Microsoft.Automation/automationAccounts/runbooks/write
Microsoft.Automation/automationAccounts/runbooks/write
Event
Writes runbook configuration such as type, runtime environment, logging, and optional content links. Draft upload/publish operations are separate workflows, but Create Or Update can also supply publishContentLink; it is not universally metadata-only. Resource creation or publishing does not itself execute a job.
Security Context
Unauthorized runbook changes can prepare abuse of automation tooling (contextual T1072). Production runbook updates can be legitimate. A metadata-only example does not establish an implanted script or a persistent trigger.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Automation/automationAccounts/runbooks/write. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
properties.requestbody | Runbook type, runtime, logging, draft and publishContentLink where present. |
resourceId | Runbook identity; correlate content and job changes. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Compare the complete previous and new resource configuration with change approval.
- Recover content revisions and publication state, including any content link; do not execute referenced code during review.
- Correlate schedules, webhooks, and actual jobs before asserting persistence or execution.
Sample Event
Synthetic scenario. The sample creates a PowerShell72 runbook resource with logging flags. No script content, content link, trigger, or execution is shown; the type label is not a runtime-support recommendation.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Automation/automationAccounts/runbooks/write", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/runbooks/Backup-OffSite" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000010001100", "description": "", "eventDataId": "90000000-0000-4000-8000-000010001101", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T21:02:14.5172938Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000010001110", "operationName": { "value": "Microsoft.Automation/automationAccounts/runbooks/write", "localizedValue": "Create or Update an Azure Automation runbook" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.Automation", "localizedValue": "Microsoft.Automation" }, "resourceType": { "value": "Microsoft.Automation/automationAccounts/runbooks", "localizedValue": "Microsoft.Automation/automationAccounts/runbooks" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/runbooks/Backup-OffSite", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "Created", "localizedValue": "Created (HTTP Status Code: 201)" }, "submissionTimestamp": "2026-04-15T21:02:15.1182274Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "Created", "serviceRequestId": null, "requestbody": "{\"properties\":{\"runbookType\":\"PowerShell72\",\"description\":\"Off-site backup orchestration\",\"logVerbose\":false,\"logProgress\":false,\"logActivityTrace\":0},\"location\":\"eastus\"}", "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/runbooks/Backup-OffSite", "message": "Microsoft.Automation/automationAccounts/runbooks/write", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000010001111", "clientIpAddress": "203.0.113.66", "method": "PUT", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/runbooks/Backup-OffSite?api-version=2023-11-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Execution
- T1072 — Software Deployment Tools — Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine adminis...