Skip to main content

Office 365 Email Signatures: Sync Microsoft Security Groups

Drive your managed employee list from a Microsoft Security Group. Grant GroupMember.Read.All, supply the group ID, and validate membership. Enterprise plan.

WiseStamp for IT › Microsoft 365 › Step 7 of 12 — Sync Microsoft Security Groups


Plan requirement: Enterprise only (can be enabled during a trial by contacting WiseStamp). Microsoft domains only.


Requirements and constraints

  • Available exclusively on Enterprise plans (or trial, by request).

  • Microsoft domains only.

  • Create one Security Group containing all employees who should receive WiseStamp signatures.

  • No nested groups. Every employee must be an explicit, direct member of the group.


How setup works (overview)

This is an assisted process, not fully self-serve:

  1. You grant WiseStamp the GroupMember.Read.All permission via Microsoft Graph.

  2. You send WiseStamp the Security Group ID (the group’s Object ID).

  3. WiseStamp enables the Security Group feature and enters the Group ID on their side.

there is no self-serve UI for this today. Steps 1–2 above (granting the Graph permission and sending the Security Group ID) are completed by the customer; step 3 (enabling the feature and entering the ID) is completed by WiseStamp.


Prerequisites

  • Microsoft Entra ID directory connected (Connect Microsoft Entra ID).

  • Access to the Microsoft Entra admin center and Microsoft Graph Explorer.

  • Rights to grant application role assignments via Graph.


Procedure — grant GroupMember.Read.All via Microsoft Graph

You need three values for the final POST: PrincipalId, ServicePrincipalObjectId, and AppRoleId.

Retrieve the Principal ID

  1. Sign in to the Microsoft Entra admin center.

  2. Go to Identity > Applications > Enterprise applications > All applications.

  3. Open the WiseStamp for Outlook 365 application.

  4. In Properties, copy the Object ID — this is your PrincipalId.

Retrieve the Service Principal Object ID

  1. Sign in to Microsoft Graph Explorer.

  2. Run a GET request to: https://graph.microsoft.com/v1.0/servicePrincipals?$filter=appId eq '00000003-0000-0000-c000-000000000000'

  3. In the response, the id at the top is the ServicePrincipalObjectId.

Retrieve the Application Role ID

  1. In the same response, search for GroupMember.Read.All.

  2. Find the entry with "origin": "Application" and "value": "GroupMember.Read.All".

  3. Its id is the AppRoleId.

Grant the permission

  1. Request body:

    {
    "principalId": "<PrincipalId>",
    "resourceId": "<ServicePrincipalObjectId>",
    "appRoleId": "<AppRoleId>"
    }

  2. Run the query. A successful response returns 201 Created.


Procedure — provide the Security Group ID

  1. Sign in to the Microsoft Entra admin center.

  2. Go to Identity > Groups > All groups.

  3. Open the Security Group you want to sync.

  4. Copy its Object ID — this is the Security Group ID.

  5. Send the Security Group ID to WiseStamp.

WiseStamp then enables the feature and enters the ID. Once active, you can manage sync from the Security Group via Settings > Sync & Automations (Manage Sync from Security Group option, Enterprise only).


Validation

  • After WiseStamp enables the feature, confirm the Employees list reflects the group’s membership.

  • Add a test member to the Security Group and confirm they appear in WiseStamp after the next sync.

  • Remove a test member and confirm they are removed on the next sync.

Sync timing: directory sync runs daily when enabled. Allow for sync latency between a membership change in Entra ID and the change appearing in WiseStamp. See Ongoing Admin Guide.

Related articles


Did this answer your question?