On-Prem and Office 365 GALs are different

Hi everyone.

We're in a hybrid setup with Exchange 2013 and Ofice 365.

Our issue is that some users with a mailbox in Office 365 cannot send to some users with mailbox on the on-prem Exchange 2013.
I've narrowed it down to the GALs, where the primarysmtp fields are different for the same user.

On-prem GAL entry:
x500:/0=ExchangeLabns/.... etc

Office 365 GAL entry:
SPO:SPO_436334 etc
x500:/o=COMPANY/ou=Exchange Administrative Group [FYDI.... etc

The MAIN culprit here is of course that the user's Primary SMTP address, listed in the Office 365 GAL, does not exist on the user's mail account at all.

But why are those two GAL's different? Is that by design? Links and/or helpful answers are much appreciated.


Bjorn Dirchsen
Bjorn DirchsenSysAdmAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Vasil Michev (MVP)Commented:
If you have made changes directly in O365, those are in general not written back to AD. This is indeed by design, there are very few attributes that are written back to on-premises and only in specific situations. ProxyAddresses is one of those attributes (if you have the "Hybrid" option in AAD Connect enabled), so I'm not sure what went wrong in your case. But it's always required to make any changes in AD, then rely on dirsync to replicate them in O365.

In this specific scenario, you can just add the additional alias on-prem and be done with it.
Shreedhar EtteCommented:
Is domain dept-company.com is added to Office 365 Domains?
Bjorn DirchsenSysAdmAuthor Commented:
@Vasil Michev. We ONLY make changes to users from the on-prem AD/Exchange since only few changes are written back from Office 365.  SO we can rule this out. Ok, I can add the nescessary attributes, but since these users are test-users i would like this to work before I migrate the remaining 100 users :)

Thanks, Bjorn
Big Business Goals? Which KPIs Will Help You

The most successful MSPs rely on metrics – known as key performance indicators (KPIs) – for making informed decisions that help their businesses thrive, rather than just survive. This eBook provides an overview of the most important KPIs used by top MSPs.

Bjorn DirchsenSysAdmAuthor Commented:
@Shreedhar Ette. No, dept-company.com is not added to the Office 365 domains. Could that be the reason?
Shreedhar EtteCommented:
Yes, Domain needs to be added to Office 365.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Vasil Michev (MVP)Commented:
Oh, good catch Shreedhar, I totally missed that. And it seems I also misinterpreted the addresses, assuming the O365 ones are the on-premises ones... Guess I should drink some more coffee :)

So yeah, Bjorn, you need to add/verify any domains you have associated with email addresses and any other attributes. Otherwise they will either be replaced with the @tenant.onmicrosoft.com domain or dropped altogether.
Bjorn DirchsenSysAdmAuthor Commented:
Cool. I'll jump to it right away and update with my findings.

Thanks a lot guys!

Br, Bjorn
Bjorn DirchsenSysAdmAuthor Commented:
It worked! Adding dept-company.com to the list of Domains (and waiting for the GAL to be updated at 5am)  solved it.

The attributes of the user in the O365 GAL are now:

Office 365 GAL entry:
SMTP:user.name@dept-company.com   <-- New!
SPO:SPO_436334 etc
x500:/o=COMPANY/ou=Exchange Administrative Group [FYDI.... etc
smtp:initials@dept-company.com   <--- New!

Thanks to Shreedhar for spotting the culprit right away!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.