I started learning programming with no prior experience, and after three months of consistent practice, PowerShell and Microsoft Graph are finally beginning to make sense. I recently wrote a function that creates a user in Microsoft Entra ID and tried to apply practices such as parameter validation, splatting, CmdletBinding, verbose messages, custom objects, and try/catch error handling.
The function accepts a display name, user principal name, mail nickname, and account-enabled setting. It generates a temporary password, creates the user, and returns a summary object containing the new user's details. I would appreciate feedback on the code, including any technical issues, security concerns, or design improvements. What should I focus on learning next?
3 Answers
Using functions is a good habit because it keeps automation structured and readable. As scripts grow, that organization becomes much more valuable. The next step is making the function self-documenting with comment-based help and clear parameter behavior.
Functions are useful, although I still prefer to inspect the implementation when I encounter one because the name alone does not always explain what it does.
This is a solid start, especially for only a few months of learning. A few improvements would make the function more idiomatic and easier to maintain. Consider making AccountEnabled a switch parameter when you want to distinguish between a supplied and omitted option. You can also use format strings or subexpressions instead of concatenating the temporary password. Since New-MgUser returns the created user object, use its verified properties when building your output rather than repeating input values. Add comment-based help so users can discover the function with Get-Help. Also, the function call at the bottom should use normal named parameters rather than backtick line continuations, since those can become fragile. Double-check the Microsoft Graph command syntax as well; the configuration has to be passed with the correct parameter name.
The password generation approach is not cryptographically strong enough for production use. Get-Random is intended for general randomness, not secure credential generation. Use a cryptographically secure generator or let the identity platform create or manage the temporary credential when possible. Temporary passwords should also be handled carefully and never unnecessarily written to logs or shared output.
That’s helpful to know. I’ll look into secure password generation and safer ways to handle temporary credentials.

Thanks! I’m trying to build good habits early so I don’t have to untangle everything once my automation scripts become much larger.