That's a tough one, as many organizations have privacy and security issues
around the ability to 'fish' into a directory. We only allow a user to be
added if someone knows the correct directory account name, we don't allow
you to enter in their email address and have the lookup bring back their AD
account.
In our organization we have two separate directories one for internal
employees and one for external partners that seperation works very well for
us.