Skip to main content

Office 365 Email Signature Deployment: Prerequisites Checklist

Everything that must be true before you connect WiseStamp to Office 365: Global Admin rights, plan tier, Exchange Online, DNS and firewall allowlisting.

WiseStamp for IT › Microsoft 365 › Step 2 of 12 — Prerequisites Checklist


Audience: IT manager / system administrator. Complete this before starting Connect Microsoft Entra ID.


1. Administrative access

Requirement

Applies to

Notes

Microsoft 365 Global Administrator account

All setups

Required to integrate the Entra ID directory, deploy the Outlook Add-In centrally, and authorize server-side connectors. The Global Admin must be signed into Microsoft in a separate browser tab before starting.

WiseStamp account with Owner or Admin role

All setups

Needed to access the Integrations page and complete connections. See Permissions Reference.


2. WiseStamp plan

Confirm your plan supports the method you intend to deploy.

Method

Minimum plan

Outlook Add-In (client-side) + Entra ID employee sync

Basic

Server-side deployment + server-side signature rules

Platform

SSO (SAML) for admin sign-in

Platform

Security Group synchronization

Enterprise (or trial, by request)

A 14-day free trial is available and can have Security Group sync enabled on request.


3. Microsoft 365 / Exchange Online requirements

Requirement

Applies to

Notes

Exchange Online with active Exchange Online mailboxes

All setups

The Add-In requires users to have Exchange Online mailboxes.

Directory in or federated to Microsoft Entra ID

All setups

Your subscription directory must be in or federated to Entra ID.

Exchange admin access to Mail flow > Connectors and Rules

Server-side only

Required to create the outbound/inbound connectors and transport rules (automated or manual).

Supported Outlook clients (Outlook Add-In)

The Add-In requires these minimum clients/builds:

  • Microsoft 365 Business (Business Standard, Business Premium) version 1701 or later

  • Office 365 Enterprise (E1 / E3 / E5 / F3) version 1701 or later

  • Microsoft 365 Enterprise (E3 / E5 / F3) version 1701 or later

  • Office for Mac version 16.0.9318.1000 or later

  • Outlook mobile for iOS version 2.75.0 or later

  • Outlook mobile for Android version 2.2.145 or later

  • Outlook on the web

Note: The minimum build numbers above are taken from the help center and are undated. WiseStamp could not confirm a specific verification date but believes these floors are still correct.


4. Email authentication (DNS)

Requirement

Applies to

Notes

SPF record updated for WiseStamp

Server-side

During server-side setup you will be prompted to add SPF records to any domains missing them, then verify. Have DNS edit access ready.

DKIM alignment

Server-side (recommended)

The KB provides a separate DKIM setup article. Align DKIM to avoid deliverability/spam issues once mail routes through WiseStamp.

Have access to your public DNS zone editor before starting server-side setup.


5. Network / firewall allowlist

Microsoft 365 server-side routing

Server-side routing for Exchange Online uses these WiseStamp hostnames in the connectors and rules:

  • Outbound target: ms.smtp.wisestamp.net (with your tenant routing code as a prefix, e.g. <routing-code>.ms.smtp.wisestamp.net)

  • Inbound authenticating domain: outbound.smtp.wisestamp.net

IP ranges: the Microsoft IPs behind these hostnames are:

104.198.34.229
34.133.172.126
35.224.156.40
34.173.9.51
35.225.126.165
34.173.64.165

Normally clients don’t need to add these IPs anywhere — hostname-based connectors/rules are sufficient. The exception is if you run a spam-filtering service in front of Exchange (e.g., Barracuda); those services may need your domain or these IPs allowlisted explicitly.


6. Pre-flight checklist

Tick all before proceeding:

  • ☐ Microsoft 365 Global Admin account confirmed and signed in.

  • ☐ WiseStamp plan supports the intended deployment method.

  • ☐ WiseStamp Owner/Admin access confirmed.

  • ☐ Exchange Online mailboxes active for in-scope users.

  • ☐ Directory is in or federated to Entra ID.

  • ☐ (Add-In) Outlook client builds meet the minimums above.

  • ☐ (Server-side) Exchange Mail flow admin access confirmed.

  • ☐ (Server-side) DNS edit access available for SPF/DKIM.

  • ☐ (Server-side) Network team briefed on routing hostnames; IP allowlist added if required (see IP ranges above).

  • ☐ Decision made: client-side, server-side, or hybrid (see Setup Overview).

Related articles


Did this answer your question?