PowerShell | Active Directory | Windows Server | Hyper-V | CSV | HTML Reporting
This project showcases the use of PowerShell to automate common IT support and Active Directory administrative tasks in a Windows Server lab environment.
The automation workflows inventory the Active Directory environment, create multiple user accounts from a CSV file, assign departmental security groups, reset passwords, offboard users, generate audit logs, and produce an HTML summary report.
This lab extends the Windows infrastructure deployed in my Active Directory Home Lab by introducing repeatable PowerShell automation for common administrative tasks.
The automated workflows support activities commonly performed by IT Support and Systems Administration teams, including user provisioning, password management, offboarding, reporting, and audit logging.
Together with the Active Directory, Help Desk, and Microsoft Entra ID & Intune labs, this project demonstrates both manual administration and administrative automation within a simulated enterprise environment.
- Automate Active Directory inventory collection.
- Create multiple users from structured CSV data.
- Place users in the appropriate organizational units.
- Assign departmental security groups automatically.
- Validate duplicate accounts, OUs, and groups before provisioning.
- Perform secure password-reset operations.
- Require password changes at the next sign-in.
- Automate employee offboarding.
- Remove departmental group memberships.
- Disable and relocate offboarded accounts.
- Generate CSV audit logs for administrative actions.
- Produce an HTML management summary.
- Develop reusable PowerShell scripts for common IT support tasks.
- Implement error handling and rollback protection.
flowchart TD
A[IT Administrator] --> B[PowerShell Scripts]
C[CSV User Input] --> B
B --> D[Active Directory]
D --> E[Users and OUs]
D --> F[Security Groups]
B --> G[CSV Audit Logs]
B --> H[HTML Summary Report]
| Component | Configuration |
|---|---|
| Hypervisor | Microsoft Hyper-V |
| Server | Windows Server 2022 |
| Domain controller | DC01 |
| Domain | cabreralab.test |
| Directory service | Active Directory Domain Services |
| Automation platform | Windows PowerShell |
| Input format | CSV |
| Audit format | CSV |
| Management report | HTML |
| PowerShell module | ActiveDirectory |
| Script | Purpose | Output
|---|---|
| Get-ADInventory.ps1 | Inventories Active Directory users, groups, and organizational units | Csv |
| New-ADUsersFromCSV.ps1 | Creates users from CSV data and assigns departmental groups | Csv Log |
| Reset-ADUserPassword.ps1 | Resets passwords, unlocks accounts, and requires password changes | Csv Log |
| Disable-ADUserOffboarding.ps1 | Disables accounts, removes groups, and moves users to the disabled OU | Csv Log |
| New-AutomationLabReport.ps1 | Generates an HTML summary from Active Directory and audit data | HTML Dashboard |
The inventory script imports the Active Directory module and collects:
- User accounts
- Security and distribution groups
- Organizational units
- Domain information
The results are exported to separate CSV reports for later review.
A structured CSV file supplies the following properties:
- First and last name
- Username
- Department
- Job title
- Organizational unit
- Departmental security group
Before creating an account, the script validates that:
- The username does not already exist.
- The destination OU exists.
- The security group exists.
- The supplied password complies with domain policy.
The script then creates the user, assigns the departmental group, requires a password change at the next logon, and records the outcome.
The password-reset workflow:
- Locates the requested account.
- Displays its enabled and lockout status.
- Accepts a temporary password securely.
- Resets the password.
- Unlocks the account when necessary.
- Requires a password change at the next sign-in.
- Records the technician, username, action, and result.
The offboarding workflow:
- Displays the employee's account information.
- Requires explicit confirmation.
- Disables the account.
- Removes non-default security groups.
- Adds an offboarding description and date.
- Moves the account to the Disabled Accounts OU.
- Generates an audit record.
The reporting script consolidates information from Active Directory, the automation scripts, and CSV audit logs into a browser-readable dashboard.
The report displays:
- Total, enabled, and disabled users
- Security group and OU counts
- Bulk provisioning results
- Password-reset activity
- Offboarding activity
- PowerShell script inventory
The scripts implement several administrative safeguards:
-ErrorAction Stopfor terminating errors.try/catchblocks for controlled exception handling.- Duplicate-account validation.
- OU and security-group validation.
- Secure password input using
Read-Host -AsSecureString. - Confirmation before offboarding.
- Rollback of partially created user accounts.
- CSV audit logging for traceability.
- No hard-coded passwords or production credentials.
A Hyper-V checkpoint was created before making automation changes, providing a recovery point for the domain controller.
The domain, organizational-unit structure, and departmental security groups were verified before running automation scripts.
The inventory script collected domain users, groups, and organizational units and exported the results into CSV reports.
The structured input file contains the account, department, title, OU, and security-group information required for automated provisioning.
Four departmental accounts were successfully created after validation of the destination OUs, groups, and password policy.
The newly created accounts were verified with their departmental attributes and Active Directory security-group memberships.
The password-reset script completed successfully and configured the user to change the temporary password at the next logon.
The account state and generated CSV audit record were reviewed to confirm the password-reset operation.
The offboarded account was disabled, removed from its departmental security group, moved to the Disabled Accounts OU, and recorded in the audit log.
The final HTML dashboard summarizes Active Directory objects, provisioning activity, password resets, offboarding actions, and available automation scripts.
Additional chronological evidence is available in the screenshots directory.
The completed automation was successfully validated by:
- Executing the Active Directory inventory script and verifying CSV exports.
- Provisioning multiple users from structured CSV input.
- Confirming correct organizational unit placement.
- Verifying automatic departmental security-group assignments.
- Successfully completing password-reset operations.
- Confirming password change at next sign-in.
- Validating user offboarding, account disablement, and OU relocation.
- Reviewing generated CSV audit logs.
- Generating and validating the HTML management summary.
The completed automation successfully produced:
- 3 Active Directory inventory reports.
- 4 successfully provisioned departmental users.
- Validated departmental group memberships.
- A successful password-reset workflow.
- A successful employee-offboarding workflow.
- 3 CSV audit logs.
- A consolidated HTML summary report.
- 5 reusable PowerShell scripts.
- PowerShell scripting
- Windows Server administration
- Active Directory administration
- User lifecycle management
- Bulk account provisioning
- Password reset automation
- Employee offboarding
- CSV processing
- HTML reporting
- Audit logging
- Error handling
- Technical documentation
This repository represents a controlled lab environment. The names and accounts used are fictional. Passwords, private credentials, and production information are not included.
Carlos Cabrera
CompTIA A+ Certified
IT Support | Windows Administration | Active Directory | PowerShell Automation









