Mail-enabled groups that have an email address aren't synchronized to Microsoft 365
Article
Applies to:
Exchange Online, Azure Active Directory, Microsoft 365
Original KB number: 2508722
Problem
When you use the Microsoft Azure Active Directory Sync Tool to sync your on-premises Active Directory Domain Services (AD DS) environment to Microsoft 365, you notice that mail-enabled groups that have an email address aren't synced to Microsoft 365.
This issue occurs if a display name isn't specified for the on-premises mail-enabled group.
Solution
Important
This section contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more info about how to back up and restore the registry, see How to back up and restore the registry in Windows.
To fix this issue, make sure that the on-premises mail-enabled group has a display name. You can use a tool such as Active Directory Service Interfaces Editor (ADSI Edit) or the LDP tool to populate the displayName attribute for the mail-enabled group in the on-premises AD DS environment.
The following procedure describes how to edit a display name by using ADSI Edit.
On a domain controller or a computer on which the Windows Server Administration Toolkit is installed, click Start, click Run, type adsiedit.msc in the Open box, and then click OK.
Right-click ADSI Edit, and then click Connect to.
Under Connection Point, click Select a well known Naming Context, and then make sure that Default naming context is selected in the drop-down box.
In the navigation pane on the left side, in the AD DS hierarchy, locate the mail-enabled group that isn't synced to Microsoft 365. Right-click the group, and then click Properties.
Click Filter, and then clear the Show only attributes that have values option.
On the Attribute Editor tab, locate the displayName attribute, and then double-click it.
In this example, the value of the displayName attribute is set to <not set>. This is reason why the group isn't synced to Microsoft 365.
In the Value box, enter a display name for the group, and then click OK.
Exit ADSI Edit.
Set the value of the FullSyncNeeded registry entry to 1. To do this, follow these steps:
Open Registry Editor. To do this, click Start, click Run, type regedit, and then press Enter.
In Registry Editor, locate the following registry subkey:
This learning path examines how organizations should plan for and implement identity synchronization in a hybrid Microsoft 365 deployment. You learn how to implement Microsoft Entra Connect Sync and Microsoft Entra Cloud Sync, and how to manage synchronized identities.
Describes an issue in which the owner of a distribution group that's synced to Microsoft 365 can no longer manage the distribution group. A resolution is provided.
Describes an issue that triggers an error when you try to remove a distribution group or make a change to the group in Exchange Online or in on-premises Exchange Server. Provides two methods of resolution.
Use the Exchange admin center (EAC) or Exchange Online PowerShell to create a new distribution group in your Exchange Online organization or to mail-enable an existing group.
A mail-enabled security group can be used to distribute messages and to grant access permissions to resources in Active Directory. For more information, see Recipients.