Sets a new password for one account and, by default, forces a change at the next logon. Leaving the password parameter empty makes the script take the value handed over by the previous runbook step, so chaining it after the random password generator gives you a reset that never puts a password in a script file.
powershell
# Reset an AD User Password
# Single use case: set a new password and force change at next logon
# Tip: chain after 00-GENERATE-RandomPassword.ps1 in a runbook ($store)
#-----------------------------------------------------------------
function Write-Log {
param($Message)
Write-Host "<WRITE-LOG = `"*$Message*`">"
}
# --- Parameters (replace via ServerEngine API parameters if needed) ---
$SamAccountName = "j.doe"
$NewPassword = "" # leave empty to use $store from a previous runbook script
$ForceChange = $true # user must change password at next logon
if ([string]::IsNullOrWhiteSpace($NewPassword)) { $NewPassword = "$store" }
if ([string]::IsNullOrWhiteSpace($NewPassword)) {
Write-Log "No password provided (parameter empty and nothing in `$store)!"
return
}
if (-not (Get-Module -ListAvailable -Name ActiveDirectory)) {
Write-Log "ActiveDirectory module not available on this host!"
return
}
Import-Module ActiveDirectory
$user = Get-ADUser -Filter "SamAccountName -eq '$SamAccountName'" -ErrorAction SilentlyContinue
if ($null -eq $user) {
Write-Log "User not found: $SamAccountName"
return
}
$secure = ConvertTo-SecureString $NewPassword -AsPlainText -Force
Set-ADAccountPassword -Identity $user.DistinguishedName -NewPassword $secure -Reset
if ($ForceChange) {
Set-ADUser -Identity $user.DistinguishedName -ChangePasswordAtLogon $true
Write-Log "Password reset for $SamAccountName - change enforced at next logon."
} else {
Write-Log "Password reset for $SamAccountName."
}Run it across your fleet
This script runs as-is on a single host. Paste it into ServerEngine to schedule it, run it on a whole server group in parallel, and keep the credentials out of the file — see the scripts documentation and the credential store.
More in Active Directory
Active Directory User Onboarding with PowerShell
2026-08-17Active Directory User Offboarding with PowerShell
2026-08-17Disable an Active Directory User with PowerShell
2026-08-17Enable an Active Directory User with PowerShell
2026-08-17Unlock an Active Directory Account with PowerShell
2026-08-17Move AD Users to an OU by Department with PowerShell
2026-08-17Ready when you are.
Try ServerEngine free for 7 days.