Exchange Hybrid - GAL

%3CLINGO-SUB%20id%3D%22lingo-sub-185260%22%20slang%3D%22en-US%22%3EExchange%20Hybrid%20-%20GAL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-185260%22%20slang%3D%22en-US%22%3E%3CP%3ESo%20we%20have%20a%20hybrid%20environment%20with%20on-premises%20AD%20users%20that%20are%20synced%20to%20Office%20365.%20Users'mailboxes%20are%20on%20Exchange%20Online.%20Azure%20AD%20OU%20filtering%20is%20not%20used%20yet%20so%20we%20sync%20all%20accounts%20(even%20disabled%20ones)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20Skype%20for%20Business%20Online%20when%20you%20search%20for%20a%20contact%2C%20it%20will%20also%20show%20the%20disabled%20accounts%20whereas%20the%20Exchange%20Address%20book%20won't%20show%20the%20disabled%20accounts%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20that%20normal%2C%20Skype%20doesn't%20use%20the%20same%20address%20book%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20coming%20from%20an%20Exchange%20on-premises%20setup%20but%20we%20have%20almost%20migrated%20all%20mailboxes%20online%2C%20how%20does%20the%20GAL%20is%20maintained%20now%20Can%20I%20delete%20my%20on-premises%20Address%20lists%3F%20How%20can%20I%20create%20Address%20lists%20in%20Office%20365%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-185260%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-202396%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20-%20GAL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-202396%22%20slang%3D%22en-US%22%3E%3CP%3EOne%20quick%20thought%20from%20reading%20about%26nbsp%3Bthis%20issue%20is%20that%20when%20Skype%20desktop%20client%20downloads%20it's%20address%20book%2C%20it%20then%20saves%20the%20address%20book%20in%20the%20users%20Skype%20profile.%20If%20you%20sign%20on%20to%20a%20PC%20or%20laptop%2C%20Try%20deleting%20the%20Skype%20profile%26gt%3B%20exit%20out%20of%20the%20skype%20client%20by%20right%20clicking%20the%20skype%20icon%20in%20systray%20and%20clicking%20exit.%20Restart%20Skype.%20This%20will%20force%20a%20new%20download%20of%20the%20address%20book.%20If%20the%20deleted%20account%20still%20appears%20in%20searches%2C%20then%20you%20will%20need%20to%20alter%20the%20Skype%20online%20address%20book.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20simplest%20solution%20to%20alter%20the%20skype%20online%20address%20book%20would%20involve%20moving%20deleted%20users%20or%20users%20that%20should%20be%20hidden%20to%20an%20OU%20and%20configure%20AAD%20to%20filter%20that%20OU%20from%20AAD%20replication.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-186285%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20-%20GAL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-186285%22%20slang%3D%22en-US%22%3E%3CP%3EOne%20more%20thing%20the%20disabled%20accounts%20will%20only%20show%20when%20you%20use%20the%20SfB%20client%20from%20a%20laptop%20or%20PC.%3C%2FP%3E%3CP%3EIf%20we%20use%20the%20mobile%20client%20on%20Android%20or%20iPhone%20they%20don't%26nbsp%3Bshow%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-186284%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20-%20GAL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-186284%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20do%20that%2C%20you%20might%20loose%20any%20data%20stored%20in%20her%20ODFB%2C%20so%20make%20sure%20you%20back%20that%20up%20if%20needed.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-186271%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20-%20GAL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-186271%22%20slang%3D%22en-US%22%3E%3CP%3EI%20still%20don't%26nbsp%3Bknow%20what%20I%20should%20do...As%20an%20example%2C%20I%20have%20a%20user%20who%20left%20the%20company%2C%20her%20account%20is%20disabled%20in%20AD%2C%20the%20Exchange%20properties%20have%20been%20removed%2C%20her%20mailbox%20deleted%2C%20she%20is%20not%20licensed%20for%20anything%20in%20Office%20365%2C%20she%20is%20an%20OU%20that%20gets%20synced%20by%20Azure%20AD%20connect%2C%20she%20shows%20p%20in%20SfB%20but%20not%20Exchange.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20the%20only%20way%20for%20her%20to%20not%20show%20in%26nbsp%3BSfB%20is%20to%20remove%20the%20sync%20on%20the%20OU%20she%20is%20in%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-186255%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20-%20GAL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-186255%22%20slang%3D%22en-US%22%3E%3CP%3EIt's%20not%20about%20contacts%20per%20se%2C%20it's%20about%20the%20recipient%20type%20for%20the%20corresponding%20object.%20Here's%20an%20example%20to%20try%20in%20your%20tenant%3A%20create%20a%20user%20directly%20in%20the%20O365%2C%20do%20not%20license%20it%20for%20Exchange%2C%20but%20give%20it%20a%20SfB%20license.%20Such%20user%20will%20be%20visible%20in%20SfB%2C%20but%20NOT%20visible%20in%20Exchange%2C%20as%20it%20is%20not%20recognized%20as%20any%20valid%20Exchange%20recipient.%20The%20same%20applies%20when%20you%20sync%20objects%20from%20on-premises%20-%20only%20the%20objects%20that%20are%20recognized%20as%20valid%20Exchange%20recipients%20will%20show%20up%20in%20the%20GAL.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-186242%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20-%20GAL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-186242%22%20slang%3D%22en-US%22%3E%3CP%3EWould%20you%20know%20how%20to%20explain%20the%20difference%20between%20the%20Skype%26nbsp%3Band%20Exchange%20Online%20contacts%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20trying%20to%20understand%26nbsp%3Bhow%20I%20could%20make%20that%20disabled%20accounts%20don't%20show%20up%20on%20Skype.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-185735%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20-%20GAL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-185735%22%20slang%3D%22en-US%22%3E%3CP%3EAh%2C%20I%20see.%20That%20explains%20it%20actually%2C%20Exchange%20address%20lists%20(including%20the%20GAL)%20only%20include%20valid%20Exchange%20recipient%20types%2C%20if%20the%20user%20doesn't%20have%20a%20mailbox%20(and%20is%20not%20represented%20by%20a%20mail-user%20object%20on-premises)%2C%20Exchange%20Online%20will%20ignore%20it.%20I%20wrongly%20assumed%20you%20are%20talking%20about%20Exchange-related%20objects.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-185723%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20-%20GAL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-185723%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20not%20what%20we%20are%20experiencing%20which%20is%20why%26nbsp%3BI%20thought%20it%20had%20to%20do%20with%20AD%20Connect.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20go%20to%20Outlook%20and%20go%20to%20Address%20Book%2C%20I%20do%20not%20see%20the%20disabled%20accounts%20in%20question.%3C%2FP%3E%3CP%3ENow%20if%20I%20open%20SfB%20and%20Type%20the%20name%20in%20the%20%22find%20someone%22%20search%20box%20the%20name%20shows%20up.%3C%2FP%3E%3CP%3EThe%20account%20in%20question%20doesn't%20have%20a%20mailbox%20(neither%20on-premises%20nor%20online)%2C%20I%20also%20checked%20the%20AD%20attribute%26nbsp%3B%3CSPAN%3EmsEchHideFromAddressLists%20which%20is%20set%20to%20TRUE%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWe%20observe%20this%20behavior%20for%20all%20our%20disabled%20accounts%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-185399%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20-%20GAL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-185399%22%20slang%3D%22en-US%22%3E%3CP%3EBoth%20Exchange%20and%20SfB%20will%20show%20disabled%20accounts%2C%20the%20don't%20differ%20I%20this%20regard%20and%20use%20the%20same%20attribute%20to%20%22hide%22%20a%20user.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20for%20address%20list%2C%20you%20can%20use%20the%20familiar%20Exchange%20cmdlets%3A%20%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fjj983798(v%3Dexchg.150).aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fjj983798(v%3Dexchg.150).aspx%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

So we have a hybrid environment with on-premises AD users that are synced to Office 365. Users'mailboxes are on Exchange Online. Azure AD OU filtering is not used yet so we sync all accounts (even disabled ones)

 

In Skype for Business Online when you search for a contact, it will also show the disabled accounts whereas the Exchange Address book won't show the disabled accounts

 

Is that normal, Skype doesn't use the same address book?

 

We are coming from an Exchange on-premises setup but we have almost migrated all mailboxes online, how does the GAL is maintained now Can I delete my on-premises Address lists? How can I create Address lists in Office 365?

9 Replies
Highlighted

Both Exchange and SfB will show disabled accounts, the don't differ I this regard and use the same attribute to "hide" a user.

 

As for address list, you can use the familiar Exchange cmdlets: https://technet.microsoft.com/en-us/library/jj983798(v=exchg.150).aspx

Highlighted

This is not what we are experiencing which is why I thought it had to do with AD Connect.

 

If I go to Outlook and go to Address Book, I do not see the disabled accounts in question.

Now if I open SfB and Type the name in the "find someone" search box the name shows up.

The account in question doesn't have a mailbox (neither on-premises nor online), I also checked the AD attribute msEchHideFromAddressLists which is set to TRUE

 

We observe this behavior for all our disabled accounts

Highlighted

Ah, I see. That explains it actually, Exchange address lists (including the GAL) only include valid Exchange recipient types, if the user doesn't have a mailbox (and is not represented by a mail-user object on-premises), Exchange Online will ignore it. I wrongly assumed you are talking about Exchange-related objects.

Highlighted

Would you know how to explain the difference between the Skype and Exchange Online contacts?

 

I am trying to understand how I could make that disabled accounts don't show up on Skype.

 

Highlighted

It's not about contacts per se, it's about the recipient type for the corresponding object. Here's an example to try in your tenant: create a user directly in the O365, do not license it for Exchange, but give it a SfB license. Such user will be visible in SfB, but NOT visible in Exchange, as it is not recognized as any valid Exchange recipient. The same applies when you sync objects from on-premises - only the objects that are recognized as valid Exchange recipients will show up in the GAL.

Highlighted

I still don't know what I should do...As an example, I have a user who left the company, her account is disabled in AD, the Exchange properties have been removed, her mailbox deleted, she is not licensed for anything in Office 365, she is an OU that gets synced by Azure AD connect, she shows p in SfB but not Exchange.

 

So the only way for her to not show in SfB is to remove the sync on the OU she is in?

 

Highlighted

If you do that, you might loose any data stored in her ODFB, so make sure you back that up if needed.

Highlighted

One more thing the disabled accounts will only show when you use the SfB client from a laptop or PC.

If we use the mobile client on Android or iPhone they don't show

Highlighted

One quick thought from reading about this issue is that when Skype desktop client downloads it's address book, it then saves the address book in the users Skype profile. If you sign on to a PC or laptop, Try deleting the Skype profile> exit out of the skype client by right clicking the skype icon in systray and clicking exit. Restart Skype. This will force a new download of the address book. If the deleted account still appears in searches, then you will need to alter the Skype online address book.

 

The simplest solution to alter the skype online address book would involve moving deleted users or users that should be hidden to an OU and configure AAD to filter that OU from AAD replication.