Preview build — Pull Request #115

Using Signature 365 in a hybrid configuration with on-premises Exchange mailboxes

Use the Signature 365 Classic Agent for on-premises Exchange mailboxes in hybrid environments, with Autodiscover access for authentication.
Note
Use the Outlook (Classic) agent if you need signatures inserted while composing email from an on-premises Exchange mailbox. The Outlook add-in can still be used for preview mode or together with How Microsoft 365 server-side signatures work where appropriate.
Warning
Attempting to use the add-in to insert signatures on compose with on-premises Exchange will result in errors because of API compatibility limitations.

If you are using Signature 365 with Microsoft 365 mailboxes and then try to use the add-in with an on-premises mailbox, you may receive an error similar to the following:

Checking the add-in logs on your device, you may see the following error:

[Log] [S365] [messageCompose] https://id.signature365.com/connect/token failed

Signature 365 must confirm the authenticity of the user contacting the service. For on-premises mailboxes, this can only be done by contacting your on-premises Exchange server.

The Signature 365 identity servers do this by contacting the Autodiscover URL of your on-premises Exchange server to authorise the user.

If your firewall blocks access to this endpoint, Signature 365 can receive either a 401 unauthorised response or a timeout. That causes the errors listed above.

You must allow access to your on-premises Exchange Autodiscover URL through any external firewalls so Signature 365 can authorise your on-premises users.

The Signature 365 identity servers are a global resource and use the region closest to the connected user. If your users are geographically closer to another region, that region's identity server may be used.

The external IP addresses are listed in Signature 365 SMTP host list and IP whitelist. Allow those IP addresses to access your on-premises Exchange server so authentication can complete successfully.

Next steps

  1. Deploy the Outlook (Classic) agent for users who need on-compose signatures with on-premises mailboxes.
  2. Allow the IP addresses in Signature 365 SMTP host list and IP whitelist.
  3. If you also use Microsoft 365 mailboxes, review How to install the Outlook add-in and How Microsoft 365 server-side signatures work for those scenarios.