# Not able create user with employee number

**URL:** <https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360>\
**Category:** PowerShell Help\
**Created:** [August 20, 2021, 11:49am UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360 "2021-08-20T11:49:54Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexxx55555](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@alexxx55555](https://forums.powershell.org/u/alexxx55555)\
**Post date:** [August 20, 2021, 11:49am UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/1 "2021-08-20T11:49:54Z")

</div>

Hi all,  
I have a script that should create a user with an employee number a should check if the employee number is exciting to create a new employee number.  
but this stop is no working for me

```auto
Import-Module ActiveDirectory
Function Test-PasswordForDomain {
    Param (
        [Parameter(Mandatory=$true)][string]$Password,
        [Parameter(Mandatory=$false)][string]$AccountSamAccountName = "",
        [Parameter(Mandatory=$false)][string]$AccountDisplayName,
        [Microsoft.ActiveDirectory.Management.ADEntity]$PasswordPolicy = (Get-ADDefaultDomainPasswordPolicy -ErrorAction SilentlyContinue)
    )

    If ($Password.Length -lt $PasswordPolicy.MinPasswordLength) {
        return $false
    }

   if (($AccountSamAccountName) -and ($Password -match "$AccountSamAccountName")) {
        return $false
    }
   if ($AccountDisplayName) {
    $tokens = $AccountDisplayName.Split(",.-,_ #`t")
    foreach ($token in $tokens) {
        if (($token) -and ($Password -match "$token")) {
            return $false
        }
    }
}
   
   
    return $true   
   
}

function Get-AvailableEmployeeNumber {
param(
    [int]$EmployeeNumber,
    [string[]]$AllNum
)

if($AllNum -contains $EmployeeNumber){
    Get-AvailableEmployeeNumber -EmployeeNumber ($EmployeeNumber + 1) -AllNum $AllNum

}
else{
    $EmployeeNumber
}

}

# Grab Variables from User
$ADPath = "OU=Users,OU=Alex,DC=alex,DC=local"

    

# Grab Variables from User
$firstname = Read-Host -Prompt "Enter First Name"

# Stop by empty first name
while (!($firstname -eq "")){

$lastname = Read-Host -Prompt "Enter Last Name"
 
do {
    try {
        [int]$EmployeeNumber = Read-Host "Enter Employee Number"
    }
    catch [System.Management.Automation.PSInvalidCastException] {
        Write-Warning "You can only use numbers!"
        
    }
}
until (($EmployeeNumber -or $EmployeeNumber -eq 0) -and $EmployeeNumber -match "^[0-9]*$")

if (-not(Get-ADUser -filter "EmployeeNumber -eq '$EmployeeNumber'")) {
    write-output "$EmployeeNumber is available."
}
else {
    Write-Warning "EmployeeNumber '$EmployeeNumber' is already in use."
    $allNum = 
    [Int32[]]($((Get-ADUser -Filter * -Properties EmployeeNumber).EmployeeNumber)) |
    Sort-Object -Descending 

    $newNum = Get-AvailableEmployeeNumber -EmployeeNumber $EmployeeNumber -AllNum $allNum
    Write-Output "The next Available EmployeeNumber is '$newNum'"

}

$password = Read-Host -Prompt "Enter password"

while(!(Test-PasswordForDomain -Password $password)){
    write-host -ForegroundColor Yellow "Password complexity error!!!"
    $password = Read-Host -Prompt "Enter password"

}

# Set username
$i = 1
$username = $firstName + $lastName.Substring(0,$i)
$username = $username.ToLower()
   
while ((Get-ADUser -filter {SamAccountName -eq $username}).SamAccountName -eq $username)
{

        $username = $firstName + $lastName.Substring(0,$i++)
        $username = $username.ToLower()
}

$email = $username + "@alex.local" 
if (Get-ADUser -Filter "surname -eq '$lastname' -and givenname -eq '$firstname'")

{
  
# Create the AD User
New-ADUser `
-Name "$firstname $lastname ($EmployeeNumber)" `
-GivenName $firstname `
-Surname $lastname `
-EmployeeNumber $EmployeeNumber `
-Displayname "$FirstName $lastname" `
-UserPrincipalName $email `
-SamAccountName $username `
-AccountPassword (ConvertTo-SecureString $password -AsPlainText -Force) `
-Path $ADPath `
-Enabled 1   
}
else
{
   # Create the AD User
New-ADUser `
-Name "$firstname $lastname" `
-GivenName $firstname `
-Surname $lastname `
-EmployeeNumber $EmployeeNumber `
-Displayname "$FirstName $lastname" `
-UserPrincipalName $email `
-SamAccountName $username `
-AccountPassword (ConvertTo-SecureString $password -AsPlainText -Force) `
-Path $ADPath `
-Enabled 1   
}

Write-Host -ForegroundColor Green "The user"$username" created successfully."

Remove-Variable -Name 'EmployeeNumber'

$firstname = Read-Host -Prompt "Enter First Name"

}

Write-Host -ForegroundColor Red "Done, Thank You"

```

any idea why is not working?

thank you

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 20, 2021, 12:10pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/2 "2021-08-20T12:10:55Z")

</div>

Alex,

that’s a big chunk of code. Where exactly does it stop? Please don’t make us debugging your complete script. 😉

And BTW: Since you seem to anyway increase the number the user of this script enters if it’s already there why not assigning a new employee number automatically by increasing the last/highest found employee number? That would make your script a little more robust.

---

<div class="post-metadata">

**Author:** ![alexxx55555](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@alexxx55555](https://forums.powershell.org/u/alexxx55555)\
**Post date:** [August 20, 2021, 12:26pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/3 "2021-08-20T12:26:04Z")

</div>

i treid to that but it wasnt working so i use the function

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 20, 2021, 12:30pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/4 "2021-08-20T12:30:53Z")

</div>

Maybe you gave up to easily. 😉 Why don’t we try to make this working?

---

<div class="post-metadata">

**Author:** ![alexxx55555](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@alexxx55555](https://forums.powershell.org/u/alexxx55555)\
**Post date:** [August 20, 2021, 2:57pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/5 "2021-08-20T14:57:41Z")

</div>

i thouth this is helping forum  
so i thouth that maybe someone will hlep me  
but i see that you the only one whos here an you not willing to help  
so i will look for some other help

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 20, 2021, 3:02pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/6 "2021-08-20T15:02:08Z")

</div>

> [@alexxx55555](#):
>
> but i see that you the only one whos here an you not willing to help

I just offered to help you!?!?

---

<div class="post-metadata">

**Author:** ![alexxx55555](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@alexxx55555](https://forums.powershell.org/u/alexxx55555)\
**Post date:** [August 20, 2021, 3:21pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/7 "2021-08-20T15:21:26Z")

</div>

> [@alexxx55555](#):
>
> but i see that you the only one whos here an you not willing to help

not feeling like if ,  
if I knew what to do I wasn’t asking questions in this post

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 20, 2021, 3:26pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/8 "2021-08-20T15:26:17Z")

</div>

> [@alexxx55555](#):
>
> if I knew what to do I wasn’t asking questions in this post

Of course. But you have to be willing to help us helping you as well. So either you tell us where exactly your code is not working as expected or you post the approach you coulnd’t complete and we could try to make it work.

---

<div class="post-metadata">

**Author:** ![alexxx55555](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@alexxx55555](https://forums.powershell.org/u/alexxx55555)\
**Post date:** [August 20, 2021, 4:11pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/9 "2021-08-20T16:11:37Z")

</div>

> [@alexxx55555](#):
>
> ```auto
> function Get-AvailableEmployeeNumber {
> param(
> [int]$EmployeeNumber,
> [string[]]$AllNum
> )
> 
> if($AllNum -contains $EmployeeNumber){
> Get-AvailableEmployeeNumber -EmployeeNumber ($EmployeeNumber + 1) -AllNum $AllNum
> 
> }
> else{
> $EmployeeNumber
> }
> 
> }
> 
> ```

ok i have this function

```auto
function Get-AvailableEmployeeNumber {
param(
    [int]$EmployeeNumber,
    [string[]]$AllNum
)

if($AllNum -contains $EmployeeNumber){
    Get-AvailableEmployeeNumber -EmployeeNumber ($EmployeeNumber + 1) -AllNum $AllNum

}
else{
    $EmployeeNumber
}

}

```

its chekcs if employee number exsite or not  
and if yes its give message next free number is 5

but in my script its not create the employee with free employee number  
this the script to create new user

```auto
New-ADUser `
-Name "$firstname $lastname ($EmployeeNumber)" `
-GivenName $firstname `
-Surname $lastname `
-EmployeeNumber $EmployeeNumber `
-Displayname "$FirstName $lastname" `
-UserPrincipalName $email `
-SamAccountName $username `
-AccountPassword (ConvertTo-SecureString $password -AsPlainText -Force) `
-Path $ADPath `
-Enabled 1   

```

and idont know whot to add this function to employee number  
any idea?

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 20, 2021, 4:42pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/10 "2021-08-20T16:42:28Z")

</div>

OK, assumed the employeeNumbers in your company are plain integers with no alphabetical or special charachters the following should be all you need.

It queries the AD for all employees and determines the highest employeeNumber. Then it increases it by one and that’s it. 😉

```auto
function New-EmployeeNumber {
    $SearchBase = 
        'OU=users,DC=contoso,DC=com'
    $LastEmployeeNumber = 
        Get-ADUser -Filter * -SearchBase $SearchBase -Properties EmployeeNumber | 
            Sort-Object -Property EmployeeNumber | 
                Select-Object -Last 1 -ExpandProperty EmployeeNumber 
    ($LastEmployeeNumber -as [Int32]) + 1
}

```

If you have an OU in your AD where you have all your user accounts I hihgly recommend to use a SearchBase pointing to this OU as this reduces the stress you put on your AD with this kind of query. 👆🏽

Regardless of that … please read the help for

> **[about Splatting - PowerShell](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_splatting?view=powershell-7.2&viewFallbackFrom=powershell-7.1)**
>
> Describes how to use splatting to pass parameters to commands in PowerShell.

Using backticks to be able to add line breaks is a really bad style and error prone btw.  
Your function New-AdUser would look like this:

```auto
$NewAdUserProperties = @{
    Name = "$firstname $lastname ($EmployeeNumber)"
    GivenName = $firstname
    Surname = $lastname
    EmployeeNumber = $EmployeeNumber
    Displayname = "$FirstName $lastname"
    UserPrincipalName = $email
    SamAccountName = $username
    AccountPassword = (ConvertTo-SecureString $passwordAsPlainTextForce)
    Path = $ADPath
    Enabled = $true
}
New-ADUser @NewAdUserProperties

```

---

<div class="post-metadata">

**Author:** ![alexxx55555](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@alexxx55555](https://forums.powershell.org/u/alexxx55555)\
**Post date:** [August 20, 2021, 5:26pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/11 "2021-08-20T17:26:37Z")

</div>

> [@Olaf](#):
>
> `EmployeeNumber`

Thank you for you answer  
i will read about splatting but unforcedly its still not create user with a free employee number

i think its becuse of

```auto
EmployeeNumber = $EmployeeNumber

```

i tried to ernter her EmployeeNumber = $EmployeeNumber+1

but its wasnt working

any idea?

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 20, 2021, 5:36pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/12 "2021-08-20T17:36:12Z")

</div>

> [@alexxx55555](#):
>
> but unforcedly its still not create user with a free employee number

The function i suggested has another name than yours. You have to adapt your code to it when you use it like I suggested it!!! 😉

---

<div class="post-metadata">

**Author:** ![alexxx55555](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@alexxx55555](https://forums.powershell.org/u/alexxx55555)\
**Post date:** [August 20, 2021, 5:41pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/13 "2021-08-20T17:41:18Z")

</div>

i know i changed you function to my name

```auto
unction EmployeeNumber {
    $SearchBase = 
        'OU=Users,OU=Alex,DC=alex,DC=local'
    $EmployeeNumber = 
        Get-ADUser -Filter * -SearchBase $SearchBase -Properties EmployeeNumber | 
            Sort-Object -Property EmployeeNumber | 
                Select-Object -Last 1 -ExpandProperty EmployeeNumber 
    ($EmployeeNumber -as [Int32]) + 1
}

```

```auto
do {
    try {
        [int]$EmployeeNumber = Read-Host "Enter Employee Number"
    }
    catch [System.Management.Automation.PSInvalidCastException] {
        Write-Warning "You can only use numbers!"
        
    }
}
until (($EmployeeNumber -or $EmployeeNumber -eq 0) -and $EmployeeNumber -match "^[0-9]*$")

if (-not(Get-ADUser -filter "EmployeeNumber -eq '$EmployeeNumber'")) {
    write-output "$EmployeeNumber is available."
}
else {
    Write-Warning "EmployeeNumber '$EmployeeNumber' is already in use."
    $allNum = 
    [Int32[]]($((Get-ADUser -Filter * -Properties EmployeeNumber).EmployeeNumber)) |
    Sort-Object -Descending 

    $newNum = EmployeeNumber -EmployeeNumber $EmployeeNumber -AllNum $allNum
    Write-Output "The next Available EmployeeNumber is '$newNum'"

}

```

still not creating user ☹

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 20, 2021, 6:00pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/14 "2021-08-20T18:00:52Z")

</div>

The function I suggested does not need any input at all. So you can drop all the code you used to get the input from the user and all that other stuff. With the name you used for the function (`EmployeeNumber`) all you need is this:

```auto
$newNum = EmployeeNumber

```

nothing more !!!

---

<div class="post-metadata">

**Author:** ![alexxx55555](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@alexxx55555](https://forums.powershell.org/u/alexxx55555)\
**Post date:** [August 20, 2021, 6:12pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/15 "2021-08-20T18:12:48Z")

</div>

its good but its not creating user 1 by 1 and just random

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 20, 2021, 6:17pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/16 "2021-08-20T18:17:14Z")

</div>

I realy don’t understand what you mean.

> [@alexxx55555](#):
>
> its good but its not creating user 1 by 1 and just random

That is not helpful.

---

<div class="post-metadata">

**Author:** ![alexxx55555](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@alexxx55555](https://forums.powershell.org/u/alexxx55555)\
**Post date:** [August 20, 2021, 6:21pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/17 "2021-08-20T18:21:22Z")

</div>

sorry  
i want it to create user with employee number  
1 by 1  
for expamle  
alex employeenumber 1  
Olaf employeenumber 2

hope that its explandebale

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 20, 2021, 6:27pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/18 "2021-08-20T18:27:57Z")

</div>

The function I suggested determines the next unused employeenumber. So you don’t need to provide a particular employeenumber at all. If you insist to provide a particular employeenumber you have to use your own code. Is that really so hard to understand?

> [@alexxx55555](#):
>
> i want it to create user with employee number  
> 1 by 1  
> for expamle  
> alex employeenumber 1  
> Olaf employeenumber 2

Do you have a completely empty AD with no user accounts yet?

---

<div class="post-metadata">

**Author:** ![alexxx55555](https://avatars.discourse-cdn.com/v4/letter/a/ecae2f/32.png) [@alexxx55555](https://forums.powershell.org/u/alexxx55555)\
**Post date:** [August 20, 2021, 6:35pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/19 "2021-08-20T18:35:26Z")

</div>

> [@Olaf](#):
>
> `$newNum`

yes i have i couple of user

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 20, 2021, 6:44pm UTC](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360/20 "2021-08-20T18:44:52Z")

</div>

> [@alexxx55555](#):
>
> yes i have i couple of user

OK. And I assume they already have employeenumbers, right? So when you use my suggestion the newly created user will automatically get an employeenumber 1 number higher than the highest already existing employeenumber.

[Next page](https://forums.powershell.org/t/not-able-create-user-with-employee-number/17360.md?page=2)
