I need to add a new email address format as an alias for several hundred Active Directory users. Legacy addresses use the first initial followed by the surname, such as [email protected]. Newer accounts use [email protected]. I'm looking for a safe PowerShell approach that can identify the relevant users, generate the firstname.lastname alias, add it to the proxyAddresses attribute, and provide a way to validate the changes. The examples here are fictional; the actual domains and user data are different.
4 Answers
If you already have a list of accounts, importing a CSV can make the operation more controlled:
$legacyUsers = Import-Csv 'C:legacyUsers.csv'
foreach ($account in $legacyUsers) {
$adUser = Get-ADUser $account.SamAccountName -Properties GivenName,Surname,proxyAddresses
$alias = "smtp:$($adUser.GivenName).$($adUser.Surname)@domain2.co.uk"
if ($adUser.proxyAddresses -notcontains $alias) {
Set-ADUser $adUser -Add @{proxyAddresses=$alias}
}
}
Before running this broadly, export the current proxyAddresses values, test with a small group, and check for duplicate aliases, missing names, and accounts that already have the desired address. If the alias needs to become primary, that is a separate change because the existing uppercase `SMTP:` entry must be replaced carefully.
For a basic single-user example, you can read the first name and surname, build the alias, and add it to proxyAddresses:
Get-ADUser jdoe -Properties GivenName,Surname | ForEach-Object {
$alias = "smtp:$($_.GivenName).$($_.Surname)@domain2.co.uk"
Set-ADUser $_ -Add @{proxyAddresses=$alias}
}
Use lowercase `smtp:` for a secondary alias. The uppercase `SMTP:` prefix is normally reserved for the primary address, so don’t use it unless you intend to change the primary email address.
Avoid putting real employee data or directory exports into an external AI service. A safer approach is to work from a controlled CSV or directly query the directory, then use PowerShell string manipulation to construct the alias. You can also split an existing email address at the `@` symbol if that better matches your naming rules, but validate the generated values before writing them back to Active Directory.
Break the task into smaller steps: retrieve the users with Get-ADUser or the appropriate mailbox cmdlet, filter the accounts you actually want to change, loop through them, update the proxyAddresses attribute, and then validate the results. It’s best to get the command working against one test account first before scaling it to the whole directory.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures