Managing a large number of Active Directory users manually can be time-consuming and error-prone. In this guide, we will automate the process by generating a CSV file from an Excel spreadsheet using Python and then importing the users into Active Directory with PowerShell.
Prerequisites
Before starting, make sure you have:
- Python 3 installed
- The
openpyxlandpandaslibraries installed - Active Directory PowerShell module installed on the Domain Controller or management server
- Appropriate permissions to create users in Active Directory
Install the required Python libraries:
pip install openpyxl pandas
Step 1: Prepare the Excel File
Create an Excel file named AD_Users.xlsx.
The worksheet should contain the following columns:
| Name | SamAccountName | UserPrincipalName | Password | Domain | Enabled |
|---|---|---|---|---|---|
| John Smith | jsmith | jsmith@omidgroup.local | P@ssw0rd1 | omdgoup.local | TRUE |
| Jane Doe | jdoe | jdoe@omidgroup.local | S3cureP@ss | omdgroup.local | TRUE |
Column Description
- Name: Display name of the user.
- SamAccountName: The logon name used for Windows authentication.
- UserPrincipalName: User logon name in email format.
- Password: Initial password assigned to the user.
- Domain: The Active Directory domain name.
- Enabled: Specifies whether the account should be enabled.
Step 2: Convert Excel to CSV Using Python
The following Python script reads the Excel file and creates a CSV file that can be imported by PowerShell.
After running the script, a file named AD_Users_omidgroup.csv will be created.
from openpyxl import load_workbook
import pandas as pd
xlsx = "AD_Users.xlsx"
wb = load_workbook(xlsx)
ws = wb.active
data = list(ws.values)
headers = data[0]
df = pd.DataFrame(data[1:], columns=headers)
csv_path = "AD_Users_omidgroup.csv"
df.to_csv(csv_path, index=False, encoding="utf-8-sig")
Step 3: Import Users into Active Directory
Create a PowerShell script named Import-ADUsers.ps1:
Import-Module ActiveDirectory
$Users = Import-Csv ".\AD_Users.csv"
foreach ($User in $Users) {
$SecurePassword = ConvertTo-SecureString $User.Password -AsPlainText -Force
New-ADUser `
-Name $User.Name `
-SamAccountName $User.SamAccountName `
-UserPrincipalName $User.UserPrincipalName `
-AccountPassword $SecurePassword `
-Enabled $true `
-ChangePasswordAtLogon $true
}
This script performs the following actions:
- Imports the CSV file.
- Converts the plain text password into a secure string.
- Creates a new Active Directory user.
- Enables the account.
- Forces the user to change the password at first logon.
Running the Script
Copy both files to your Domain Controller or management server:
AD_Users.csvImport-ADUsers.ps1
Then run:
Set-ExecutionPolicy RemoteSigned
.\Import-ADUsers.ps1
Benefits of This Method
- Saves time when creating multiple users.
- Reduces manual configuration errors.
- Easily reusable for onboarding new employees.
- Can be extended to include Organizational Units (OUs), groups, departments, and additional user attributes.
By combining Python and PowerShell, administrators can quickly automate bulk user provisioning in Active Directory with minimal effort.