Proxy address conflict when syncing contacts into Azure AD then attempting to create guest users

%3CLINGO-SUB%20id%3D%22lingo-sub-3290619%22%20slang%3D%22en-US%22%3EProxy%20address%20conflict%20when%20syncing%20contacts%20into%20Azure%20AD%20then%20attempting%20to%20create%20guest%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3290619%22%20slang%3D%22en-US%22%3E%3CP%3EI've%20heard%20varying%20comments%20about%20proxy%20address%20conflicts%20with%20contacts%20and%20guest%20users.%26nbsp%3B%20I%20believe%20the%20context%20matters.%26nbsp%3B%20Let's%20discuss%20a%20specific%20scenario%20where%20contacts%20and%20DLs%20have%20been%20created%20on-premises%2C%20are%20being%20synced%20to%20Azure%20AD%20via%20AD%20Connect%2C%20and%20are%20causing%20an%20issue%20when%20guest%20accounts%20are%20created%20due%20to%20proxy%20address%20conflicts.%26nbsp%3B%20You%20cannot%20create%20the%20guest%20user%20since%20the%20contact%20has%20the%20same%20proxy%20address%20as%20the%20guest%20user.%26nbsp%3B%20I%20have%20recommended%20not%20syncing%20the%20contacts%20to%20AAD%20and%20removing%20them%20from%20AAD.%26nbsp%3B%20Well%20the%20purpose%20of%20syncing%20the%20contacts%20and%20DLs%20was%20so%20they%20would%20be%20available%20for%20Exchange%20Online%20users.%26nbsp%3B%20Can%20the%20contacts%20be%20replaced%20with%20guest%20users%20and%20the%20guest%20users%20be%20added%20to%20the%20Exchange%20Online%20GAL.%26nbsp%3B%20Yes%20this%20is%20possible.%26nbsp%3B%20Once%20the%20guest%20users%20have%20been%20added%20to%20the%20Exchange%20Online%20GAL%2C%20can%20DLs%20be%20created%20and%20the%20guest%20users%20be%20added%20to%20the%20DLs.%26nbsp%3B%20It%20seems%20so.%26nbsp%3B%20In%20summary%2C%20does%20this%20seem%20like%20a%20viable%20solution%20so%20that%20both%20Exchange%20Server%20users%20and%20Exchange%20Online%20users%20both%20can%20email%20users%20outside%20there%20organization%3F%26nbsp%3B%20Are%20there%20other%20recommended%20solutions%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3290619%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20hybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3297684%22%20slang%3D%22en-US%22%3ERe%3A%20Proxy%20address%20conflict%20when%20syncing%20contacts%20into%20Azure%20AD%20then%20attempting%20to%20create%20guest%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3297684%22%20slang%3D%22en-US%22%3EIn%20a%20nutshell%2C%20contacts%20are%20being%20synced%20from%20AD%20DS%20to%20Azure%20AD%20and%20have%20proxy%20addresses.%20Those%20proxy%20addresses%20are%20the%20exacting%20the%20same%20ones%20required%20to%20create%20the%20guest%20user%20accounts.%20The%20guest%20user%20cannot%20be%20created%20since%20the%20contact%20and%20guest%20user%20proxy%20address%20would%20conflict.%20The%20customer%20does%20not%20plan%20to%20move%20away%20from%20Exchange%20Hybrid%20anytime%20in%20the%20foreseeable%20future%20and%20now%20wants%20to%20perform%20M365%20inter-tenant%20collaboration%20with%20two%20subsidiaries%20hence%20the%20requirement%20to%20create%20guest%20users%20for%20those%20subsidiaries.%20They%20desire%20to%20have%20those%20contacts%20available%20in%20Exchange%20Server%20GAL%20and%20replicate%20the%20equivalent%20of%20the%20contact%20in%20the%20Exchange%20Online%20GAL%20simultaneously%20but%20need%20to%20use%20guest%20user%20accounts.%20In%20summary%2C%20there%20is%20a%20need%20to%20resolve%20the%20issue%20where%20the%20contacts%20synced%20to%20Azure%20AD%20prevent%20guest%20user%20creation%20due%20to%20the%20proxy%20address%20conflict.%20The%20only%20way%20I%20know%20to%20do%20this%20is%20to%20not%20sync%20the%20contacts%20from%20AD%20into%20Azure%20AD%20so%20guest%20users%20can%20be%20created.%20The%20contacts%20and%20any%20DLs%20the%20contacts%20are%20included%20in%20would%20not%20be%20available%20in%20Azure%20AD%20hence%20the%20Exchange%20Online%20GAL.%20That%20would%20allow%20the%20creation%20of%20guest%20users%20since%20the%20proxy%20address%20conflict%20would%20be%20resolved.%20The%20next%20issue%20is%20how%20to%20make%20those%20former%20contacts%20available%20in%20the%20Exchange%20Online%20GAL%20but%20when%20using%20guest%20users.%20By%20default%2C%20guest%20users%20are%20hidden%20from%20the%20Exchange%20Online%20GAL%20but%20can%20be%20unhidden.%20DLs%20can%20be%20created%20and%20those%20guest%20users%20added%20to%20DLs%20and%20all%20would%20be%20available%20in%20the%20Exchange%20Online%20GAL.%20I%20am%20hoping%20someone%20else%20has%20run%20into%20this%20same%20issue%20and%20confirms%20that%20this%20is%20a%20sound%20approach%20or%20can%20recommend%20another%20option.%3C%2FLINGO-BODY%3E
Occasional Contributor

I've heard varying comments about proxy address conflicts with contacts and guest users.  I believe the context matters.  Let's discuss a specific scenario where contacts and DLs have been created on-premises, are being synced to Azure AD via AD Connect, and are causing an issue when guest accounts are created due to proxy address conflicts.  You cannot create the guest user since the contact has the same proxy address as the guest user.  I have recommended not syncing the contacts to AAD and removing them from AAD.  Well the purpose of syncing the contacts and DLs was so they would be available for Exchange Online users.  Can the contacts be replaced with guest users and the guest users be added to the Exchange Online GAL.  Yes this is possible.  Once the guest users have been added to the Exchange Online GAL, can DLs be created and the guest users be added to the DLs.  It seems so.  In summary, does this seem like a viable solution so that both Exchange Server users and Exchange Online users both can email users outside there organization?  Are there other recommended solutions?

1 Reply
In a nutshell, contacts are being synced from AD DS to Azure AD and have proxy addresses. Those proxy addresses are the exacting the same ones required to create the guest user accounts. The guest user cannot be created since the contact and guest user proxy address would conflict. The customer does not plan to move away from Exchange Hybrid anytime in the foreseeable future and now wants to perform M365 inter-tenant collaboration with two subsidiaries hence the requirement to create guest users for those subsidiaries. They desire to have those contacts available in Exchange Server GAL and replicate the equivalent of the contact in the Exchange Online GAL simultaneously but need to use guest user accounts. In summary, there is a need to resolve the issue where the contacts synced to Azure AD prevent guest user creation due to the proxy address conflict. The only way I know to do this is to not sync the contacts from AD into Azure AD so guest users can be created. The contacts and any DLs the contacts are included in would not be available in Azure AD hence the Exchange Online GAL. That would allow the creation of guest users since the proxy address conflict would be resolved. The next issue is how to make those former contacts available in the Exchange Online GAL but when using guest users. By default, guest users are hidden from the Exchange Online GAL but can be unhidden. DLs can be created and those guest users added to DLs and all would be available in the Exchange Online GAL. I am hoping someone else has run into this same issue and confirms that this is a sound approach or can recommend another option.