Skip to content

Microsoft.Automation/automationAccounts/webhooks/action

Azure

Microsoft.Automation/automationAccounts/webhooks/action

service: Azure - Automation
tactics:
techniques:

Event

Microsoft’s Automation operation catalog defines webhooks/action as webhook URI generation. The corresponding management API is POST on the Automation account’s webhooks/generateUri endpoint. It does not invoke a runbook, bind the URI to a runbook, or establish an executed job.

Security Context

Unexpected URI generation can precede an unauthorized webhook setup, but it is not execution evidence; no ATT&CK technique is assigned here. Approved webhook provisioning uses this operation. Do not infer that the caller is always the Automation account identity.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Automation/automationAccounts/webhooks/action. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.

Key Fields

FieldInvestigation value
operationName.value, httpRequestOperation and authenticated ARM generateUri request.
caller, resourceIdRequesting identity and Automation account context.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the actor’s authority and approved webhook provisioning request.
  3. Correlate webhook creation and subsequent configuration without exposing the generated secret URL.
  4. Use separate webhook/job evidence to establish invocation; this operation alone says nothing about runbook execution.

Sample Event

Synthetic scenario. The corrected sample illustrates an authenticated generateUri request by Draco. The returned URI is intentionally omitted. It replaces the unsupported anonymous-invocation/account-identity example.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Automation/automationAccounts/webhooks/action",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001"
},
"correlationId": "90000000-0000-4000-8000-000010010000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000010010001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T21:18:42.7172938Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000010010010",
"operationName": {
"value": "Microsoft.Automation/automationAccounts/webhooks/action",
"localizedValue": "Generate a URI for an Azure Automation webhook"
},
"resourceGroupName": "rg-occamy-pipeline",
"resourceProviderName": {
"value": "Microsoft.Automation",
"localizedValue": "Microsoft.Automation"
},
"resourceType": {
"value": "Microsoft.Automation/automationAccounts",
"localizedValue": "Microsoft.Automation/automationAccounts"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "OK",
"localizedValue": "OK (HTTP Status Code: 200)"
},
"submissionTimestamp": "2026-04-15T21:18:43.0218732Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "OK",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation",
"message": "Microsoft.Automation/automationAccounts/webhooks/action",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001"
},
"relatedEvents": [],
"httpRequest": {
"clientRequestId": "90000000-0000-4000-8000-000010010011",
"clientIpAddress": "203.0.113.66",
"method": "POST",
"url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/webhooks/generateUri?api-version=2024-10-23"
},
"identity": null
}

Sources

Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.