?
Solved

Exchange 2003 - Hide certain users from GAL, put in custom list instead

Posted on 2010-09-23
3
Medium Priority
?
785 Views
Last Modified: 2012-05-10
I have 2 groups of user accounts that need to be hidden from the GAL for housekeeping reasons, but need to be accessible by some of our staff because they are shared accounts.

The account names are sequenced, like ABCUser01, ABCUser02 etc. so it would be easy to find them via wildcarding.

I want to create custom address lists to put these accounts in, and grant access to them using security groups for the folks who need to see them.  This part I know how to do.

However, I can't hide them in the AD account GUI because they won't show in any list then.

I've seen some articles saying that you can use powershell to change an attribute on the user account to remove it from the GAL, but allow it to be published in a custom address list.

My questions are:
1. Is there an easy way to hide user accounts from the GAL but put them in a custom list?

2. If powershell or other scripted approach is the right way, can you show me how to do it?

Thank you.

John

0
Comment
Question by:jinscoe
2 Comments
 
LVL 12

Accepted Solution

by:
FDiskWizard earned 2000 total points
ID: 33745989
You can modify the GAL query... via ADSIEDIT.
But you need something uniquie to editify them with within the query.
You would have to add a search term to exclude. For example a specific descrition:
(!(description=ExcludeFromGAL))

See this: http://exchangeis.com/blogs/exchangeis/archive/2005/08/09/using-adsiedit-a-real-world-example.aspx

This is what the default GAL query looks like:

(&(mailnickname=*)(|(&(objectCategory=person)(objectClass=user)(!(homeMDB=*))(!(msExchHomeServerName=*)))(&(objectCategory=person)(objectClass=user)(|(homeMDB=*)(msExchHomeServerName=*)))(&(objectCategory=person)(objectClass=contact))(objectCategory=group)(objectCategory=publicFolder)(objectCategory=msExchDynamicDistributionList))(!(extensionAttribute1=CompanyName)))

I have changed before to exclude specific email domain used internally (users@domain2.com)
We had the same issue, we wanted them to show in other lists - just not the GAL.

So, we now have the below. You need to test your query! Do a results count before and after:

(& (mailnickname=*) (| (&(objectCategory=person)(objectClass=user)(!(homeMDB=*))(!(msExchHomeServerName=*)))(&(objectCategory=person)(objectClass=user)(|(homeMDB=*)(msExchHomeServerName=*)))(&(objectCategory=person)(objectClass=contact)(!(mail=*DOMAIN2.COM)))(objectCategory=group)(objectCategory=publicFolder)(objectCategory=msExchDynamicDistributionList) ))

For OTHER lists we added a special description and used that in the query instead of MAIL=..

let me know if you need any more info. I don't know of another way to do this..

0
 

Author Comment

by:jinscoe
ID: 33960767
l;
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I am posting this in case anyone runs into similar issues that I did, this may save you a lot of grief: Condition: 1. Your NetBIOS domain name contains an ampersand " & " character.  (e.g. AT&T) 2. You've tried to run any Microsoft installation…
Welcome to 2018! Exciting things lie ahead in the world of tech. To start things off, we compiled great member articles on how to stay safe, ways to learn, and much more! Read on to start your new year right.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Loops Section Overview
Suggested Courses

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question