Microsoft.Automation/automationAccounts/webhooks/write
Microsoft.Automation/automationAccounts/webhooks/write
Event
Configures a webhook’s runbook, enabled state, expiry, parameters, and optional Hybrid Worker group. Possession of a valid enabled webhook URL can authorize a request without Entra authentication at that endpoint. URI generation, webhook creation, invocation, and successful job execution are separate events.
Security Context
Unauthorized webhook configuration can prepare event-triggered persistence (T1546). Approved integrations are common. Exposure depends on who possesses the URL, the runbook’s handling of incoming data, and the execution context; an enabled webhook is not proof it was used.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Automation/automationAccounts/webhooks/write. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
properties.requestbody | Enabled state, expiryTime, runbook, parameters, runOn, and URI if present; treat any live URI as a secret. |
resourceId, caller | Webhook and configuring identity. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Compare prior/new configuration and the approved integration, including expiry and secret-URL handling.
- Inspect published runbook content, input validation, worker-group configuration, and effective execution permissions.
- Correlate invocation evidence and job outcomes. Do not assume every create/update response or Activity Log includes the secret URL.
Sample Event
Synthetic scenario. The sample configures an enabled webhook for Backup-OffSite with an illustrative one-year expiry. No secret URI or invocation is shown.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Automation/automationAccounts/webhooks/write", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/webhooks/webhook-backup-offsite" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000010010100", "description": "", "eventDataId": "90000000-0000-4000-8000-000010010101", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T21:14:08.5183194Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000010010110", "operationName": { "value": "Microsoft.Automation/automationAccounts/webhooks/write", "localizedValue": "Create or Update an Azure Automation webhook" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.Automation", "localizedValue": "Microsoft.Automation" }, "resourceType": { "value": "Microsoft.Automation/automationAccounts/webhooks", "localizedValue": "Microsoft.Automation/automationAccounts/webhooks" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/webhooks/webhook-backup-offsite", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "Created", "localizedValue": "Created (HTTP Status Code: 201)" }, "submissionTimestamp": "2026-04-15T21:14:09.0218739Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "Created", "serviceRequestId": null, "requestbody": "{\"properties\":{\"isEnabled\":true,\"expiryTime\":\"2027-04-15T21:14:08Z\",\"runbook\":{\"name\":\"Backup-OffSite\"},\"runOn\":\"hybrid-worker-occamy-01\",\"parameters\":{}},\"name\":\"webhook-backup-offsite\"}", "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/webhooks/webhook-backup-offsite", "message": "Microsoft.Automation/automationAccounts/webhooks/write", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000010010111", "clientIpAddress": "203.0.113.66", "method": "PUT", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.Automation/automationAccounts/aa-occamy-automation/webhooks/webhook-backup-offsite?api-version=2023-11-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1546 — Event Triggered Execution — Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cl...