# Rename UPN in AD, AAD and Update Primary SMTP

**URL:** <https://forums.powershell.org/t/rename-upn-in-ad-aad-and-update-primary-smtp/20585>\
**Category:** PowerShell Help\
**Created:** [October 7, 2022, 8:06am UTC](https://forums.powershell.org/t/rename-upn-in-ad-aad-and-update-primary-smtp/20585 "2022-10-07T08:06:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![tp447](https://avatars.discourse-cdn.com/v4/letter/t/e9c0ed/32.png) [@tp447](https://forums.powershell.org/u/tp447)\
**Post date:** [October 7, 2022, 8:06am UTC](https://forums.powershell.org/t/rename-upn-in-ad-aad-and-update-primary-smtp/20585/1 "2022-10-07T08:06:21Z")

</div>

Hi,  
I am starting to use more PowerShell for everyday jobs and put together this script to do 3 things. Wondered if there was advice on tidying this up to improve it (and my knowledge along the way!).

Any help or advice appreciated.

```auto
# Get AD Objects in Scope

$Users = Import-CSV C:\Temp\TestAAD.csv

# Rename UPN in AD

$Users | foreach-object {

Write-host “Changing UPN for user $($_.SamAccountName) to $($_.NewUserPrincipalName)” -Foregroundcolor Green

Set-ADUser -identity $_.SamAccountName -userprincipalname $_.Newuserprincipalname }

# Pause for 3 Seconds
Start-Sleep -Seconds 3

# Rename Primary SMTP Address

$Users | foreach-object {

Write-host “Changing PrimarySMTP for user $($_.UserPrincipalName) to $($_.PrimarySmtpAddress)” -Foregroundcolor Green

Set-RemoteMailbox -Identity $_.UserPrincipalName -PrimarySMTPAddress $_.PrimarySMTPAddress }

# Pause for 3 Seconds
Start-Sleep -Seconds 3

# Rename UPN in AAD

$Users | ForEach-Object {

Write-host “Changing UPN for user $($_.UserPrincipalName) to $($_.NewUserPrincipalName)” -Foregroundcolor Green

Set-MsolUserPrincipalName -UserPrincipalName $_.UserPrincipalName -NewUserPrincipalName $_.Newuserprincipalname 
}

```

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [October 9, 2022, 10:19pm UTC](https://forums.powershell.org/t/rename-upn-in-ad-aad-and-update-primary-smtp/20585/2 "2022-10-09T22:19:42Z")

</div>

tp44794,  
Welcome back to the forum. 👋🏽 … long time no see.

> [@tp447](#):
>
> Any help or advice appreciated.

You may start with reading

> **[GitHub - PoshCode/PowerShellPracticeAndStyle: The Unofficial PowerShell Best...](https://github.com/PoshCode/PowerShellPracticeAndStyle)**
>
> The Unofficial PowerShell Best Practices and Style Guide - GitHub - PoshCode/PowerShellPracticeAndStyle: The Unofficial PowerShell Best Practices and Style Guide

or this:

> **[PowerShell Best Practices: Tips from a Microsoft MVP](https://adamtheautomator.com/powershell-best-practices/?utm_source=twitter&utm_medium=social&utm_campaign=ReviveOldPost)**
>
> Learn PowerShell best practices from a 10+ year developer and Microsoft PowerShell MVP to enhance your scripting skills.

Some short recommendations:

- Do not over comment.  
Even for human beeings not knowing PowerShell it’d some kind of obvious that

```auto
Start-Sleep -Seconds 3

```

does a

```auto
# Pause for 3 Seconds

```

- Do not use `Write-Host`  
[Write-Host Considered Harmful | Jeffrey Snover's blog](https://www.jsnover.com/blog/2013/12/07/write-host-considered-harmful/)

- Do not post unnecessary white space or empty lines. It makes your code harder to read

- Format your code nicely. Use indentations. Add line breaks after pipe symbols to reduse the length of your code lines.

- Do not iterate more than once over a given array if it’s not necessary.

---

<div class="post-metadata">

**Author:** ![tp447](https://avatars.discourse-cdn.com/v4/letter/t/e9c0ed/32.png) [@tp447](https://forums.powershell.org/u/tp447)\
**Post date:** [October 10, 2022, 7:58am UTC](https://forums.powershell.org/t/rename-upn-in-ad-aad-and-update-primary-smtp/20585/3 "2022-10-10T07:58:30Z")

</div>

Thank you Olaf, much appreciated. Ill take a look at the guides 🙂

---

<div class="post-metadata">

**Author:** ![laage](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/laage/32/43_2.png) [@laage](https://forums.powershell.org/u/laage)\
**Post date:** [October 10, 2022, 8:21am UTC](https://forums.powershell.org/t/rename-upn-in-ad-aad-and-update-primary-smtp/20585/4 "2022-10-10T08:21:08Z")

</div>

Olaf has linked you to a number of resources concerning style and I have nothing to add there.  
What I’m wondering is, do you not sync your local users with AAD via an AAD-connect or similar?

If so I would be very surprised if you needed the second part of the script as the sync really should take care of the changed UPN.  
Actually I would expect the Set-MSOLUserPrincipalName to fail as the user should be managed from the local AD.

---

<div class="post-metadata">

**Author:** ![tp447](https://avatars.discourse-cdn.com/v4/letter/t/e9c0ed/32.png) [@tp447](https://forums.powershell.org/u/tp447)\
**Post date:** [October 10, 2022, 11:30am UTC](https://forums.powershell.org/t/rename-upn-in-ad-aad-and-update-primary-smtp/20585/5 "2022-10-10T11:30:52Z")

</div>

Hi,

Yes AAD Connect is used and the 2nd step does make the change as required.

Testing in my lab, the UPN updated fine with a sync, however i believe there is an issue with UPN not updating for licensed objects in M365 which means you need to change the UPN manually in AAD.

---

<div class="post-metadata">

**Author:** ![laage](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/laage/32/43_2.png) [@laage](https://forums.powershell.org/u/laage)\
**Post date:** [October 10, 2022, 11:43am UTC](https://forums.powershell.org/t/rename-upn-in-ad-aad-and-update-primary-smtp/20585/6 "2022-10-10T11:43:26Z")

</div>

OK.  
I’ve never needed to update that attribute before, so I’ll accept that may be needed.

A couple of things I’d personally look at in your script would be adding a bit of error handling. I would wrap the `Set-RemoteMailbox` and `Set-MSOLUserPrincipalName` lines in a try/catch so I could catch and log any users that may need manual intervention.

I would probably also force a delta sync in AAD connect and add a longer sleep before running the second `ForEach-Object`, so you don’t risk clashing between the changes from your script and the sync.

And just a Heads-Up. The MS OnLine module is deprecated. While it still works you should probably be looking at moving scripts to the MS Graph module instead.

---

<div class="post-metadata">

**Author:** ![tp447](https://avatars.discourse-cdn.com/v4/letter/t/e9c0ed/32.png) [@tp447](https://forums.powershell.org/u/tp447)\
**Post date:** [October 10, 2022, 12:16pm UTC](https://forums.powershell.org/t/rename-upn-in-ad-aad-and-update-primary-smtp/20585/7 "2022-10-10T12:16:51Z")

</div>

Thank you sir.

The feedback from you both is exactly what i am looking for to improve moving forward 🙂

Ill take a look at error handling next…

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:16pm UTC](https://forums.powershell.org/t/rename-upn-in-ad-aad-and-update-primary-smtp/20585/8 "2024-05-16T20:16:32Z")

</div>


