or web form
- Lock Name values for known users when authenticating
- Allow various recipient roles
- Configure the e-Witness role for recipients
- Configure in-person signing in Acrobat Sign
- Enable recipient groups
- Configure CC notifications as part of a recipient record
- Configure OneDrive file upload
- Automatically "flatten" PDF documents when uploaded
- Allow User to Modify Agreements
- Remove recipients from in-flight agreements
- Enable private messages to recipients
- Allowed signature types
- Set reminders for the agreement recipients
- Allow senders to add passwords to protect viewing the agreement PDF
- Send notifications through SMS or WhatsApp in Adobe Acrobat Sign
- Adobe Acrobat Sign Identity Authentication Methods
- Signing Password
- Knowledge-based authentication
- Configure phone authentication
- WhatsApp authentication
- Configure one-time password via email authentication
- Acrobat Sign Authentication
- Cloud-based digital signatures
- Digital Identity Provider authentication
- Government ID authentication
- Signer Identity Report
- Configure Content Protection
- Configure Automatic Document Expiration (Completion deadline)
- Signature order options
- Configure hybrid recipient routing
- Configure internal recipient restrictions in Acrobat Sign
- Configure the Download agreement link
- Form Field Borders
- Liquid Mode for Mobile Web Signing Experience
- Enable Template-Defined Signature Placement in Custom Workflows
- Enable Acrobat Sign to tag uploaded PDFs for accessibility
- Restricted access to agreements
- Message Templates
- Bio-Pharma Settings
- Notarize integration with Acrobat Sign
- Set up online payments
- SAML Settings
- Data Governance
- Set up an archive for your agreements
-
Email Settings
- Email header and footer images
- Enable and configure the user's personal email footer
- Adobe Acrobat Sign - Suppress email addresses in agreement notifications
- Adobe Acrobat Sign - Suppress email addresses in To and CC fields of the email header
- Enable linkless notifications
- Use customized email templates
- Understand the Acrobat Sign tracking pixel
- Migrating from echosign.com to adobesign.com
- Customize the Options for Recipients on the e-sign page
-
Guidance for regulatory demands
- Accessibility
- HIPAA configurations in Adobe Acrobat Sign Solutions
- GDPR
- 21 CFR part 11 and EudraLex Annex 11
- EU/UK considerations
- Comply with IVES
- Report Abuse links
-
Integrations
- Adobe Acrobat Sign Integrations
- Product versions and lifecycle
- Integration keys
-
Acrobat Sign for Salesforce
- Acrobat Sign for Salesforce: Install the package (v24)
- Acrobat Sign for Salesforce: Configure the package
- Adobe Acrobat Sign for Salesforce: Upgrade Guide
- Adobe Acrobat Sign for Salesforce: Release notes
- Adobe Acrobat Sign for Salesforce (Lightning profile): User Guide
- Acrobat Sign for Salesforce Mobile
- Enable authentication with digital identity providers
- Adobe Acrobat Sign for Salesforce: Mappings and Templates Guide
- Using Acrobat Sign Document Builder for Salesforce
- Configure Large Documents and Push Agreements Service
- Adobe Acrobat Sign for Salesforce: Customization Guide
- Adobe Acrobat Sign for Salesforce: Developer Guide
- Acrobat Sign for Salesforce: Other Guides
- Adobe Acrobat Sign for Salesforce: FAQs
- Acrobat Sign for Salesforce: Troubleshooting Guide
- Microsoft: Office
- Microsoft: Teams
-
Microsoft: Dynamics
- Acrobat Sign for Microsoft Dynamics
- Adobe Acrobat Sign for Microsoft Dynamics 365 Online: Installation Guide
- Adobe Acrobat Sign for Microsoft Dynamics Online: User Guide
- Adobe Acrobat Sign for Microsoft Dynamics 365 On-Premises: Installation Guide
- Adobe Sign for Microsoft Dynamics On-Premises: User Guide
- Adobe Acrobat Sign for Microsoft Dynamics Workflows: User Guide
- Adobe Acrobat Sign for Microsoft Dynamics 365 Talent
- Adobe Sign for Microsoft Dynamics: Upgrade Guide
- Adobe Acrobat Sign for Microsoft Dynamics 365: Release Notes
- Microsoft: Power Automate
- Microsoft: Search connector
- ServiceNow
- SAP SuccessFactors
- Workday
- NetSuite
- Adobe Acrobat Sign for SugarCRM
- VeevaVault
- Adobe Acrobat Sign for Coupa BSM Suite: Installation Guide
- Zapier
-
Developers
- REST APIs
- Webhooks
- Sandbox
- System-level resources
- Support
Customer-managed encryption considerations and limitations
This article contains prerelease information. Release dates, features, and other information are subject to change without notice.
Review the requirements, operational impacts, and current limitations of customer-managed encryption before enabling it for your Adobe Acrobat Sign account.
Customer-managed encryption gives your organization control of the AWS KMS key used to protect supported Acrobat Sign content at rest. That control also makes your organization responsible for keeping the key and its access credentials available.
Review these considerations before enabling customer-managed encryption or changing the key configuration.
Plan for continuous access to your encryption key
Acrobat Sign must be able to access your configured AWS KMS key to encrypt and decrypt protected content.
Content protected with your customer-managed key can become unavailable if:
- The AWS KMS key is disabled or deleted.
- The AWS credentials configured in Acrobat Sign are disabled or revoked.
- IAM permissions no longer allow Acrobat Sign to use the key.
Acrobat Sign can continue using cached key-encryption information until the configured key cache TTL expires. The TTL can be set from 5 to 60 minutes.
Keep the key and required credentials available for as long as Acrobat Sign content remains protected by that key.
Do not delete a customer-managed key while Acrobat Sign content is still protected by it. Deleting the key can make that content unrecoverable.
Understand what is protected
Customer-managed encryption applies to supported Acrobat Sign content stored at rest.
| Content | Customer-managed encryption |
|---|---|
| Agreement PDFs | Supported |
| Templates | Supported |
| Thumbnails | Supported |
| Temporary files managed by the supported file service | Supported |
| Active signature images | Supported |
| Electronic seal logos | Supported |
| Form field data | Not supported |
| Government ID verification images | Not supported |
| Sensitive account settings, including customer mTLS certificates | Not supported |
Customer-managed encryption does not change how Acrobat Sign protects data in transit. Existing transport encryption continues to apply.
AWS KMS is the supported key provider
The current implementation supports customer-managed keys in AWS Key Management Service (KMS).
The configured key must meet the requirements described in Configure Customer Managed Encryption, including use of a supported symmetric AWS KMS key and the required IAM permissions.
The following are not currently supported:
- Azure Key Vault
- Azure Government
- Acrobat Sign for Government
Support for other key-management environments is outside the current release.
Customer-managed encryption is account-level
Customer-managed encryption applies at the Acrobat Sign account level.
It cannot be configured independently for individual groups. Once enabled, supported content created for the account uses the configured customer-managed encryption configuration.
This makes key availability and key-management practices an account-wide operational dependency.
Existing content requires background processing
Enabling customer-managed encryption does not immediately re-encrypt the account's entire history.
Existing eligible content is migrated through a background re-encryption process. Bulk encryption and decryption jobs run during the account's off-peak processing window, from 7:00 PM to 7:00 AM local time.
For accounts with large amounts of content, processing can span multiple windows and may take days or weeks.
Agreements remain accessible while processing is underway. During a migration, an account can temporarily contain both:
- content protected with the customer-managed key; and
- content that is still protected with Adobe-managed encryption.
For instructions on starting and monitoring these operations, see Manage customer keys.
Disabling customer-managed encryption takes time
Disabling customer-managed encryption does not immediately remove the dependency on the customer-managed key.
Acrobat Sign must first process content that is currently protected by the customer-managed key and return it to Adobe-managed encryption. The AWS KMS key and credentials must remain available throughout this process.
Do not disable or delete the AWS KMS key, revoke its credentials, or remove required permissions until the migration back to Adobe-managed encryption is complete.
Large migrations are asynchronous
Bulk encryption and decryption are background operations designed to avoid interrupting normal agreement activity.
Keep these behaviors in mind:
- Processing occurs only during the off-peak processing window.
- Large accounts can require multiple processing windows.
- Individual items can fail even when the overall job completes.
- Failed items can be retried without repeating successfully processed items.
- A running migration can be stopped and resumed.
- The status page does not refresh automatically; refresh it to see the latest processing state.
Detailed job management belongs to Manage customer keys.
Review automatically protected content
Automatically applying customer-managed encryption does not eliminate the need to understand which content types are within the supported encryption scope.
In particular, do not assume that enabling customer-managed encryption means every type of account data is protected by your AWS KMS key. Content listed as unsupported continues to use its existing Acrobat Sign protection model.
For a detailed explanation of the encryption model, see Understand customer-managed encryption in Acrobat Sign.
Plan AWS key maintenance carefully
AWS can rotate the underlying key material for a customer-managed KMS key without changing its key ARN.
Acrobat Sign does not provide a separate customer-key migration workflow for moving already protected content from the configured AWS KMS key to a different customer-managed key in the current implementation.
Plan changes to the configured key and its credentials carefully, and validate new access before removing access that Acrobat Sign currently depends on.
Consider compliance and operational ownership
Customer-managed encryption changes who controls a critical dependency for access to protected Acrobat Sign content.
Before enabling it, establish ownership for:
- AWS KMS key administration.
- IAM credential management.
- Key-access monitoring.
- Credential rotation.
- Responding to key-access failures.
- Keeping the key available during encryption and decryption migrations.
Acrobat Sign administrator notifications can alert active account administrators to key-access failures, but your organization remains responsible for restoring access to its AWS resources.