How to Hide a Shared Mailbox from the Global Address List in Hybrid Exchange
Question details
The user needs to hide a shared mailbox from the Global Address List (GAL) but is experiencing issues where the mailbox remains visible despite on-premises configurations.

- Product
- Microsoft Exchange
- Device & OS
- not provided
- Scenario
- Attempting to hide a shared mailbox from the GAL by setting the on-premises Active Directory attribute in a hybrid Exchange setup.
- Observed behavior
- The shared mailbox remains visible in the GAL even after the msExchHideFromAddressLists attribute is set to True in the on-premises Active Directory.
Ensure you have the necessary administrative credentials for both the on-premises Active Directory and Exchange Online, and verify that Azure AD Connect is running without major directory synchronization errors.
Verify Directory Synchronization and Exchange Online Attributes
Use this solution to ensure that the on-premises AD attribute changes are correctly syncing to Microsoft 365 and reflecting in Exchange Online.
In a Hybrid Exchange environment, the on-premises Active Directory is the authoritative source. Therefore, GAL visibility must be managed on-premises and synchronized to Exchange Online via Azure AD Connect.
Open 'Active Directory Users and Computers' with Advanced Features enabled. Locate the shared mailbox, go to the 'Attribute Editor' tab, and confirm that the 'msExchHideFromAddressLists' attribute is set to True.
Open PowerShell on your Azure AD Connect server and run 'Start-ADSyncSyncCycle -PolicyType Delta' to force an immediate synchronization to Microsoft 365.
Connect to Exchange Online PowerShell and run the command: 'Get-Mailbox <MailboxIdentity> | Format-List'. Check the output to confirm that 'HiddenFromAddressListsEnabled' is marked as True.
If the attribute does not update, review the Azure AD Connect synchronization logs for errors, and check the Microsoft 365 audit logs to see if subsequent operations overwrote the mailbox changes.

Manage Your Work More Efficiently with WPS Office
While resolving backend Microsoft Exchange synchronization issues requires technical troubleshooting, managing your daily documents shouldn't be complicated. WPS Office provides a lightweight, highly compatible alternative to Microsoft Office for your productivity needs.
- 1. Download the Installer: Visit the official WPS Office website to download the free version suited for your operating system (Windows, Mac, or Linux).
- 2. Install WPS Office: Run the downloaded installer file and follow the straightforward on-screen instructions to set up the software.
- 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Office files (.docx, .xlsx, .pptx) without losing any formatting.

Frequently Asked Questions
Why can't I hide the shared mailbox directly in the Exchange admin center?
In a Hybrid Exchange environment where the mailbox is synchronized from an on-premises Active Directory, the on-premises AD remains the authoritative source. You cannot modify synced attributes directly in the Microsoft 365 Exchange admin center.
What should I do if the msExchHideFromAddressLists attribute does not sync?
First, verify that the 'mailNickname' attribute is populated in the on-premises Active Directory, as Azure AD Connect requires this attribute to successfully sync the 'msExchHideFromAddressLists' property.
How can I verify if the Offline Address Book (OAB) has been updated?
You can force a manual download of the OAB in the Outlook desktop client by navigating to the Send/Receive tab, clicking Send/Receive Groups, and selecting 'Download Address Book'. If the mailbox is still visible, the OAB generation on the server may not have completed yet.




