Learn Exchange the Guru way !!!


GAL segregation based on Organizational unit (OU)

Creating a GAL based on OU filter is not an easy task.

I was recently working on an issue to segregate the GAL based on OU because of multiple domains hosted in a single AD Forest

There are multiple ways of doing the segregation using ldap query and using different attributes but this option sounds me very easy and simple.

Open Adsiedit.msc

Browse to Configuration–> CN=Microsoft Exchange –> CN=ORG –> CN=Address Lists Container –> All Global Address List –>

Right click Global Address List and go to Properties.

Look for the Addribute name MsExchSearchBase and add the OU in the following format


Check the screenshot.

Click apply, then ok. Close Adsiedit. Now this Gal will be restricted to this OU.

To make it more useful let us take a situation. You are into an issue where the requirement is to make an external contact visible in group membership from outlook and not visible in GAL. Microsoft has confirmed that this is a product by design if an object is selected “hide from Exchange Address Lists” and this is a member of a distribution Group then this object will receive the email, will be visible the distribution group membership in OWA but it will not be visible in outlook in the distribution group membership. So we need a work around to make our customer happy.

Follow the steps:

  1. Created the group 123 in the Users OU.
  2. Created the User TestGAL1 in the Users OU.
  3. Created the contact testgc2 in the Users OU

Created the contact tg3 in test container

Configured msExchSearchBase attribute with the value Users ou DN.

Tested in the outlook

-123 is the group

-Tg3 is the contact in the non searchbase OU which is showing as member of the DL but not showing in the GAL.

MsExchSearchBase is one the nice and simple attribute which allows you to restrict you GAL query.

Prabhat Nigam

Team @MSExchangeGuru

12 Responses to “GAL segregation based on Organizational unit (OU)”

  1. amit Says:


  2. ram Says:

    Does this apply to Exchange 2003?
    I’ve tried with no luck.
    According to “” this doesn’t work for Exchange 2000.

  3. Prabhat Nigam Says:


    This article applies to Exchange 2007/10. We have never tested on 2003 but 2000 and 2003 works the same way so I am not sure.
    I will try to see if I get any 2003 environment to test.

  4. Alan Says:

    You need to take part in a contest for one of the best websites online.
    I am going to recommend this blog!

  5. Prabhat Nigam Says:

    Thank you Alan

  6. Weal starr Says:

    I couldn’t refrain from commenting. Perfectly written!

  7. Prabhat Nigam Says:

    Thank you Weal

  8. Mobin Says:


    Thanks for the help. Though I’m facing issues segregating GAL for a few mailbox users which have same name on different domains.


    DomainA AD User Logon It can only see DomainA address lists

    DomainB AD User Logon (Pre-Windows User Logon=DomainB\ It can see both DomainA and DomainB address lists.

    All others users with different username/email are working fine. Just to add on AD for I can’t see entry for msExchAddressBookPolicyLink on Attribute Editor but for I can see Address List entry under msExchAddressBookPolicyLink. I tried to add entry manually but it didn’t make any difference.

    Any help please?



  9. Prabhat Nigam Says:

    You can’t assign same email address to two mailboxes.
    Create an OU and move the user then exclude the OU from 1st domain’s email address policy.

  10. Mobin Says:

    Thanks for the reply Prabhat. These are 2 completely different email addresses as domains are different.

    I’ve resolved it by reassigning the Address book policy.


  11. Prabhat Nigam Says:

    Good to hear 🙂

  12. Kingshuk Says:

    Mobin can you please explain the below mentioned things ?

    I have created 2 or more UPN in my AD, like, After that created OU in my AD, OU names like and also created accepted domain in exchange 2010 server name like same.

    My domain name is rnd.local.

    Now my question is when mail users login in exchange OWA they can see all the address list which is default global address list.

    ? 1. How to set for different UPN can see only a specific address list like users mail id only not others.

    ? 2. How to set different password for exchange and AD.

Leave a Reply




Do NOT follow this link or you will be banned from the site!