Skip to content

Microsoft.Automation/automationAccounts/credentials/read

Azure

Microsoft.Automation/automationAccounts/credentials/read

service: Azure - Automation
tactics:
techniques:

Event

The management-plane credential GET exposes metadata such as the asset name and username, not its password. Retrieving a usable PSCredential inside a runbook through Get-AutomationPSCredential is a different operation/context, not an API-version variant of this ARM read.

Security Context

Metadata can inform an investigation, but it is not evidence of secret extraction. No credential-access technique is assigned to this operation alone. Normal inventory and runbook maintenance read these assets; an asset named OnPremDomainAdmin does not prove domain-admin rights or network connectivity.

Log Source

This is an ARM permission/API operation, not a guaranteed default Activity Log event. Azure Activity Log does not typically capture GET/read operations. Confirm available client/service telemetry before writing a detection; runbook secret retrieval needs separate job/runtime evidence.

Key Fields

FieldInvestigation value
method, resourceIdIllustrative GET and target asset.
response.properties.userNameMetadata, if collected; no password is included.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Confirm what client or service telemetry actually captured the GET; do not assume default Activity Log coverage.
  3. Resolve asset metadata and approved use without exposing stored secrets.
  4. Correlate separately with runbook content and job evidence if investigating credential use or disclosure.

Sample Event

Synthetic scenario. The sample is a minimal synthetic management-request illustration, not an asserted Activity Log event. It records a metadata GET without a secret value.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"method": "GET",
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/credentials/OnPremDomainAdmin",
"apiVersion": "2024-10-23",
"response": {
"properties": {
"userName": "CONTOSO\\automation-backup",
"description": "Illustrative credential metadata"
}
}
}

Sources

Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.