Microsoft.Automation/automationAccounts/credentials/read
Microsoft.Automation/automationAccounts/credentials/read
Event
The management-plane credential GET exposes metadata such as the asset name and username, not its password. Retrieving a usable PSCredential inside a runbook through Get-AutomationPSCredential is a different operation/context, not an API-version variant of this ARM read.
Security Context
Metadata can inform an investigation, but it is not evidence of secret extraction. No credential-access technique is assigned to this operation alone. Normal inventory and runbook maintenance read these assets; an asset named OnPremDomainAdmin does not prove domain-admin rights or network connectivity.
Log Source
This is an ARM permission/API operation, not a guaranteed default Activity Log event. Azure Activity Log does not typically capture GET/read operations. Confirm available client/service telemetry before writing a detection; runbook secret retrieval needs separate job/runtime evidence.
Key Fields
| Field | Investigation value |
|---|---|
method, resourceId | Illustrative GET and target asset. |
response.properties.userName | Metadata, if collected; no password is included. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Confirm what client or service telemetry actually captured the GET; do not assume default Activity Log coverage.
- Resolve asset metadata and approved use without exposing stored secrets.
- Correlate separately with runbook content and job evidence if investigating credential use or disclosure.
Sample Event
Synthetic scenario. The sample is a minimal synthetic management-request illustration, not an asserted Activity Log event. It records a metadata GET without a secret value.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "method": "GET", "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/credentials/OnPremDomainAdmin", "apiVersion": "2024-10-23", "response": { "properties": { "userName": "CONTOSO\\automation-backup", "description": "Illustrative credential metadata" } }}