Microsoft.Automation/automationAccounts/webhooks/action
Microsoft.Automation/automationAccounts/webhooks/action
Event
Microsoft’s Automation operation catalog defines webhooks/action as webhook URI generation. The corresponding management API is POST on the Automation account’s webhooks/generateUri endpoint. It does not invoke a runbook, bind the URI to a runbook, or establish an executed job.
Security Context
Unexpected URI generation can precede an unauthorized webhook setup, but it is not execution evidence; no ATT&CK technique is assigned here. Approved webhook provisioning uses this operation. Do not infer that the caller is always the Automation account identity.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Automation/automationAccounts/webhooks/action. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
operationName.value, httpRequest | Operation and authenticated ARM generateUri request. |
caller, resourceId | Requesting identity and Automation account context. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify the actor’s authority and approved webhook provisioning request.
- Correlate webhook creation and subsequent configuration without exposing the generated secret URL.
- Use separate webhook/job evidence to establish invocation; this operation alone says nothing about runbook execution.
Sample Event
Synthetic scenario. The corrected sample illustrates an authenticated generateUri request by Draco. The returned URI is intentionally omitted. It replaces the unsupported anonymous-invocation/account-identity example.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Automation/automationAccounts/webhooks/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001" }, "correlationId": "90000000-0000-4000-8000-000010010000", "description": "", "eventDataId": "90000000-0000-4000-8000-000010010001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T21:18:42.7172938Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000010010010", "operationName": { "value": "Microsoft.Automation/automationAccounts/webhooks/action", "localizedValue": "Generate a URI for an Azure Automation webhook" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.Automation", "localizedValue": "Microsoft.Automation" }, "resourceType": { "value": "Microsoft.Automation/automationAccounts", "localizedValue": "Microsoft.Automation/automationAccounts" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T21:18:43.0218732Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation", "message": "Microsoft.Automation/automationAccounts/webhooks/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000010010011", "clientIpAddress": "203.0.113.66", "method": "POST", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/webhooks/generateUri?api-version=2024-10-23" }, "identity": null}