Disable Global Directory for an OU

alexgrutza
Contributor III

We have an OU in google that houses terminated users temporarily, and I am wondering if there is a way via the Dashboard to remove these accounts from the GAL. We would like all other users not to be able to see these users in this specific OU as they are terminated. 

I presume this will not reflect within a persons gmail when they go to create an email to send to one of these accounts? The name will still populate I presume?

I don't know of anyone who actually goes into the GAL to look up people.. at least I have never.. I just use the To: field to populate.. 

--
CISSP | LinkedIn | @Phyxiis
3 REPLIES 3

SteveHarmon
Contributor

Not sure if there is a way to do exactly what I think you are asking for, but there are ways to set up Custom Directories for different OUs. We do this for our student OUs so that they can only find the staff and students from their school sites, not from the entire district. You can also set it to No users, which means that accounts in that OU cannot see other accounts in the domain (we do this for our Disabled Users OU and some others).

Directory > Directory settings > Visibility settings

Right, it would be somewhat like your disabled users ou, however my question to that is: if the account is disabled, why would you disable the directory visibility to accounts which aren't logging in? Or is it vis versa where no one can lookup the disabled accounts in the gal?

We're higher ed so it's not too big of a concern if our students can see everyone in the gal, but what we'd want is so that disabled users or terminated users are not present in the gal because they're in an ou that has all users in that ou removed automatically via the dashboard. 

I'm aware that a gam script could run periodically and just remove the user from gal within that directory, but would like to know if it's possible via the dashboard for other admins to be aware of 

--
CISSP | LinkedIn | @Phyxiis

Steve,

Thank you for the reminder of this setting. Am I correct in understanding that removing "Domain Shared Contacts" from each building's student OU will limit the student addresses to their building?