SOLVED

Delegated Admin tenants and adding a list of the same users across multiple tenants PowerShell

%3CLINGO-SUB%20id%3D%22lingo-sub-1406075%22%20slang%3D%22en-US%22%3EDelegated%20Admin%20tenants%20and%20adding%20a%20list%20of%20the%20same%20users%20across%20multiple%20tenants%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1406075%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20the%20point%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20managing%20clients%20tenants%20through%20Partner%20Centre%20-%20However%2C%20there%20is%20limited%20controls.%20i.e.%20Cannot%20properly%20manage%20SharePoint%2C%20Convert%20users%20mailboxes%20to%20Shared%20Mailboxes%2C%20manage%20Teams%20etc.%20Therefor%20the%20only%20way%20around%20this%20that%20I%20can%20tell%20is%20to%20create%20all%20our%20service%20desk%20users%20as%20users%20in%20each%20client%20tenant.%20Then%20assign%20the%20appropriate%20admin%20roles%20they%20require%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EThrough%20PowerShell%2C%20we%20can%20create%20users%20using%20Delegated%20Access%2C%20creating%20a%20CSV%20listing%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-html%22%3E%3CCODE%3EUserPrincipalName%2CFirstName%2CLastName%2CDisplayName%2CPassword%2CTenantId%2CUsageLocation%2CLicenseAssignment%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%3CBR%20%2F%3EThen%20in%20PowerShell%20-%20we%20can%20get%20a%20list%20of%20all%20our%20clients%20%22%3CSTRONG%3ETenant%20ID%3C%2FSTRONG%3E's%22%20then%20substitute%20them%20into%20the%20CSV%3C%2FP%3E%3CP%3EAnd%20we%20require%20to%20add%20each%20users%20UPN%20to%20match%20the%20clients%20active%20domain%20name.%20i.e.%20%3CSTRONG%3Econtoso.onmicrosoft.com%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%3CSTRONG%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSTRONG%3EWe%20then%20can%20run%20the%20following%20for%20a%20single%20client%20tenant%20and%20it%20will%20create%20the%20users%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-powershell%22%3E%3CCODE%3EImport-Csv%20.%5CFILENAME.CSV%20%7C%20foreach%20%7BNew-MsolUser%20-UserPrincipalName%20%24_.UserPrincipalName%20-DisplayName%20%24_.DisplayName%20-FirstName%20%24_.FirstName%20-LastName%20%24_.LastName%20-Password%20%24_.Password%20-UsageLocation%20%24_.UsageLocation%20-LicenseAssignment%20%24_.LicenseAssignment%20-ForceChangePassword%3A%24true%20-PasswordNeverExpires%3A%24true%20-TenantId%20%24_.TenantId%7D%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20a%20user%20leaves%2C%20we%20simple%20run%20a%20removal%20script%20to%20remove%20the%20service%20desk%20user%20from%20the%20client's%20Microsoft%20tenant.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EThe%20Problem%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EWe%20have%20almost%2090%20clients%20we%20are%20managing%20from%20our%20service%20desk%2C%20we%20want%20to%20be%20able%20to%20have%201%20list%20of%20our%20users%20and%20run%20the%20script%20to%20loop%20through%20each%20tenant%20ID%20and%20create%20the%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20seem%20to%20have%20this%20almost%20down%2C%20however%20the%20UPN%20bit%20is%20what%20is%20catching%20us.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20creating%20a%26nbsp%3B%3CSTRONG%3ENew-MsolUser%26nbsp%3B%3C%2FSTRONG%3Ewhen%20you%20get%20to%20the%20%3CSTRONG%3E-UserPrincipleName%26nbsp%3B%3C%2FSTRONG%3Ewe%20not%20sure%20how%20to%20automate%20and%20append%20each%20clients%20%22%40contoso.onmicrosoft.com%22%20address%20to%20each%20user%20in%20our%20user%20list.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E--%20Currently%20we%20have%20it%20like%20this%3A%20(may%20still%20not%20be%20right%20but%20just%20trying%20to%20fudge%20the%20idea%20together%20to%20perhaps%20find%20a%20way%20of%20doing%20it%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-applescript%22%3E%3CCODE%3E%24cred%20%3D%20Get-Credential%0AImport-Module%20MsOnline%0AConnect-MsolService%20-Credential%20%24cred%0A%0AGet-MsolPartnerContract%20-All%20%7C%20ForEach%20%7B%0A%20%20%20%20Import-Csv%20-Path%20%3CINPUT%20csv%3D%22%22%20file%3D%22%22%20path%3D%22%22%20and%3D%22%22%20name%3D%22%22%20%2F%3E%20%7C%20foreach%20-TenantId%20%24_.TenantId.Guid%20%7BNew-MsolUser%20-DisplayName%20%24_.DisplayName%20-FirstName%20%24_.FirstName%20-LastName%20%24_.LastName%20-UserPrincipalName%20%24_.UserPrincipalName%20-UsageLocation%20%24_.UsageLocation%20-LicenseAssignment%20%24_.AccountSkuId%20-Password%20%24_.Password%20-ForceChangePassword%3A%24true%20-PasswordNeverExpires%3A%24true%7D%0A%7D%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3Eany%20ideas%20or%20clues%20would%20be%20great%2C%26nbsp%3B%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fenterprise%2Fpowershell%2Fmanage-office-365-tenants-with-windows-powershell-for-delegated-access-permissio%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fenterprise%2Fpowershell%2Fmanage-office-365-tenants-with-windows-powershell-for-delegated-access-permissio%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewe've%20refrenced%20this%20so%20far%3A%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1406075%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1406274%22%20slang%3D%22en-US%22%3ERe%3A%20Delegated%20Admin%20tenants%20and%20adding%20a%20list%20of%20the%20same%20users%20across%20multiple%20tenants%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1406274%22%20slang%3D%22en-US%22%3E%3CP%3EIt's%20been%20a%20long%20time%20since%20I%20had%20a%20partner%20account%2C%20but%20you%20should%20be%20able%20to%20get%20the%20domain%20name%20from%20the%20output%20of%20Get-MsolPartnerContract%2C%20or%20just%20call%20Get-MsolDomain%20for%20each%20tenant%3F%20Then%20append%20to%20the%20UPN.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1407866%22%20slang%3D%22en-US%22%3ERe%3A%20Delegated%20Admin%20tenants%20and%20adding%20a%20list%20of%20the%20same%20users%20across%20multiple%20tenants%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1407866%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20thought%20this%20too%20but%20I%20get%20all%20the%20clients%20domains%2C%20if%20I%20filter%20by%20-Match%20%22.onmicrosoft.com%22%20I%20get%20mostly%202%20returns.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Econtoso.mail.onmicrosoft.com%20and%20contoso.onmicrosoft.com%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1408135%22%20slang%3D%22en-US%22%3ERe%3A%20Delegated%20Admin%20tenants%20and%20adding%20a%20list%20of%20the%20same%20users%20across%20multiple%20tenants%20PowerShell%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1408135%22%20slang%3D%22en-US%22%3E%3CP%3EWorked%20it%20out%20%3AD%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-powershell%22%3E%3CCODE%3EGet-MsolPartnerContract%20-All%20%7C%20ForEach%20%7B%0A%20%20%20%20%24tenantprefix%20%3D%20%5Bstring%5D%24_.DefaultDomainName%0A%20%20%20%20%24TenantId%20%3D%20%5Bstring%5D%24_.TenantId.Guid%0A%0A%20%20%20%20Import-Csv%20.%5Cusers1.csv%20%7C%20foreach%20%7B%0A%20%20%20%20%20%20%20%20%24newUPN%20%3D%20%24_.UserPrincipalName%20%2B%20%22%40%22%20%2B%20%24tenantprefix%0A%20%20%20%20%20%20%20%20%24newUPN%20%3D%20%5Bstring%5D%24newUPN%0A%20%20%20%20%20%20%20%20New-MsolUser%20-DisplayName%20%24_.DisplayName%20-UserPrincipalName%20%24newUPN%20-Password%20%24_.Password%20-ForceChangePassword%3A%24true%20-PasswordNeverExpires%3A%24true%20-TenantId%20%24TenantId%20%0A%20%20%20%20%7D%0A%7D%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Hello 

 

To the point: 

 

We are managing clients tenants through Partner Centre - However, there is limited controls. i.e. Cannot properly manage SharePoint, Convert users mailboxes to Shared Mailboxes, manage Teams etc. Therefor the only way around this that I can tell is to create all our service desk users as users in each client tenant. Then assign the appropriate admin roles they require 

Through PowerShell, we can create users using Delegated Access, creating a CSV listing: 

 

 

UserPrincipalName,FirstName,LastName,DisplayName,Password,TenantId,UsageLocation,LicenseAssignment

 


Then in PowerShell - we can get a list of all our clients "Tenant ID's" then substitute them into the CSV

And we require to add each users UPN to match the clients active domain name. i.e. contoso.onmicrosoft.com



We then can run the following for a single client tenant and it will create the users 

 

Import-Csv .\FILENAME.CSV | foreach {New-MsolUser -UserPrincipalName $_.UserPrincipalName -DisplayName $_.DisplayName -FirstName $_.FirstName -LastName $_.LastName -Password $_.Password -UsageLocation $_.UsageLocation -LicenseAssignment $_.LicenseAssignment -ForceChangePassword:$true -PasswordNeverExpires:$true -TenantId $_.TenantId}

 

 

When a user leaves, we simple run a removal script to remove the service desk user from the client's Microsoft tenant. 

 

The Problem

We have almost 90 clients we are managing from our service desk, we want to be able to have 1 list of our users and run the script to loop through each tenant ID and create the users.

 

We seem to have this almost down, however the UPN bit is what is catching us. 

 

When creating a New-MsolUser when you get to the -UserPrincipleName we not sure how to automate and append each clients "@contoso.onmicrosoft.com" address to each user in our user list. 

 

-- Currently we have it like this: (may still not be right but just trying to fudge the idea together to perhaps find a way of doing it: 

 

 

$cred = Get-Credential
Import-Module MsOnline
Connect-MsolService -Credential $cred

Get-MsolPartnerContract -All | ForEach {
    Import-Csv -Path <Input CSV File Path and Name> | foreach -TenantId $_.TenantId.Guid {New-MsolUser -DisplayName $_.DisplayName -FirstName $_.FirstName -LastName $_.LastName -UserPrincipalName $_.UserPrincipalName -UsageLocation $_.UsageLocation -LicenseAssignment $_.AccountSkuId -Password $_.Password -ForceChangePassword:$true -PasswordNeverExpires:$true}
}

 

any ideas or clues would be great, we've referenced this so far:  https://docs.microsoft.com/en-us/office365/enterprise/powershell/manage-office-365-tenants-with-wind...

 

 

3 Replies
Highlighted

It's been a long time since I had a partner account, but you should be able to get the domain name from the output of Get-MsolPartnerContract, or just call Get-MsolDomain for each tenant? Then append to the UPN.

Highlighted

Thanks, @Vasil Michev 

 

I thought this too but I get all the clients domains, if I filter by -Match ".onmicrosoft.com" I get mostly 2 returns. 

 

contoso.mail.onmicrosoft.com and contoso.onmicrosoft.com  

 

 

Highlighted
Solution

Worked it out :D 

 

 

Get-MsolPartnerContract -All | ForEach {
    $tenantprefix = [string]$_.DefaultDomainName
    $TenantId = [string]$_.TenantId.Guid

    Import-Csv .\users1.csv | foreach {
        $newUPN = $_.UserPrincipalName + "@" + $tenantprefix
        $newUPN = [string]$newUPN
        New-MsolUser -DisplayName $_.DisplayName -UserPrincipalName $newUPN -Password $_.Password -ForceChangePassword:$true -PasswordNeverExpires:$true -TenantId $TenantId 
    }
}