Skip to content

Microsoft.Automation/automationAccounts/jobs/write

Azure

Microsoft.Automation/automationAccounts/jobs/write

service: Azure - Automation
tactics:
techniques:

Event

Submits a job for a runbook, with parameters and an optional runOn Hybrid Runbook Worker group. runOn names the group, not necessarily an individual host. Accepted job creation does not establish completion, the worker that executed it, or which credentials the code used.

Security Context

Unauthorized runbook jobs can execute through automation tooling (contextual T1072). Routine operations are common. The runbook name does not establish malicious script content, on-premises reachability, or credential dumping.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Automation/automationAccounts/jobs/write. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
resourceId, properties.requestbodyJob ID, runbook, parameters, and optional worker group.
status, subStatusCreation result; follow job status and streams separately.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Recover the exact published runbook content and approved job request.
  3. Resolve worker-group membership, execution identity, dependencies, and effective permissions.
  4. Follow job status, output/streams, worker telemetry, and resource effects. A metadata credential read does not prove password disclosure.

Sample Event

Synthetic scenario. The sample submits Backup-OffSite to a Hybrid Runbook Worker group. It contains neither runbook code nor evidence of credential extraction.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Automation/automationAccounts/jobs/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/jobs/90000000-0000-4000-8000-000010001000"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000010001000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000010001001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T21:08:32.7382194Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000010001010",
"operationName": {
"value": "Microsoft.Automation/automationAccounts/jobs/write",
"localizedValue": "Create or Update an Azure Automation job"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Automation",
"localizedValue": "Microsoft.Automation"
},
"resourceType": {
"value": "Microsoft.Automation/automationAccounts/jobs",
"localizedValue": "Microsoft.Automation/automationAccounts/jobs"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/jobs/90000000-0000-4000-8000-000010001000",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "Created",
"localizedValue": "Created (HTTP Status Code: 201)"
},
"submissionTimestamp": "2026-04-15T21:08:33.0218732Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "Created",
"serviceRequestId": null,
"requestbody": "{\"properties\":{\"runbook\":{\"name\":\"Backup-OffSite\"},\"parameters\":{},\"runOn\":\"hybrid-worker-occamy-01\"}}",
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/jobs/90000000-0000-4000-8000-000010001000",
"message": "Microsoft.Automation/automationAccounts/jobs/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000010001011",
"clientIpAddress": "203.0.113.66",
"method": "PUT",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/jobs/90000000-0000-4000-8000-000010001000?api-version=2023-11-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Execution

Techniques:
  • T1072 — Software Deployment Tools — Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine adminis...
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.