I need to update several hundred Active Directory users by adding a secondary email alias. Legacy addresses use the first initial plus surname format, such as [email protected], while newer accounts use [email protected]. I'd like a PowerShell script that can identify the users, build the new alias from their first name and surname, and add it to each account without replacing the existing address. The examples use fictional names and domains. I'd also like to know how to validate the changes safely before running the update across everyone.
4 Answers
If you already have a list of accounts, import it from CSV and process each one. Include checks so you don’t add duplicates or overwrite existing values:
$legacyUsers = Import-Csv 'C:legacyUsers.csv'
foreach ($account in $legacyUsers) {
$user = Get-ADUser -Identity $account.SamAccountName -Properties GivenName,Surname,proxyAddresses
$alias = "smtp:$($user.GivenName).$($user.Surname)@domain2.co.uk"
if ($user.proxyAddresses -notcontains $alias) {
Set-ADUser -Identity $user -Add @{proxyAddresses=$alias}
Write-Host "Added $alias to $($user.SamAccountName)"
}
}
Test it on a small group first, and consider using `-WhatIf` where supported or replacing the update with output to a CSV so you can review the proposed changes.
For a single account, you can construct the alias from the first name and surname and add it as a lowercase secondary address. For example:
$adUser = Get-ADUser -Identity 'jdoe' -Properties GivenName,Surname,proxyAddresses
$alias = "smtp:$($adUser.GivenName).$($adUser.Surname)@domain2.co.uk"
Set-ADUser -Identity $adUser -Add @{proxyAddresses=$alias}
The lowercase `smtp:` prefix marks it as a secondary alias. An uppercase `SMTP:` prefix is used for the primary address, so don’t use that unless you intentionally want to change the primary address.
Be careful about relying on an AI tool with real directory data or personally identifiable information. The script should be designed around your environment, and you should test against representative but non-sensitive accounts. Also account for edge cases such as missing surnames, hyphens, apostrophes, duplicate aliases, and users who already have a different address. A preview report and post-update validation are important before modifying hundreds of accounts.
Break the task into smaller steps: retrieve the users with Get-ADUser, select or filter the accounts you want to change, loop through them with foreach, update proxyAddresses with Set-ADUser, and then verify the results. It’s best to make the command work for one test account first, run it in report or preview mode, and only then scale it up.

Related Questions
How To: Running Codex CLI on Windows with Azure OpenAI
Set Wordpress Featured Image Using Javascript
How To Fix PHP Random Being The Same
Why no WebP Support with Wordpress
Replace Wordpress Cron With Linux Cron
Customize Yoast Canonical URL Programmatically