Jeff Swift 

Hide from GAL/Remove user

Hi all.  How are O365 customers, without an on-prem exchange server or the Exchage attributes in AD, handling hiding departed emplyees from the GAL?  When we try to hide a user from the address list, we receive an error: 

The operation on mailbox "user.name_36dc2c04ca" failed because it's out of the current user's write scope. The action 'Set-Mailbox', 'HiddenFromAddressListsEnabled', can't be performed on the object 'user.name_36dc2c04ca' because the object is being synchronized from your on-premises organization. This action should be performed on the object in your on-premises organization.

Has anyone else come across this?  If so, what is the resolution?  I have a case with Okta opened but i'm curiouse to see what other folks are doing.
Razvan Negri (Okta, Inc.)
Hi Jeff,

The only workaround would be switching to Universal Sync and mapping the attribute from your AD Okta instance to O365 as:

For more information about Universal Sync check:

Please note that this is an EA feature.

Jeff Swift
Thank you for the reply.  We're using Universal Sync but we don't have the msExchHideFromAddressLists attribute in our AD - we don't have an on-prem exchange server nor do we have the schema extended for Exchange.  

Where would I map hasDirectoryUser()?findDirectoryUser().MSExchHideFromAddressLists:null?  Is there an Okta supported document for customers in our situation?