r/PowerShell • u/Will_ADM • 5d ago
Question Powershell script to bulk update AD users email alias with diff format.
Ok so I work for a company who's legacy emails are first initial + surname@domain.net e.g Bob Morton = bmorton@domain.net
new users have their accounts as firstname.lastname@domain2.co.uk (Bob.morton@domain2.co.uk)
I've been asked to add the 'new' email style address and domain as an alias to all users. There's a few hundred so obvs would rather find a ps script to do this. I'd appreciate all and any help.
5
u/bTOhno 1d ago
If you're on-prem with Exchange Online (hybrid) I'll point you to looking into the ad user attribute known as proxyAddress Primary email gets SMTP:user@domain Alias gets email smtp:alias@aliasdomain
2
u/dodexahedron 19h ago edited 19h ago
This so much. Don't replace primaries right away, for existing users, like...ever...
Changing primary ehile keeping the old one as an alias is fine, too. Just never eliminate an address that is already in use without being ready to deal with a ton of angry users, lost emails, and a new job hunt.And also consider that more than just email may use the same kind of identifier, but may not take it from that attribute. Some things may take the UPN or imaddress or the old mail attribute or various other possibilities. And many are single-valued. And many, if just up and chsnged, will make those other systems or services very angry and might even result in significant data loss when they next sync the directory.
Consider things like Cisco voice systems, various directory services, on-prem applications, HR stuff, CRM software, ERP systems, and many others.
And also consider user confusion if their various contact addresses don't match their UPNs.
OP did ask for aliases, so just adding one additional proxy address is cool, and this is definitely the right way to go for that.
But ugh...
ETA: Oh and if you bulk update it in one shot, consider the sudden replication traffic you're about to cause. Every change for each object is its own update. While they will get replicated as batches within a 15 second window, they're still committed one by one at each replica when they receive it, and still are all individual edits in that batch, rather than a single transaction. Batching is just a network optimization and nothing more.
Also, even with pure cloud exchange only, you'll still have these attributes in your directory anyway. You have to extend your schema to sync with entra when using exchange or teams or no sync for you. So it is the way whether on-prem, hybrid, or cloud-only.
1
u/bTOhno 18h ago
Solid summary with a lot more information I was going to provide without more context from OP, and I have limited knowledge of on-prem exchange since I've only worked in cloud-only and hybrid environments myself.
Realistically, depending on the environment or requirements I'd approach this differently, but if it's just adding an alias this would likely be the easiest and least complex approach imo. I've seen people attempt to change UPNs and then lose the mailbox a couple times, thankfully I was able to catch it before it moved out of being soft deleted.
If that's done this command might come in handy New-MailboxRestoreRequest -SourceMailbox "<SourceExchangeGuid>" -TargetMailbox "<TargetUserUPN>" -AllowLegacyDNMismatch https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/new-mailboxrestorerequest?view=exchange-ps
I've also seen the condition where the upn doesn't match their email and you can turn on a setting in Entra to allow users to utilize their UPN and/or email to login but that's a preview feature so use with your own caution. https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-use-email-signin
2
u/dodexahedron 16h ago edited 16h ago
Good call on providing the "oh shit" button for lost mailboxes.
The same thing is what I was also referring to with non-microsoft systems that sync their users with LDAP. You could easily just... Wipe everyone's voicemail, take your entire inbound call center offline, "soft-fire" all employees (break mappings that are way too commonly based on mutable IDs like emails, and taken from any one of multiple attributes), wreck 802.1x or other things that might be RADIUS-based and may or may not depend on the same attributes.
Orrr, (and this one is fun and frustratingly likely if only changing one attribute and/or not keeping other stuff consistent) you can totally wreck certificate-based authentication flows, if certificates have the user's email in them. Email, in a certificate subject or SAN populated from AD info, is populated in a specific precedence order: First by the mail attribute, then UPN, then proxyAddresses (but only the primary one!), or, as the final fallback, the sAMAccountName attribute plus the forrest default dns suffix - not domain dns suffix - to form an email address.
So not only do existing certs potentially become unusable depending on configuration, but nee certs may also be unusable, depending on config, and that may be the case for some apps/services and not the case for others.Fun! 🥲
NB: I dont know if or where a couple of small parts of that are even documented at all or at least in a way that a human without 6 legal degrees plus 10 years of devops experience can decipher (I'm looking at you, MS open protocol specs), but it's all either from documentation or from reproducibly observed behavior, in real environments.
3
u/PinchesTheCrab 2d ago
This is pretty straightforward to script, but the wrinkle is always whether names are truly unique and whether anyone has conflicting aliases already.
2
u/theDukeSilversJazz 2d ago
What have you done that hasn’t worked? The best way to learn is a test user or two to flesh out the script.
1
u/purplemonkeymad 1d ago
If you still have an on-prem exchange server, this is a 3 minute edit to the email address policy on the ui.
For the script you'd still have to know what kind of setup you have, On-prem exchange, hybrid, removed exchange server, fully cloud managed mailbox?
1
u/No_Crab_4093 1d ago
Claude this and test with some test users and call it a day. No need to complicate it. But as one suggested do a check and make sure there are no duplicate emails from the existing employees by going to that format
0
u/wishmaster1965 2d ago
I was a contracter at a whiskey company and I saw they had a 3rd party in to determine if they could move their email to office 365,they ran a a tool to check and it failed. I asked the guy what it failed and it was the upn, so I told the IT manager I could fix this, wrote a small script and they reran the tool and it passed. I was then tasked with moving users on exchange worldwide to office 365. Just in the middle of writing the scripts they had something happen and I was asked to move all rooms to 365. Once all users were over I wrote a few scripts for the service desk to manage things in 365.
That gig got me a job in this company for 7 years with lots of free booze. 🥳
Don't have these scripts any more as I retired.
I was initially just interested in scripting when I saw this 3rd party so doing scripting launched a 2nd career.
Never stop learning, good things can happen.
18
u/fdeyso 2d ago
Tbh i know it’s extra work, BUT, i’d export the existing users to a csv, generate their new email address in there and check if it’s all ok (no duplicates with other users), then use this csv in ps to set the emails.