logo
search
Exchange Connection Problems

How to Hide a Shared Mailbox from the Global Address List in Hybrid Exchange

Emma BrownEmma Brown Sep 27, 2026 869 views

Question details

The user needs to hide a shared mailbox from the Global Address List (GAL) but is experiencing issues where the mailbox remains visible despite on-premises configurations.

How to Hide a Shared Mailbox from the Global Address List in Hybrid Exchange
Product
Microsoft Exchange
Device & OS
not provided
Scenario
Attempting to hide a shared mailbox from the GAL by setting the on-premises Active Directory attribute in a hybrid Exchange setup.
Observed behavior
The shared mailbox remains visible in the GAL even after the msExchHideFromAddressLists attribute is set to True in the on-premises Active Directory.
Before you start

Ensure you have the necessary administrative credentials for both the on-premises Active Directory and Exchange Online, and verify that Azure AD Connect is running without major directory synchronization errors.

Solution 1Recommended

Verify Directory Synchronization and Exchange Online Attributes

Use this solution to ensure that the on-premises AD attribute changes are correctly syncing to Microsoft 365 and reflecting in Exchange Online.

In a Hybrid Exchange environment, the on-premises Active Directory is the authoritative source. Therefore, GAL visibility must be managed on-premises and synchronized to Exchange Online via Azure AD Connect.

1
Configure the On-Premises Attribute

Open 'Active Directory Users and Computers' with Advanced Features enabled. Locate the shared mailbox, go to the 'Attribute Editor' tab, and confirm that the 'msExchHideFromAddressLists' attribute is set to True.

2
Force Directory Synchronization

Open PowerShell on your Azure AD Connect server and run 'Start-ADSyncSyncCycle -PolicyType Delta' to force an immediate synchronization to Microsoft 365.

3
Verify in Exchange Online PowerShell

Connect to Exchange Online PowerShell and run the command: 'Get-Mailbox <MailboxIdentity> | Format-List'. Check the output to confirm that 'HiddenFromAddressListsEnabled' is marked as True.

4
Review Operational Logs

If the attribute does not update, review the Azure AD Connect synchronization logs for errors, and check the Microsoft 365 audit logs to see if subsequent operations overwrote the mailbox changes.

Verify Directory Synchronization and Exchange Online Attributes
Offline Address Book Delay: Even after successful synchronization, it can take up to 24 hours for the changes to appear in the Outlook desktop client due to the time required to generate and download the Offline Address Book (OAB).
Free Microsoft Office alternative

Manage Your Work More Efficiently with WPS Office

While resolving backend Microsoft Exchange synchronization issues requires technical troubleshooting, managing your daily documents shouldn't be complicated. WPS Office provides a lightweight, highly compatible alternative to Microsoft Office for your productivity needs.

  1. 1. Download the Installer: Visit the official WPS Office website to download the free version suited for your operating system (Windows, Mac, or Linux).
  2. 2. Install WPS Office: Run the downloaded installer file and follow the straightforward on-screen instructions to set up the software.
  3. 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Office files (.docx, .xlsx, .pptx) without losing any formatting.
Completely free and lightweight Office suiteHighly compatible with Microsoft Word, Excel, and PowerPoint formatsAll-in-one workspace featuring seamless tabbed document viewingBuilt-in PDF editing, conversion, and annotation tools
microsoft office alternative - wps office

Frequently Asked Questions

Why can't I hide the shared mailbox directly in the Exchange admin center?

In a Hybrid Exchange environment where the mailbox is synchronized from an on-premises Active Directory, the on-premises AD remains the authoritative source. You cannot modify synced attributes directly in the Microsoft 365 Exchange admin center.

What should I do if the msExchHideFromAddressLists attribute does not sync?

First, verify that the 'mailNickname' attribute is populated in the on-premises Active Directory, as Azure AD Connect requires this attribute to successfully sync the 'msExchHideFromAddressLists' property.

How can I verify if the Offline Address Book (OAB) has been updated?

You can force a manual download of the OAB in the Outlook desktop client by navigating to the Send/Receive tab, clicking Send/Receive Groups, and selecting 'Download Address Book'. If the mailbox is still visible, the OAB generation on the server may not have completed yet.