Skip to content

Microsoft.Automation/automationAccounts/runbooks/write

Azure

Microsoft.Automation/automationAccounts/runbooks/write

service: Azure - Automation
tactics:
techniques:

Event

Writes runbook configuration such as type, runtime environment, logging, and optional content links. Draft upload/publish operations are separate workflows, but Create Or Update can also supply publishContentLink; it is not universally metadata-only. Resource creation or publishing does not itself execute a job.

Security Context

Unauthorized runbook changes can prepare abuse of automation tooling (contextual T1072). Production runbook updates can be legitimate. A metadata-only example does not establish an implanted script or a persistent trigger.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Automation/automationAccounts/runbooks/write. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
properties.requestbodyRunbook type, runtime, logging, draft and publishContentLink where present.
resourceIdRunbook identity; correlate content and job changes.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Compare the complete previous and new resource configuration with change approval.
  3. Recover content revisions and publication state, including any content link; do not execute referenced code during review.
  4. Correlate schedules, webhooks, and actual jobs before asserting persistence or execution.

Sample Event

Synthetic scenario. The sample creates a PowerShell72 runbook resource with logging flags. No script content, content link, trigger, or execution is shown; the type label is not a runtime-support recommendation.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Automation/automationAccounts/runbooks/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/runbooks/Backup-OffSite"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/",
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud"
},
"correlationId": "90000000-0000-4000-8000-000010001100",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000010001101",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T21:02:14.5172938Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000010001110",
"operationName": {
"value": "Microsoft.Automation/automationAccounts/runbooks/write",
"localizedValue": "Create or Update an Azure Automation runbook"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Automation",
"localizedValue": "Microsoft.Automation"
},
"resourceType": {
"value": "Microsoft.Automation/automationAccounts/runbooks",
"localizedValue": "Microsoft.Automation/automationAccounts/runbooks"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/runbooks/Backup-OffSite",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "Created",
"localizedValue": "Created (HTTP Status Code: 201)"
},
"submissionTimestamp": "2026-04-15T21:02:15.1182274Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "Created",
"serviceRequestId": null,
"requestbody": "{\"properties\":{\"runbookType\":\"PowerShell72\",\"description\":\"Off-site backup orchestration\",\"logVerbose\":false,\"logProgress\":false,\"logActivityTrace\":0},\"location\":\"eastus\"}",
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/runbooks/Backup-OffSite",
"message": "Microsoft.Automation/automationAccounts/runbooks/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000010001111",
"clientIpAddress": "203.0.113.66",
"method": "PUT",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/runbooks/Backup-OffSite?api-version=2023-11-01"
},
"identity": null
}

Sources

MITRE ATT&CK Mapping

Tactics: Execution

Techniques:
  • T1072 — Software Deployment Tools — Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine adminis...
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.