Skip to content
Contactzilla
Back to Blog
Uncategorized •

Sync the Global Address List (GAL) to iPhone

Nick Holder

Nick Holder

MDM Deployment Specialist

Contactzilla banner reading "How to Sync the Global Address List (GAL) To iPhones," showing an icon for the source directory flowing into the Contactzilla logo, next to two phone screens showing the Contacts app with lists split out by department, such as "department:finance" and "department:hr."

Keeping the Global Address List up to date in Microsoft 365 is the easy part. Getting it onto your team's iPhones as real contacts, with caller ID working when someone calls in, is the part Microsoft doesn't hand you by default.

Short answer: The GAL is a directory lookup, not a contacts account, so iPhone's Contacts app never receives it directly. Something has to pull the directory data out and deliver it as a real contacts account, most reliably a CardDAV account pushed through MDM. Contactzilla does this by importing from Microsoft Entra ID into a managed address book, then deploying that address book to iPhone as a CardDAV account, so the contacts appear natively with caller ID.

Does the Global Address List sync to iPhone Contacts automatically?

No. Microsoft 365 keeps directory data and device contact sync deliberately separate. The GAL exists to support email addressing and Exchange directory lookups, and Microsoft's sync model runs the other way: through Exchange ActiveSync and Outlook, which sync a mailbox's own Contacts folder, not the directory itself. iOS follows the same split. The Contacts app only shows entries belonging to a configured account, such as iCloud, CardDAV, or an Exchange mailbox, and the GAL isn't one of those. Microsoft's own support engineers confirm this directly: it is "currently not possible to sync GAL to mobile phones natively", and a manual per-contact export from Outlook is the only workaround Microsoft itself offers.

That's why searching in iOS can surface a GAL entry through a linked Exchange or Outlook connection, while the same person is nowhere to be found in the Contacts app itself: search reaches the directory, but the Contacts app only reads from accounts.

Key definitions

Global Address List (GAL): the organisation-wide directory Exchange builds from users, mail contacts and distribution lists, used mainly for email addressing and lookups rather than device contacts.

Entra ID directory users: the identity objects behind those people in Microsoft Entra ID, carrying attributes such as name, phone number, job title and department, which is the data an importer actually reads.

Mailbox contacts: the personal contacts inside one person's mailbox, synced individually through Outlook or ActiveSync, and unrelated to the shared directory.

Tip: New to CardDAV? What is CardDAV? covers how the protocol itself works before you get into the Entra ID and MDM specifics below.

What are your options for getting the GAL onto iPhone?

Every approach comes down to the same question: what pulls the directory data out, and how does it reach the device as a contacts account. Here's how the common approaches compare.

Options for delivering GAL data to iPhone Contacts

OptionStays updated?Shows in native Contacts / caller ID?Effort
Manual CSV or vCard exportNo, one-offYes, once importedLow per export, grows over time
Outlook "Save Contacts"Partial, depends on the mailboxInconsistent, duplicates commonLow to enable, unreliable to maintain
Exchange ActiveSync (mailbox contacts)Yes, for that mailbox's own contactsYesMedium; creates a separate copy per mailbox
Script or Graph API exportOnly if you build and run it on a scheduleNo, not directly, it writes contacts into individual Outlook mailboxes, not a shared device accountHigh; app registration, a maintained script, no built-in deduplication
Third-party sync toolYes, typicallyYes, typicallyMedium; ongoing subscription and setup
Entra importer + MDM (Contactzilla)Yes, automaticallyYesLow, after initial setup

The script/Graph API route is real and IT admins do build it: a common pattern uses Microsoft Graph's Contacts.ReadWrite permission to write directory data into each user's own Outlook contacts (see Practical 365's walkthrough of the approach). It stops at the mailbox, though: those contacts only reach the native Contacts app if Outlook's own device sync is also switched on, which is the same partial, duplicate-prone path covered above. In community discussion (for example this Jamf admin forum thread), the answer to "how do I sync the GAL to iPhone" tends to be a dedicated third-party tool rather than a maintained script, precisely because MDM platforms have no built-in way to read the GAL themselves.

How the GAL-to-iPhone workflow works

Diagram showing Microsoft Entra ID contacts imported into a Contactzilla address book and deployed to devices using CardDAV and configuration profiles

1) Connect Contactzilla to Microsoft Entra ID: from the address book you want this data in, Contactzilla authenticates against your tenant over OAuth and reads directory data, nothing is copied into individual mailboxes.

2) Configure the import: point it at your tenant, decide how much of the directory to bring in, and set how often it checks for changes.

3) Map fields and set update rules: Entra attributes map to contact fields, and you decide what's hidden, who's filtered out, and how deletions and duplicates are handled.

4) Deploy to iPhone via MDM: the address book reaches devices as a CardDAV contacts account, appearing in the native Contacts app with caller ID.

What you need before you start

  1. Directory read permissions in Microsoft Entra ID (an admin may need to grant tenant-wide consent for a bulk deployment).
  2. A Contactzilla account with an address book to import into.
  3. An MDM platform for automatic deployment (Intune, Jamf Pro, MaaS360, Workspace ONE or Mosyle), or none if you plan to install the contacts account manually on a small number of devices.
Tip 💡 Whether devices are personally owned or company-owned changes how you'll want to roll this out, and how much end users can be prevented from touching the setup. If that's not already decided, see BYOD vs COPE: choosing the right mobile device policy.

Step 1: Connect Contactzilla to Microsoft Entra ID

From the address book you want this data to land in, for example a dedicated "Staff Directory" address book, choose Import and select Microsoft Entra ID. Contactzilla then walks you through Microsoft's own OAuth consent flow, scoped to read-only directory access, so no credentials are stored outside Microsoft's system. The first time, an Entra admin also grants admin consent directly in Entra (under Enterprise Applications, against the Contactzilla connector), so the connection covers the whole tenant rather than one user at a time.

Contactzilla's Import screen showing Standard Importers (CSV, vCard) and Premium Importers with Microsoft Entra ID selected alongside Google Workspace, SharePoint lists and Odoo.
Microsoft Entra ID sits under Premium Importers, started from inside the address book that will hold the imported contacts.

Step 2: Configure the Entra import

Paste in your Microsoft tenant ID, found on the Entra admin center overview page. If your Entra tenant is already organised into a group that matches who you want, such as a staff or all-employees group, you can scope the import to just that group; otherwise it's usually simpler to bring in everyone and filter out what you don't want at the mapping stage next. Set how often the import checks Entra for changes, from manual up to monthly, manual is worth keeping while you're testing. From here on, this address book, not any individual mailbox, is the shared company contact list every device pulls from.

Contactzilla's Entra ID import sync settings showing the tenant ID field and a sync interval dropdown with Manual, hourly, daily, weekly and monthly options.

Step 3: Map Entra fields and set update behaviour

Entra typically returns far more columns than belong on a phone, so mapping is also where you decide what's actually shown: map name, phone number and department onto Contactzilla's contact fields, and leave anything you don't want visible on the device, such as a home address or job title, unmapped. Crucially, the Entra ID field itself gets mapped to a Hidden Custom Unique field: it never reaches the device, but it's what lets every future sync, on whatever interval you set, recognise the same contact again rather than creating a duplicate.

Contactzilla's field mapping screen with the Entra ID column mapped to Hidden Custom Unique, the setting that lets future syncs recognise the same contact instead of duplicating it.
Mapping Entra ID to Hidden Custom Unique is what lets a repeat sync recognise the same contact instead of duplicating it.

Filters then decide which records reach that address book in the first place. If your tenant has a mix of real people and service or shared-mailbox accounts, a filter can require a mobile number before a record is imported, exclude specific Entra groups, or match on company name for a multi-tenant setup. Deletion handling comes next: disabling someone's Entra account can be set to remove their contact on the next sync, so leavers drop off automatically instead of lingering. Duplicate handling then decides what happens on every other sync, Replace keeps the address book an exact mirror of Entra, while Merge or Skip suit setups where Contactzilla also holds data added by hand, so the list keeps reflecting who has actually joined, moved or left.

Contactzilla's mapping screen showing an active filter that excludes 26 records with no mobile phone number from the import.
A mobile-number filter in action: 26 records without one are excluded from this import.

Step 4: Deploy the address book to iPhone via MDM

Create a device connection for the address book, and the platform generates an iOS configuration profile you can upload directly to your chosen MDM. Set the connection to read-only: end users can't edit or delete what they see on their device, so the address book in Contactzilla stays the one source of truth instead of drifting as people make their own changes on-device.

Contactzilla's device connection setup for iOS, with Access Type set to Full Read Only so contacts can't be edited or deleted on-device.
Setting the device connection to Full Read Only is what stops end users editing or deleting the shared contacts on their phone.

That configuration profile follows Apple's own format for adding a managed contacts account to a device, called a Contacts payload, the same format every MDM builds on, which is why the same profile works whichever platform sits underneath it.

A Contactzilla device connection's menu open on Download Profile, the option that downloads the .mobileconfig file to upload to your MDM.
Download Profile is where the .mobileconfig file for the MDM upload comes from.

On Microsoft Intune, for example, a policy is created and assigned to a device group, the downloaded .mobileconfig file is uploaded directly to that policy, and the contacts appear in the native Contacts app on the next check-in. The same file installs the same way through Jamf Pro, Workspace ONE, MaaS360 or any other MDM, just under that platform's own custom-profile upload screen, see the platform guides below for the exact clicks. Once installed, the shared contact list shows up in the native iOS Contacts app, with automatic updates and caller ID.

Step 5: Verify it worked

On a test device, open Settings > Apps > Contacts > Contacts Accounts and confirm the Contactzilla account is listed. Check that a known contact appears correctly in the Contacts app, then place a test call from that number and confirm the name resolves instead of showing just a number.

iPhone Settings showing the Contacts Accounts list with the CardDAV account listed and its account details, including the dav.contactzilla.app server address.
A successful deployment shows the CardDAV account listed under Settings on the device, with its own server address.
Tip 💡 Contactzilla's CardDAV delivery isn't tied to Intune specifically. If you're on Jamf Pro, Workspace ONE, MaaS360, or no MDM at all, the same managed address book deploys the same way. LINK TBD: sync-gal-without-intune post walks through each of those paths.
Tip 💡 Contactzilla integrates with leading MDM platforms by generating standard iOS configuration profiles for deployment. If you're rolling out contacts at scale, follow the step-by-step setup guides for Microsoft Intune, Mosyle MDM, Jamf Pro or IBM MaaS360.

Can the Global Address List sync to Android too?

Yes. Contactzilla delivers the same shared address book into the native Android Contacts app through its Sync app, with the same read-only or read-write control, and the option to limit a deployment to specific labels or groups. See Android CardDAV setup for teams and shared contacts for the full walkthrough, including the QR-code pairing step the Sync app uses in place of iPhone's built-in CardDAV support.

Android deployment guides

Row of Android phones displaying CardDAV contact sync interface with user profiles

When this approach is the right fit

  • You want your organisation's Entra ID directory, the whole tenant, to be the shared contact list your team's devices use.
  • Contacts need to appear natively on the device for calling, caller ID and messaging, not just as a searchable directory.
  • People join, move roles or leave often enough that a one-off export won't stay accurate.
  • Devices are managed through an MDM, or few enough to set up by hand.

Troubleshooting syncing the GAL to iPhone

Most problems trace back to one of a few places: Entra admin consent, the MDM-deployed profile and its device assignment, or field mapping.

If the import doesn't bring in any contacts: check that an Entra admin has granted admin consent for the Contactzilla connector under Enterprise Applications in the tenant. That consent is a one-off, tenant-wide step, and without it the connection can complete while the import itself has nothing to read.

Entra's Enterprise Applications permissions screen for Contactzilla Entra Import, with Grant admin consent highlighted alongside the Microsoft Graph directory read permissions requested.
Grant admin consent here, in Entra's Enterprise Applications, if imports aren't returning any contacts.

If contacts don't appear after the profile installs: confirm the profile shows as installed under Settings on the device, then check in your MDM that the policy carrying the device connection is actually assigned to the device group containing the affected phones, a correctly built profile can still miss devices sitting in the wrong group. Also check the address book actually contains contacts in Contactzilla, since an empty or still-syncing address book will deploy an empty account.

iPhone Settings showing the Contacts Accounts list with the CardDAV account listed and its account details, including the dav.contactzilla.app server address.
The same on-device check used to confirm a working deployment also rules out a missing or failed profile install.

If contacts appear but caller ID doesn't work: check the phone number is mapped to a phone field, mobile, work, home or custom, on the mapping screen; a number left unmapped or mapped to the wrong field type won't match against an incoming call.

If duplicate contacts show up alongside the GAL: check whether Outlook's own "Save Contacts" setting is also active on the same devices, since it can create a second, separate copy of the same people.

FAQs

Why can't I see the GAL in my iPhone's Contacts app?

No, and this is by design. The GAL is a directory lookup, not a contacts account, so iOS can search it through a linked Exchange or Outlook connection without ever creating entries in the Contacts app. Only contacts stored in a synced contacts account, such as CardDAV, iCloud, or a mailbox's own Contacts folder, appear there.

Does Exchange ActiveSync sync the GAL to iPhone Contacts?

No. ActiveSync syncs a mailbox's own Contacts folder to the device, not the Global Address List itself. If GAL entries need to reach the Contacts app, they first have to be copied into a mailbox or delivered through a separate contacts account.

Will caller ID work when the GAL is synced to iPhone?

Yes, provided the contacts are delivered as real entries in the native Contacts app rather than left as a directory lookup. When a contact is deployed through a CardDAV account or profile via MDM, iOS can match an incoming call's number against it and show the name.

Can Outlook for iOS sync Microsoft 365 contacts to the native Contacts app?

Yes, partially. Enabling Outlook's "Save Contacts" setting can copy mailbox contacts into the iPhone Contacts app, but it doesn't sync the GAL as a managed list, and results vary and can create duplicates in mixed environments.

Can an MDM policy sync the Global Address List to iPhone contacts on its own?

No, not directly. MDM platforms don't read the Microsoft GAL themselves. What they can do is deploy a configuration profile that adds a managed contacts account to the device, and that account will show GAL data only if something has already delivered it into the address book backing that account.

Do I need special permissions to sync the GAL to iPhone?

Yes, in most organisations. Reading Microsoft Entra ID directory data requires directory read permissions, and a bulk deployment usually needs an admin to grant tenant-wide consent during setup. No special permissions are needed on the iPhone itself when the contacts account installs through MDM.

Can the GAL sync to both iPhone and Android at once?

Yes. Once directory contacts are published to a shared address book rather than left as a GAL lookup, both platforms can connect to that same account, an iOS configuration profile on iPhone and a CardDAV client on Android, so updates reach both at once.

Can I control which contacts are imported from the GAL?

Yes. An import can be filtered before it ever reaches a device, for example requiring a mobile number, excluding specific Entra groups such as service accounts and shared mailboxes, or matching on company name. This keeps the address book to real, reachable people rather than every object the directory happens to contain.

Is there an official Microsoft way to sync the GAL to phones?

No. Microsoft's own support engineers state plainly that it is not currently possible to sync the GAL to mobile phones natively, and point to a manual, one-off export from Outlook as the only first-party option. A feature request for native syncing has been open on Microsoft's own feedback portal without a committed timeline.

Next steps

Shared contact list displayed on multiple iPhone devices showing company directory sync across team phones.

Frequently Asked Questions

Is there a native way to sync the Global Address List to iPhone contacts?

No. Microsoft 365 does not natively sync the Global Address List (GAL) into the iPhone Contacts app as device contacts. iPhones sync contacts from a contacts account (such as iCloud, an Exchange mailbox contacts folder, or CardDAV), not directly from the GAL.

How do you sync the Microsoft Global Address List to iPhone contacts?

Sync the Microsoft Global Address List to iPhone contacts by using a contact deployment tool such as Contactzilla. It connects to Microsoft Entra ID via OAuth, imports directory users into a shared address book, then publishes that list to iPhones as a managed CardDAV contacts account deployed through an iOS configuration profile (.mobileconfig) via MDM.

Will caller ID work when syncing the Global Address List to iPhones?

Yes, caller ID can work if the Global Address List is synced onto iPhones as real device contacts in the native Contacts app. Directory lookup alone is not enough. When contacts are deployed as a managed contacts account (for example via CardDAV/profile through MDM), iOS can match incoming calls to those contacts.

Why do I only see the GAL when I search in iOS but it doesn’t show up in Contacts?

Because the Global Address List is a directory lookup, not a contacts account. iOS can search the GAL through an Exchange or Outlook connection, but it does not create contact entries in the Contacts app. Only contacts stored in a synced contacts account (iCloud, Exchange mailbox contacts, or CardDAV) appear there.

Can Outlook for iOS sync Microsoft 365 contacts to the native Contacts app?

Outlook for iOS can copy your mailbox contacts into the iPhone Contacts app if you enable its “Save Contacts” setting. It does not sync the Microsoft 365 Global Address List (GAL) as a managed contact list, and results can vary or create duplicates in mixed setups.

Can I use an MDM policy to sync the Global Address List to iPhone contacts?

Not directly. Most MDMs cannot sync the Microsoft Global Address List (GAL) on their own. What they can do is deploy a managed contacts account to iPhones using an iOS configuration profile (.mobileconfig). If that account is backed by a shared address book, devices will receive the contacts.

Do I need special permissions to sync GAL to my iPhone?

Yes, in most organisations you need directory read permissions in Microsoft Entra ID. If you are deploying contacts at scale, an admin may need to grant tenant-wide consent during OAuth setup. On the iPhone side, no special user permissions are required if the contacts account is installed via MDM.

Is it possible to sync the GAL to both my iPhone and Android device at the same time?

Yes. If you publish your Microsoft directory contacts to a shared address book (rather than relying on GAL lookup), you can connect both iPhone and Android to that same contacts account. iPhone typically uses an iOS profile; Android uses a CardDAV client so updates stay in sync.

Can GAL contacts be used for caller ID purposes on iPhone?

Yes, but only if GAL entries are deployed onto the iPhone as real Contacts app entries. Directory lookup in Outlook or Exchange alone won’t reliably trigger caller ID. Use a synced contacts account (CardDAV or mailbox contacts) so iOS can match incoming numbers.

Ready to supercharge your contact book?

Grow sales and stay organized with better contact management for your team.

No credit card required • 14-day free trial

Contactzilla contact management dashboard on a laptop