Friday, June 15, 2018

Restored AD account is not showing in Global Address List (GAL)

Environment:
Local AD syncing with Office 365 via Azure Sync.
Situation:
User has been moved to a non syncing OU.
Cloud account was disabled, then restored as InCloud and converted to shared mailbox so it could be viewed by management.
User returns to work.
AD account moved to synching OU, reattached to Cloud account and converted back from shared to a user mailbox.

Attributes in local AD have not changed.
"Show in Global Address List" is set to No.
Edit throws an error that the account is synching and any changes have to be made locally.
Specifically:
The action 'Set-Mailbox', 'HiddenFromAddressListsEnabled', can't be performed on the object because the object is being synchronized from your on-premises organization.

Hop on over to the DC, this attribute doesn't exist. We were previously an in house Exchange Server environment.

The attribute in my case is msExchHideFromAddressLists
This attribute was already set to FALSE, but because the account was disabled and re-enabled, the attribute wasn't changing the view status in the GAL.
I changed it to <not set>, waited for sync and it updated.

This attribute was also preventing user display in distribution lists. This was driving me crazy because I could see they were part of the DL groups, but weren't showing up when I expanded the list in Outlook. Once they were showing in the GAL, they showed in the DL groups.

No comments:

Post a Comment

Samsung refrigerator not making ice

How I got my stupid fridge to work again. Normally, I press/hold the blue button till it chimes. Well that didn’t work this time. Darn. I re...