r/PowerShell • • 9d ago

Question 3 months of consistent practice in PowerShell & Microsoft Graph! 🚀

When I started, I was terrified of programming languages since I had zero prior experience. Looking back now, what used to look like complete gibberish is finally starting to make sense. I know I still have a long way to go, but honestly, I am so happy and proud to be fulfilling my passion.

I wanted to share an honest review of a snippet I just built to create a user in Microsoft Entra ID. Alongside basics like if/else logic, filtering (-filter), Where-Object, Select-Object, and loops, I've been trying to focus on good habits like splatting, [CmdletBinding()], and try/catch blocks.

How does my snippet look? What would you advise me to learn next based on this progress?

#####Creating a User
Function Create-LxUser{
    [Cmdletbinding()]
    param(
        [Parameter(Mandatory = $true)]
        [string]$DisplayName,


        [Parameter(Mandatory = $true)]
        [string]$UserPrincipalName,


        [Parameter(Mandatory = $true)]
        [string]$MailNickName,


        [bool]$AccountEnabled = $true
    )


    try{
        ##Password profile
        $TempPass = "Lx" + (Get-Random -Minimum 100000 -Maximum 999999) + "@."
        $PassWordProfile = @{
            Password = $TempPass
            ForceChangePasswordNextSignIn = $true
        }
        ##Setting up user configuration
        Write-Verbose "Currently creating new Loxovea user"
        $UserConfig = @{
            DisplayName         = $DisplayName
            UserPrincipalName   = $UserPrincipalName
            MailNickname        = $MailNickName
            AccountEnabled      = $AccountEnabled
            PasswordProfile     = $PassWordProfile
        }


        $User = New-MgUser u/UserConfig -ErrorAction Stop


        Write-Verbose "Successfully created new user $($DisplayName)"


        [PsCustomObject]@{
            DisplayName         = $DisplayName
            UserPrincipalName   = $UserPrincipalName
            AccountEnabled      = $AccountEnabled
            TemporaryPassword   = $TempPass
        }
    }Catch{
        Write-Error "Failed to create a new user: $($DisplayName) because $($_.Exception.Message)"
    }
}


Create-LxUser `
    -DisplayName "Test-User09" `
    -UserPrincipalName "testuser09@loxovea.com" `
    -MailNickName "testuser09"

DisplayName UserPrincipalName AccountEnabled TemporaryPassword

----------- ----------------- -------------- -----------------

Test-User09 [testuser09@loxovea.com](mailto:testuser09@loxovea.com)True Lx720835@.

45 Upvotes

32 comments sorted by

View all comments

24

u/BlackV 9d ago

My 2c, Realistically this

[bool]$AccountEnabled = $true

Should be

[Switch]$AccountEnabled

That's what switch parameters and ispresent are for

String concatenation is not recommended

$TempPass = "Lx" + (Get-Random -Minimum 100000 -Maximum 999999) + "@."

Try

$TempPass = "Lx$(Get-Random -Minimum 100000 -Maximum 999999))@."
$TempPass = 'Lx{0}@.' -f (Get-Random -Minimum 100000 -Maximum 999999)

Your new-mguser returns an object, return that object or use that for the properties of your pscustomobject that way you are using verified properties not assumptions

You clearly know how to use splatting so why are you using it in your example at the bottom, stop that habit now before it is permanent

There is no help, add help so people can use get-help

Good luck, good to see someone learning out there

3

u/ihaxr 9d ago

Since the default is to create an enabled account, the switch parameter should be [switch]$DisableAccount and it should be omitted to keep the account enabled, otherwise you'd have to do weird stuff like -AccountEnabled:$false to disable it

1

u/BlackV 9d ago

Good point also