A day light, and slightly different from above, but without importing the details from a CSV file. Ripped from my script used to create and reset generic visitor accounts so I've not fully test the code (I had to anonymize and add the group / workstation parts). You will be prompted to enter and then confirm the password.
You might need to adjust the userPrincipalNameSuffix if your internal domain is different from your external / email domain
If you don't need to create a network home folder (probably not with 1:1 computers), remove or comment out the home folder and home drive lines.
Remember to test first.
import-module ActiveDirectory
$first = 0
$last = 0
$accountPrefix = ""
$logonWorkStationsPrefix = ""
$cannotChangePassword = $False
$ADPath = 'OU=path,OU=to,OU=Users,OU=ou,DC=example,DC=com'
$emailSuffix = 'example.com'
$userPrincipalNameSuffix = $emailSuffix
$driveLetter = 'N'
$ADGroupName = 'AD_Group'
$users = @()
##### Add the accounts to the $users list. If the account doesn't exist, create it#####
##### Add or remove the 0s on the the toString line to adjust the leading 0s####
foreach ($number in $($first)..$($last)) {
$number = $number.toString("00")
$user = "$accountPrefix-$number"
$userPrincipalName = "$user@$emailSuffix"
try {
$users += Get-ADUser -Identity $user -ErrorAction Stop
}
catch {
$userDetails = @{
DisplayName = $user
GivenName = $accountPrefix
Name = $user
userPrincipalName = $userPrincipalName
Surname = $number
SamAccountName = $user
Path = $ADPath
EmailAddress = "$user@$userPrincipalNameSuffix"
LogonWorkstations = "$logonWorkStationsPrefix$number"
}
New-ADUser @userDetails
$ADUser = Get-ADUser -Identity $user
Add-ADGroupMember -Identity $ADGroupName -Members $ADUser
#### Optional
#Sets their home directory
Get-ADUser -Identity $user -Properties HomeDirectory | Set-ADObject -replace @{HomeDirectory="\\Server\Share$\Folder\$($user.Name)\Homefolder"}
Get-ADUser -Identity $user -Properties HomeDrive | Set-ADObject -replace @{HomeDrive="$driveLetter`:"}
#### end optional
$users += Get-ADUser -Identity $user
}
}
##### Get password to set the initial password of the accounts
do {
$Password = Read-Host "Password" -AsSecureString
$Compare = Read-Host "Re-enter Password" -AsSecureString
}##### Compare the two entries. The backtick ` allows the comparison to be on 2 lines, the -cne makes it case sensitive ######
while ([Runtime.InteropServices.Marshal]::PtrToStringAuto([Runtime.InteropServices.Marshal]::SecureStringToBSTR($Password))`
-cne [Runtime.InteropServices.Marshal]::PtrToStringAuto([Runtime.InteropServices.Marshal]::SecureStringToBSTR($Compare)))
$Compare = $null
#####Set Password and optionally set Cannot change own password, and password expiry
foreach($user in $users){
Get-ADUser $user | Set-ADAccountPassword -NewPassword $Password -Reset
$passwordDetails = @{
ChangePasswordAtLogon = !$cannotChangePassword
CannotChangePassword = $cannotChangePassword
PasswordNeverExpires = $cannotChangePassword
}
Get-ADUser $user | Set-ADUser @passwordDetails
}
#######Enable the accounts
foreach($user in $users){
Enable-ADAccount $user
}