Hidden from GAL Changes Not Reflecting in Exchange Admin Center (Hybrid Environment)

Zayan zay 40 Reputation points
2026-06-20T18:42:37.18+00:00

Hi Team,

Our environment is hybrid. I have attempted to hide several users from the Global Address List (GAL) using the following steps:

  1. Open Active Directory Users and Computers.
  2. Locate the user account.
  3. Go to Attribute Editor.
  4. Set msExchHideFromAddressLists to TRUE.
  5. Run the following synchronization commands:

Start-ADSyncSyncCycle -PolicyType Delta

Start-ADSyncSyncCycle -PolicyType Initial

I have verified that Azure AD Connect synchronization is working correctly. However, I do not see any changes reflected in the Exchange Admin Center, and the users are still visible.

Could you please advise how to resolve this issue or what additional checks should be performed?

Thank you.

 

Exchange | Hybrid management
Exchange | Hybrid management

The administration of a hybrid deployment that connects on-premises Exchange Server with Exchange Online, enabling seamless integration and centralized control.

0 comments No comments

Answer accepted by question author
Vasil Michev 128K Reputation points MVP Volunteer Moderator
2026-06-20T19:19:03.1+00:00

msExchHideFromAddressLists is an Exchange attribute, and the rule to have it synced to Entra ID requires that the object has the mailNickname/alias attribute populated. So check for that. If the value of mailNickname/alias is null, the corresponding sync rule will not trigger, and changes to any Exchange-related attribute values will not be reflected in Microsoft 365.

Here's the corresponding documentation article: https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/concept-azure-ad-connect-sync-default-configuration#user-out-of-box-rules

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-06-20T18:43:01.4566667+00:00

    In a hybrid Exchange environment, hiding on-premises users from the GAL for Exchange Online requires that the msExchHideFromAddressLists attribute be correctly set on-premises and then synchronized to Azure AD/Exchange Online. The key checks and steps are:

    1. Confirm the on-premises attribute is set correctly
      • In Active Directory Users and Computers, open the user’s Properties → Attribute Editor.
      • Verify msExchHideFromAddressLists is set to True (not just edited once; confirm it is still True).
    2. Verify directory synchronization completed
      • After setting the attribute, allow time for Azure AD Connect to synchronize, or run a sync as already done.
      • Ensure the sync cycle completes successfully (no errors in Azure AD Connect).
    3. Understand how hiding works in Exchange Online
      • For cloud recipients, Exchange Online uses the HiddenFromAddressListsEnabled flag.
      • When this is set to $true, the recipient is hidden from all address lists and GALs.
      • The equivalent in Exchange Online PowerShell is:
             Set-<RecipientType> -Identity <RecipientIdentity> -HiddenFromAddressListsEnabled $true
        
        where <RecipientType> can be Mailbox, DistributionGroup, MailUser, etc.
    4. Check the recipient in Exchange Online
      • Use Exchange Online PowerShell to confirm whether the synchronized object is actually marked as hidden:
             Get-Recipient -Identity <UserUPN or Email> | fl Name,HiddenFromAddressListsEnabled
        
      • If HiddenFromAddressListsEnabled is still $false, the on-premises attribute change may not be flowing, or the object type may require direct configuration in Exchange Online.
    5. Hide directly in Exchange Online (if applicable)
      • If the object is managed in Exchange Online (for example, a Microsoft 365 Group or a cloud-only object), use the appropriate cmdlet:
        • For a mailbox:
                 Set-Mailbox -Identity <UserUPN> -HiddenFromAddressListsEnabled $true
          
        • For a distribution group:
                 Set-DistributionGroup -Identity "Group Name" -HiddenFromAddressListsEnabled $true
          
        • For a Microsoft 365 Group (Unified Group):
                 Set-UnifiedGroup -Identity <UnifiedGroupIdParameter> -HiddenFromAddressListsEnabled $true
          
    6. Verify in Exchange Admin Center (EAC)
      • In the EAC (https://admin.exchange.microsoft.com), go to:
        • Recipients → Mailboxes for user mailboxes, or
        • Recipients → Groups for groups.
      • Select the recipient and check the Hide from global address list (GAL) / Hide this group from the global address list setting.
      • Ensure the toggle is On.
    7. Verify the result in address lists
      • After the change, allow time for the GAL and Offline Address Book to update.
      • In Outlook/Outlook on the web, check that the user no longer appears in the GAL.

    If the on-premises attribute is correctly set and synchronization is confirmed, but HiddenFromAddressListsEnabled remains $false in Exchange Online, focus on configuring the recipient directly in Exchange Online as shown above and then verify via EAC and Outlook.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.