WiseStamp for IT › Exchange › Step 2 of 12 — Prerequisites Checklist
Audience: IT manager / system administrator. Complete this before Identity & Employee Sync.
1. Administrative access
Requirement | Applies to | Notes |
Microsoft 365 Global Administrator | Off-prem / hybrid (EXO) | Required for Entra ID integration, Add-In central deployment, and server-side connector authorization. Sign into Microsoft in a separate tab before starting. |
Exchange admin access to Mail flow > Connectors and Rules | Server-side (off-prem/hybrid) | Required to create/verify connectors and transport rules in the Exchange admin center. |
WiseStamp Owner or Admin role | All | Access the Integrations page. See Permissions Reference. |
On-prem Exchange admin (Organization Management) + Exchange Management Shell | Pure on-prem | Not applicable — pure on-prem is not supported. Employee sync is not supported for on-prem; no plan supports it. |
2. WiseStamp plan
Method | Minimum plan |
Outlook Add-In + Entra ID employee sync | Basic |
Server-side routing + signature rules | Platform |
SSO (SAML) | Platform |
Security Group sync | Enterprise (or trial) |
3. Topology & mailbox requirements
Requirement | Applies to | Notes |
Exchange Online with active mailboxes | Add-In | The Add-In requires Exchange Online mailboxes. |
Directory in or federated to Entra ID | Off-prem / hybrid | Required for directory sync and Add-In identity. |
Outbound mail egress via Exchange Online | Hybrid | Server-side routing is documented at the EXO egress point. |
On-prem mail flow control (Send/Receive connectors, transport) | Pure on-prem | Not supported. Employee sync is not supported for on-prem; no plan supports it. |
Supported Outlook clients (Add-In)
Microsoft 365 Business (Standard/Premium) v1701+
Office 365 Enterprise (E1/E3/E5/F3) v1701+
Microsoft 365 Enterprise (E3/E5/F3) v1701+
Office for Mac 16.0.9318.1000+
Outlook mobile iOS 2.75.0+ / Android 2.2.145+
Outlook on the web
Note: build minimums are from the help center and undated. WiseStamp could not confirm a specific verification date but believes these floors are still correct.
4. Email authentication (DNS) — server-side
Requirement | Notes |
SPF | Add include:outbound.smtp.wisestamp.net to your sending domains' SPF before routing through WiseStamp. |
DKIM | Routing through WiseStamp can break existing DKIM. WiseStamp issues a unique DKIM record per account — request it from support, add as TXT, then have support enable signing. Verify dkim=pass. |
5. Network / firewall allowlist — server-side
Server-side routing references these WiseStamp hostnames:
Outbound target: ms.smtp.wisestamp.net (prefixed with your tenant routing code, e.g. <routing-code>.ms.smtp.wisestamp.net)
Inbound authenticating domain: outbound.smtp.wisestamp.net
IP ranges (Exchange Online and hybrid):
104.198.34.229
34.133.172.126
35.224.156.40
34.173.9.51
35.225.126.165
34.173.64.165
Normally clients don’t need to add these IPs anywhere — hostname-based connectors/rules are sufficient — unless you run a spam-filtering service (e.g., Barracuda) in front of Exchange, in which case allowlist your domain or these IPs on that service. Pure on-prem is not supported, so this list does not apply.
6. Pre-flight checklist
☐ Topology identified (off-prem / hybrid / on-prem).
☐ WiseStamp plan supports the intended method.
☐ Microsoft 365 Global Admin confirmed (off-prem/hybrid).
☐ Exchange admin access to Mail flow (server-side).
☐ WiseStamp Owner/Admin access confirmed.
☐ (Add-In) EXO mailboxes; Outlook builds meet minimums.
☐ (Server-side) SPF updated; DKIM record requested/added; signing enabled.
☐ (Server-side) Allowlist hostnames in place; IP list added if required (see IP ranges above).
☐ (Pure on-prem) Confirmed not supported — employee sync is not supported for on-prem and no plan supports it; migrate identity to Entra ID (hybrid, at minimum) before proceeding.