This page looks best with JavaScript enabled

Bulk Create Active Directory Users v1.6

For years I’ve had a AD user import VBS script as part of my toolkit, I thought it was about time to update it to PowerShell as well as add a few new features. This utility is available to download from the Microsoft TechNet Gallery and GitHub.

If you’d like to get in touch with me please use the comments, Twitter (you can tweet me and my DMs are open) or my contact form. Please consider donating to support my work:

Thank you!

-Mike

Features and Requirements

This utility will create Active Directory user accounts based on information provided in a CSV file. All other options are added via command line switches.

Options include:

  • Organisation Unit in which to create the users.
  • The UPN that user accounts should have.
  • Home Drive location.
  • Home Drive Letter.
  • Membership of an Active Directory Group.
  • Account Expiry Date.

This utility has been tested running on Windows Server 2016 and Windows Server 2012 R2 Domain Controller’s and on a Windows 10 client. This utility requires the Active Directory PowerShell modules to be installed.

The -file Parameter

When running the script via Schedule Tasks or the command prompt be sure to use the -file parameter before specifying the script, so you can use “double quotes” for the command line switches that need them, if you do not use -file, then you should use ‘single quotes’.

CSV File Formatting

The first line of the CSV file should be the column names so the script (and you) know what each column is for.

The structure of the CSV file is as follows:

1
2
3
Firstname,Lastname,SAM,Password
Joe,Bloggs,jbloggs,P@ssw0rd1
Jane,Bloggs,janeb,P@ssw0rd2

Generating A Password File

The password used for SMTP server authentication must be in an encrypted text file. To generate the password file, run the following command in PowerShell, on the computer that is going to run the script and logged in with the user that will be running the script. When you run the command you will be prompted for a username and password. Enter the username and password you want to use to authenticate to your SMTP server.

Please note: This is only required if you need to authenticate to the SMTP server when send the log via e-mail.

1
2
$creds = Get-Credential
$creds.Password | ConvertFrom-SecureString | Set-Content c:\scripts\ps-script-pwd.txt

After running the commands, you will have a text file containing the encrypted password. When configuring the -Pwd switch enter the path and file name of this file.

Configuration

Here’s a list of all the command line switches and example configurations.

1
-csv

The path and filename of the csv file containing the user information to create users from.

1
-ou

The Organisational Unit to create the users in.

1
-upn

The Universal Principal Name the users should be configured with.

1
-HomeLetter

The drive letter to use for the home drive path.

1
-HomePath

The path where the location of the home drive should reside.

1
-Group

The DN of a group that all the new users should be made a member of.

1
-Expire

The expiry date of the new users.

1
-L

The path to output the log file to. The file name will be AD-Account-Creation-YYYY-MM-dd-HH-mm-ss.log

1
-Subject

The email subject that the email should have. Encapulate with single or double quotes.

1
-SendTo

The e-mail address the log should be sent to.

1
-From

The from address the log should be sent from.

1
-Smtp

The DNS or IP address of the SMTP server.

1
-User

The user account to connect to the SMTP server.

1
-Pwd

The password for the user account.

1
-UseSsl

Connect to the SMTP server using SSL.

Example

1
Create-Accounts-CSV.ps1 -Csv C:\foo\users.csv -Ou 'ou=Imported_Accounts,ou=MyUsers,dc=contoso,dc=com' -HomeLetter W: -HomePath \\filesrvr01\UserHomes -Group 'cn=All_Users,ou=Groups_Security,dc=contoso,dc=com' -Expire 31/07/2022 -Upn contoso.com -L C:\scripts\logs -Subject 'Server: Created AD Accounts' -SendTo me@contoso.com -From AD-Account-Creation@contoso.com -Mail exch01.contoso.com

This will take information from the users.csv file and create the users in the Imported_Accounts OU. The users home drive will be mapped to W: and be located under \filesrvr01\UserHomes. The users will be a member of the All_Users AD group, will expire 31/07/2022 and will have the UPN of contoso.com. The log will be output to C:\scripts\logs and e-mailed with a custom subject line.

Change Log

2019-09-04 v1.6

  • Added custom subject line for e-mail.

2017-10-16 v1.5

  • Changed SMTP authentication to require an encrypted password file.
  • Added instructions on how to generate an encrypted password file.

2017-10-07 v1.4

  • Added necessary information to add the script to the PowerShell Gallery.

2017-09-13 v1.3

  • Added check for existence of user before attempting to create user.
  • Improved logging to handle the above change.

2017-07-22 v1.2

  • Improved code commenting for documentation purposes.
  • Added authentication and SSL options for e-mail notification.
Share on
Support the author with