Creates a fully populated AD account — name, UPN, mail, department, office, address and target OU — and then adds it to the security groups that belong to each role in a comma separated role list. The x-prefixed values are ServerEngine parameter placeholders that get filled in per run, so the same script serves the whole joiner process. The role blocks at the bottom are the part you adapt to your own group naming.
powershell
# Active Directory: User Onboarding
#-------------------------------------------
Import-Module ActiveDirectory
# Enable detailed debugging
$VerbosePreference = "Continue"
$ErrorActionPreference = "Stop"
Write-Host "Converting password to SecureString"
$SecurePassword = ConvertTo-SecureString 'xAccountPassword' -AsPlainText -Force
# Create new AD User
Write-Host "Creating New-ADUser..."
try {
New-ADUser `
-Name 'xName' `
-GivenName 'xGivenName' `
-Surname 'xSurname' `
-DisplayName 'xDisplayName' `
-SamAccountName 'xSamAccountName' `
-UserPrincipalName 'xUserPrincipalName' `
-EmailAddress 'xEmailAddress' `
-Description 'xDescription' `
-Department 'xDepartment' `
-Office 'xOffice' `
-Company 'xCompany' `
-Title 'xTitle' `
-OfficePhone 'xPhone' `
-StreetAddress 'xStreetAddress' `
-City 'xCity' `
-PostalCode 'xPostalCode' `
-State 'xState' `
-Country 'xCountry' `
-Path 'xPath' `
-AccountPassword $SecurePassword `
-Enabled $true `
-Verbose
$roleList = 'xGroups'
$roles = $roleList -split ','
foreach ($role in $roles) {
# Trim leading/trailing whitespace from role
$role = $role.Trim()
if ($role -like 'Finance') {
try {
Add-ADGroupMember -Identity 'SG-FIN-Accountants' -Members 'xSamAccountName' -Verbose
Add-ADGroupMember -Identity 'SG-FIN-AP-Team (Accounts Payable)' -Members 'xSamAccountName' -Verbose
Add-ADGroupMember -Identity 'SG-FIN-AR-Team (Accounts Receivable)' -Members 'xSamAccountName' -Verbose
Add-ADGroupMember -Identity 'SG-FIN-Payroll-Processors' -Members 'xSamAccountName' -Verbose
Add-ADGroupMember -Identity 'SG-FIN-Financial-Analysts' -Members 'xSamAccountName' -Verbose
Add-ADGroupMember -Identity 'SG-FIN-Budget-Managers' -Members 'xSamAccountName' -Verbose
}
catch {
Write-Host "<WRITE-LOG = ""*Failed to assign user to role $role*"">"
}
}
if ($role -like 'HR') {
try {
Add-ADGroupMember -Identity 'SG-HR-Users' -Members 'xSamAccountName' -Verbose
Add-ADGroupMember -Identity 'SG-HR-HRIS' -Members 'xSamAccountName' -Verbose
Add-ADGroupMember -Identity 'SG-HR-Personnel-Files' -Members 'xSamAccountName' -Verbose
}
catch {
Write-Host "<WRITE-LOG = ""*Failed to assign user to role $role*"">"
}
}
# Define more assignments here...
}
Write-Host "<WRITE-LOG = ""*User Onboarding completed!*"">"
Write-Host "<WRITE-LOG = ""*User created: xName*"">"
Write-Host "<WRITE-LOG = ""*Email: xUserPrincipalName*"">"
Write-Host "<WRITE-LOG = ""*Login: xSamAccountName*"">"
Write-Host "<WRITE-LOG = ""*Password: xAccountPassword*"">"
}
catch {
Write-Error "AD User creation failed: $($_.Exception.Message)"
}Run it across your fleet
This script runs as-is on a single host. Paste it into ServerEngine to schedule it, run it on a whole server group in parallel, and keep the credentials out of the file — see the scripts documentation and the credential store.
More in Active Directory
Active Directory User Offboarding with PowerShell
2026-08-17Disable an Active Directory User with PowerShell
2026-08-17Enable an Active Directory User with PowerShell
2026-08-17Unlock an Active Directory Account with PowerShell
2026-08-17Reset an Active Directory Password with PowerShell
2026-08-17Move AD Users to an OU by Department with PowerShell
2026-08-17Ready when you are.
Try ServerEngine free for 7 days.