Avatar of Tech Man
Tech ManFlag for United States of America

asked on 

Global Address List (GAL) and Offline Address Book in Hybrid Exchange with Cloud only accounts.

Global Address List (GAL) and Offline Address Book in Hybrid Exchange with Cloud only accounts.

We have Hybrid Exchange, almost all the mailboxes are in the cloud. ADsync runs to synchronize on-prem AD with Azure AD.
Our organization also has about 200 cloud only users (No op-prem AD accounts).
What would be a recommended way to configure GAL and OAB that on-prem users can find On-prem and Cloud only users and vise-versa?

Thank you
ExchangeMicrosoft 365* Exchange HybridAzure

Avatar of undefined
Last Comment
Tech Man
Avatar of Mahesh
Mahesh
Flag of India image

Create those 200 accounts with onpremise AD as users and enable remote mailbox (it actually set remote routing address  or target address on those accounts pointing to .onmicrosoft.com ID in cloud) and sync them to O365, this way they will get connected to respective O365 users and will be populated with onpremise exchange GAL as well.
Avatar of Tech Man
Tech Man
Flag of United States of America image

ASKER

Thank you for your response but in our case, we don't want to have their accounts on-prem, Why?

- because they don't have access to on-prem network and will not be able to change their password.
- Don't want to pay Server CAL licenses for users who are remote
- Don't want to purchase Azure AD Premium for password write back


Our goal is to have corporate users (who are in the network) to have their account On-Prem synced with AAD but have their mailboxes in the cloud (Hybrid). But frontline workers to have their account Cloud only.

Thank you
Avatar of Mahesh
Mahesh
Flag of India image

You will simply create those accounts in onpremise AD
It not means you have to pay CALS for them since you sync those accounts with password to cloud and exchange online use azure ad for authentication and not onpremise AD
If you concerned about password, you can set non expiring password
OR
There are bunch of free online password reset tools available for onpremise AD, you can use that

Else You can create contact objects in exchange onpremise and point them to Onmicrosoft.com target address to populate with GAL but they cannot be synced to O365 actual mailboxes and then its difficult to manage onpremise GAL as contact remains isolated
Avatar of Tech Man
Tech Man
Flag of United States of America image

ASKER

Thank you for response:
- do you have any Microsoft documentation referencing to what you said about not being required to purchase CALs for users who are just synced ?

- do you know solid tool that would allow users to reset their AD PASSOWRD.  main concern is securoty.

Thank you
ASKER CERTIFIED SOLUTION
Avatar of Mahesh
Mahesh
Flag of India image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of Tech Man
Tech Man
Flag of United States of America image

ASKER

Thank you Mahesh, very helpful!
Exchange
Exchange

Exchange is the server side of a collaborative application product that is part of the Microsoft Server infrastructure. Exchange's major features include email, calendaring, contacts and tasks, support for mobile and web-based access to information, and support for data storage.

213K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo