How to Manage Email Aliases in Microsoft 365 Hybrid Active Directory
Question details
Administrators are unable to add or view email aliases for synchronized users directly in the Microsoft 365 portal and must find the correct way to manage them.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Attempting to add, edit, or remove an email alias for a user account in a hybrid Microsoft 365 environment.
- Observed behavior
- Synchronized aliases cannot be managed in the cloud portal because directory-synchronized attributes are locked and require local Active Directory management.
Ensure you have Domain Admin or appropriate organizational management permissions in your local Active Directory, and verify that Azure AD Connect is actively running without sync errors.
Manage Aliases Using the proxyAddresses Attribute in Local Active Directory
Because the user account is synced from your local AD, all alias modifications must be performed on-premises and then synchronized to the cloud.
In a hybrid environment, the Source of Authority for synced users is your local Active Directory. Microsoft 365 locks the ability to edit these attributes in the cloud portal to prevent synchronization conflicts. Updating the proxyAddresses attribute locally is the standard method.
Log in to your domain controller and launch 'Active Directory Users and Computers' (ADUC).
Click on the 'View' menu at the top and ensure 'Advanced Features' is checked. This allows you to view the Attribute Editor.
Navigate to the Organizational Unit (OU) where the user resides, right-click their account, and select 'Properties'.
Go to the 'Attribute Editor' tab, scroll down to find the 'proxyAddresses' attribute, and click 'Edit'.
To add a secondary email alias, type 'smtp:alias@yourdomain.com' (with a lowercase 'smtp') and click 'Add'. Ensure the primary address uses an uppercase 'SMTP:' prefix. Click 'OK' to save.
Wait for the next automatic Azure AD Connect sync cycle (usually every 30 minutes), or manually force a delta sync using PowerShell.

Update Aliases via On-Premises Exchange Admin Center
If you maintain a local Exchange server for management purposes, you can use its web-based interface to manage email addresses more intuitively.
A Lightweight and Compatible Alternative to Microsoft Office
While IT administrators manage complex Microsoft 365 hybrid environments, end-users often just need a reliable, fast, and highly compatible office suite. WPS Office provides an excellent alternative that handles standard documents, spreadsheets, and presentations seamlessly.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install the Software: Run the downloaded installer and follow the quick on-screen instructions to set up WPS Office on your computer.
- 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Office files without any conversion or formatting loss.

Frequently Asked Questions
Why can't I edit aliases directly in the Microsoft 365 admin center?
In a hybrid setup, the on-premises Active Directory is the authoritative source for synchronized users. To prevent data conflicts between the cloud and on-premises environments, Microsoft 365 disables cloud-side editing for attributes like email aliases. They must be updated locally and synced upwards.
What is the difference between 'SMTP:' and 'smtp:' in the proxyAddresses attribute?
The uppercase 'SMTP:' prefix designates the primary email address used for outgoing mail. The lowercase 'smtp:' prefix is used for secondary email aliases that only receive incoming mail.
How long does it take for a new alias to appear in Exchange Online?
By default, Azure AD Connect synchronizes changes every 30 minutes. Once the synchronization process completes, it may take a few additional minutes for Exchange Online to fully propagate the new alias to the user's mailbox and Global Address List.
Can I manage cloud-only user aliases in Active Directory?
No. Users created directly in Microsoft 365 (cloud-only users) are not synchronized from your local Active Directory. Their email aliases and other attributes must be managed directly in the Microsoft 365 admin center or the Exchange admin center.




