WiseStamp for IT › Microsoft 365 › Step 1 of 12 — Setup Overview
Audience: IT manager / system administrator running the deployment. You will need Microsoft 365 Global Administrator rights for most setup steps.
The two deployment methods
WiseStamp applies signatures in one of two ways. You can also combine them (hybrid).
Client-side (Outlook Add-In) | Server-side (Exchange Online routing) | |
When the signature is applied | While the user composes the email (pre-send) | After the email is sent, in transit through WiseStamp’s cloud (post-send) |
User sees signature before sending | Yes | No |
Coverage | Outlook clients where the add-in runs (web, desktop, mobile) | All devices and clients, including mobile and CRM — nothing installed on the client |
What you install | WiseStamp Outlook Add-In (centrally deployed) | Mail flow connectors + transport rules in Exchange Online |
Plan requirement | Basic and above | Platform or Enterprise |
Best for | Teams that want a visible signature in Outlook and a fast, app-based rollout | Organizations needing universal coverage across every device and client, including non-Outlook senders |
Hybrid mode
Hybrid runs both methods together. The client-side add-in applies the signature first; the server-side service only adds a signature if it does not already detect a WiseStamp signature on the message. This gives you preview-in-Outlook plus full cross-device coverage without duplicate signatures. Hybrid requires a plan with server-side (Platform or Enterprise).
Which method should I choose?
Use this decision logic:
Do you need signatures on every device and client (mobile mail apps, CRMs, scan-to-email, non-Outlook senders), with nothing installed on endpoints? → Server-side. Requires Platform or Enterprise.
Is your fleet effectively all-Outlook (web/desktop/mobile) and you want users to see the signature before sending? → Client-side (Outlook Add-In). Available from Basic.
Do you need both visible-in-Outlook preview and guaranteed coverage on every other device? → Hybrid. Requires Platform or Enterprise.
Are you on Basic or Grow (no server-side)? → Client-side is your only option until you upgrade to Platform/Enterprise.
Trade-off to weigh: server-side guarantees coverage and removes endpoint dependencies, but routes outbound mail through WiseStamp’s service and requires Exchange Online mail flow changes. The Add-In avoids touching mail flow but only covers Outlook clients where it is installed and signed in.
Plan requirements at a glance
Capability | Minimum plan |
Microsoft 365 integration + Outlook Add-In | Basic |
Auto-sync employee details from Entra ID | Basic |
Server-side deployment + signature rules | Platform |
Single Sign-On (SAML) | Platform |
Roles & permissions | Platform |
Security Group synchronization | Enterprise (or trial, by request) |
See Office 365 IT Admin Guide for the full tier matrix.
Order of operations
Do these in sequence. Skipping ahead (for example, installing the Add-In before connecting the directory) is the most common cause of "signatures not appearing."
Confirm prerequisites — supported Microsoft 365 / Exchange Online setup, plan tier, admin rights, and any network allowlisting. → Prerequisites Checklist
Connect your Microsoft Entra ID directory — establishes identity and lets WiseStamp import and sync employees. Required for both deployment methods. → Connect Microsoft Entra ID
Deploy signatures using your chosen method:
Outlook Add-In (client-side) → Deploy the Outlook Add-In
Server-side via Exchange Online → Server-Side Deployment
(Optional, Platform/Enterprise) Configure SSO for admin sign-in. → SSO with Entra ID (SAML)
(Optional, Enterprise) Sync employee groups via Microsoft Security Groups. → Sync Microsoft Security Groups
Activate employees and validate with the go-live checklist. → Go-Live Checklist
Hand off to employees and move into ongoing operations. → Employee Rollout Handoff, Ongoing Admin Guide
Key dependency: connecting the Entra ID directory does not by itself put signatures on email. You must also deploy via the Add-In and/or server-side. Integrating the directory only handles identity and employee sync.
What WiseStamp accesses on your tenant
Setup grants specific, scoped Microsoft permissions:
Outlook Add-In: ReadWriteItem — to insert the signature into the message being composed. WiseStamp states it does not read or store email content.
Entra ID directory: User.Read.All — to import users and sync employee fields (name, title, department, etc.).
Security Group sync (Enterprise): GroupMember.Read.All — to read membership of the designated group.
Full details and the rationale for each permission are in Permissions Reference.