WiseStamp for IT › Microsoft 365 › Step 2 of 12 — Prerequisites Checklist
Audience: IT manager / system administrator. Complete this before starting Connect Microsoft Entra ID.
1. Administrative access
Requirement | Applies to | Notes |
Microsoft 365 Global Administrator account | All setups | Required to integrate the Entra ID directory, deploy the Outlook Add-In centrally, and authorize server-side connectors. The Global Admin must be signed into Microsoft in a separate browser tab before starting. |
WiseStamp account with Owner or Admin role | All setups | Needed to access the Integrations page and complete connections. See Permissions Reference. |
2. WiseStamp plan
Confirm your plan supports the method you intend to deploy.
Method | Minimum plan |
Outlook Add-In (client-side) + Entra ID employee sync | Basic |
Server-side deployment + server-side signature rules | Platform |
SSO (SAML) for admin sign-in | Platform |
Security Group synchronization | Enterprise (or trial, by request) |
A 14-day free trial is available and can have Security Group sync enabled on request.
3. Microsoft 365 / Exchange Online requirements
Requirement | Applies to | Notes |
Exchange Online with active Exchange Online mailboxes | All setups | The Add-In requires users to have Exchange Online mailboxes. |
Directory in or federated to Microsoft Entra ID | All setups | Your subscription directory must be in or federated to Entra ID. |
Exchange admin access to Mail flow > Connectors and Rules | Server-side only | Required to create the outbound/inbound connectors and transport rules (automated or manual). |
Supported Outlook clients (Outlook Add-In)
The Add-In requires these minimum clients/builds:
Microsoft 365 Business (Business Standard, Business Premium) version 1701 or later
Office 365 Enterprise (E1 / E3 / E5 / F3) version 1701 or later
Microsoft 365 Enterprise (E3 / E5 / F3) version 1701 or later
Office for Mac version 16.0.9318.1000 or later
Outlook mobile for iOS version 2.75.0 or later
Outlook mobile for Android version 2.2.145 or later
Outlook on the web
Note: The minimum build numbers above are taken from the help center and are undated. WiseStamp could not confirm a specific verification date but believes these floors are still correct.
4. Email authentication (DNS)
Requirement | Applies to | Notes |
SPF record updated for WiseStamp | Server-side | During server-side setup you will be prompted to add SPF records to any domains missing them, then verify. Have DNS edit access ready. |
DKIM alignment | Server-side (recommended) | The KB provides a separate DKIM setup article. Align DKIM to avoid deliverability/spam issues once mail routes through WiseStamp. |
Have access to your public DNS zone editor before starting server-side setup.
5. Network / firewall allowlist
Microsoft 365 server-side routing
Server-side routing for Exchange Online uses these WiseStamp hostnames in the connectors and rules:
Outbound target: ms.smtp.wisestamp.net (with your tenant routing code as a prefix, e.g. <routing-code>.ms.smtp.wisestamp.net)
Inbound authenticating domain: outbound.smtp.wisestamp.net
IP ranges: the Microsoft IPs behind these hostnames are:
104.198.34.229
34.133.172.126
35.224.156.40
34.173.9.51
35.225.126.165
34.173.64.165
Normally clients don’t need to add these IPs anywhere — hostname-based connectors/rules are sufficient. The exception is if you run a spam-filtering service in front of Exchange (e.g., Barracuda); those services may need your domain or these IPs allowlisted explicitly.
6. Pre-flight checklist
Tick all before proceeding:
☐ Microsoft 365 Global Admin account confirmed and signed in.
☐ WiseStamp plan supports the intended deployment method.
☐ WiseStamp Owner/Admin access confirmed.
☐ Exchange Online mailboxes active for in-scope users.
☐ Directory is in or federated to Entra ID.
☐ (Add-In) Outlook client builds meet the minimums above.
☐ (Server-side) Exchange Mail flow admin access confirmed.
☐ (Server-side) DNS edit access available for SPF/DKIM.
☐ (Server-side) Network team briefed on routing hostnames; IP allowlist added if required (see IP ranges above).
☐ Decision made: client-side, server-side, or hybrid (see Setup Overview).