SOLVED

Hide User from Skype for Business Online GAL - Possible?

Iron Contributor

Wanted to ask if its possible on O365 to hide users from Skype for Business Online on the resources that appear in address book / GAL search.

Why would I want to hide users?

Perhaps you have members of the organisation that you don’t want contacted by everybody else. Say if you have a strict communications policy that the CEO shouldn’t be directly contactable, you could hide them from appearing in the address book.

 

Let me know as currently in OnPrem you can but havent found articles about S4B Online

11 Replies
The reasoning behind the request is a bit of a concern, as CEO's are not beyond reproach. Good leaders do not hide themselves from their employees.
In any case, focusing on the request at hand and the tech you have - if the same cmdlet or method you use on-prem doesn't work online then it's a no go. Online doesn't have 100% parity with Server.
best response confirmed by Michael Hincapie (Iron Contributor)
Solution

@Loryan Strant Thank you for the response. it was just a scenario based question to make the point though. There are different scenarios we want to make sure we can use it for.   The presence privacy mode option might work for what we are looking for.

We had this problem. We cannot remove user accounts for compliance. We ended up creating an OU that was not synced to Office 365 and moving the user to the OU. It worked for us and was easier than any other option we found.

Well for my organization we have users that leave that we would not like listed in the GAL.

Within AD you can hide the account through "Attribute Editor" search for "msExchHideFromAddressLists" change the Value to "True" this would remove the user from the GAL and SFB. :)

 

But your way is also a right way.

@Damone PierreSetting the "msExchHideFromAddressLists" attribute is also how we choose to hide users from the GAL. However, we use AAD Connect to sync AD to Office 365 and I have found that setting this attribute only hides contacts in Outlook. If users search for the 'hidden' user in S4B or while logged into Office 365, the 'hidden' accounts are still visible.

 

The 'hidden' accounts are converted to shared mailboxes so that old email can still be accessed so the option of configuring an OU that does not sync to the tenant is not an option for us. I am doing some more testing around this and will report back anything useful.

I'm interested in any solutions to this issue. Same thing going on here.

Hi Bruce, 

 

I found some suggestion that this may be due to having disabled the AD accounts prior to setting the "msExchHideFromAddressLists" attribute. I tested reversing that order but it made no difference, the 'hidden' accounts are still visible when searching via Skype or Outlook web. 

Still needing a solution to this on our end so I'll update this if I find anything.

 

Regards,

I finally found a solution to this issue so hopefully this will assist others. Overview of our environment:

 

- Email in Office 365 tenant (migrated from on prem Exchange 2010)

- Setting the AD attribute 'msExchHideFromAddressList' to TRUE resulted in the mailbox being hidden from the GAL when using Outlook client but NOT when viewed in Web mail or Skype

- Requirement was to keep shared mailboxes in Office 365 (eg: could not simply stop synchronizing these users) for archive purposes but prevent those mailboxes from appearing when searching the GAL

 

I ended up doing some 'stare and compare' between users that were successfully hidden from the GAL everywhere and those that were not, it quickly became apparent the accounts that were originally created in Exchange and migrated to 365 were the accounts successfully being hidden from the GAL. I compared all AD attributes between a couple of accounts and found the users created after the migration did not have the 'mailNickname' attribute set - this is due to the fact you can make an account work on the Office 365 tenant by simply setting the 'proxyAddresses' attribute which is how all newer mailboxes had been commissioned. 

 

Confirmed after manually setting  the 'mailNickname' attribute and doing "start-adsyncsynccylce -Policytype Initial" the mailboxes were hidden from the GAL across the board.

So here is my issue for hiding users from Skype which none of these actually work.

I have 7000 mail contacts that we sync from a partner organization where I want them

to show in the GAL but not Skype

@Michael Thompson - That is outside the realm of what was being discussed in this thread so I'd suggest starting a new conversation. You may investigate synchronizing your external mail contacts to a separate address book that is available to all Outlook users.

 

Regards,

Benn

Trying to implement this myself and am a bit Skype-ignorant. I assume there is some sort of lag between this attribute being synced to AzureAD and population of the SfB Online/Exchange Online GAL and any Offline Address list. Is this the case? How long should I wait for this to come into effect in my SfB Client?

1 best response

Accepted Solutions
best response confirmed by Michael Hincapie (Iron Contributor)
Solution

@Loryan Strant Thank you for the response. it was just a scenario based question to make the point though. There are different scenarios we want to make sure we can use it for.   The presence privacy mode option might work for what we are looking for.

View solution in original post