-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathnewuser.ps1
More file actions
81 lines (71 loc) · 2.81 KB
/
Copy pathnewuser.ps1
File metadata and controls
81 lines (71 loc) · 2.81 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
#requires -Module ActiveDirectory
[CmdletBinding(ConfirmImpact = 'High', SupportsShouldProcess)]
param (
[Parameter(Mandatory)]
[ValidateNotNullOrEmpty()]
[string]$FirstName,
[Parameter(Mandatory)]
[ValidateNotNullOrEmpty()]
[string]$LastName,
[Parameter(Mandatory)]
[ValidateNotNullOrEmpty()]
[string]$Department,
[Parameter(Mandatory)]
[ValidateNotNullOrEmpty()]
[int]$EmployeeNumber
)
try {
## First attempt to create a username with first initial/last name
$userName = '{0}{1}' -f $FirstName.Substring(0, 1), $LastName
## Use a while loop to check for different variations of the username if the original is already taken
## In this case, if first initial/last name is taken, try first second initials/last name, third initials, etc
## until a unique username is found.
$i = 2
while ((Get-AdUser -Filter "samAccountName -eq '$userName'") -and ($userName -notlike "$FirstName*")) {
Write-Warning -Message "The username [$($userName)] already exists. Trying another..."
$userName = '{0}{1}' -f $FirstName.Substring(0, $i), $LastName
Start-Sleep -Seconds 1
$i++
}
## Ensure we didn't exhaust all username options
if ($userName -like "$FirstName*") {
throw 'No available username could be found'
} elseif (-not ($ou = Get-ADOrganizationalUnit -Filter "Name -eq '$Department'")) {
## Check to see if the OU with the name of the department exists
throw "The Active Directory OU for department [$($Department)] could not be found."
} elseif (-not (Get-AdGroup -Filter "Name -eq '$Department'")) {
throw "The group [$($Department)] does not exist."
} else {
## Create a random password
Add-Type -AssemblyName 'System.Web'
$password = [System.Web.Security.Membership]::GeneratePassword((Get-Random -Minimum 20 -Maximum 32), 3)
$secPw = ConvertTo-SecureString -String $password -AsPlainText -Force
$newUserParams = @{
GivenName = $FirstName
EmployeeNumber = $EmployeeNumber
Surname = $LastName
Name = $userName
AccountPassword = $secPw
ChangePasswordAtLogon = $true
Enabled = $true
Department = $Department
Path = $ou.DistinguishedName
Confirm = $false
}
if ($PSCmdlet.ShouldProcess("AD user [$userName]", "Create AD user $FirstName $LastName")) {
## Create the user
New-AdUser @newUserParams
## Add the user to the department group
Add-AdGroupMember -Identity $Department -Members $userName
[pscustomobject]@{
FirstName = $FirstName
LastName = $LastName
EmployeeNumber = $EmployeeNumber
Department = $Department
Password = [System.Runtime.InteropServices.marshal]::PtrToStringAuto([System.Runtime.InteropServices.marshal]::SecureStringToBSTR($secPw))
}
}
}
} catch {
Write-Error -Message $_.Exception.Message
}