Home > Support Articles > Global Address List (GAL) Sync > How to Set Impersonation Mode for GAL or Public Folder Sync to User Mailboxes

There are two ways that permissions can be given to a service account for GAL or Public Folder sync to user mailboxes:

  • The IT Admin can delegate user permissions to their service accounts.
  • The IT Admin can also set impersonation mode on their service account.

This guide shows how to set up impersonation mode on a service account.

NOTE: More information on Application Impersonation and service account permissions can be found here: Exchange Service Account Permissions and itrezzo Contact Management.



  1. Launch the Office 365 Admin Portal.
  2. Click Admin centers > Exchange to display the Admin Exchange Center dialog box. (See figure below.)
  3. Click permissions in the navigation panel.  
  4. Click + to add a new role group and name the group in admin roles. In this example, the new group is named App Impersonation.
  5. Click + under Roles, and add the Application Impersonation Role.
  6. Click + under Members, and add the service account of choice.
  7. Click Save. NOTE: It can take 30–40 minutes for the Application Impersonation role to apply on the service account and replicate across Office 365 services. (See figure below.)

More Technical Articles