An Automation Account runs runbooks (PowerShell or Python) under its own identity, holds credential, variable, and connection assets that are often cleartext, and can reach on-prem or VM hosts through Hybrid Runbook Workers. It is one of the highest-value targets on the Azure resource plane: a runbook is arbitrary code as a privileged identity, and the account's assets routinely store service-principal secrets.
What folds in here#
- Runbooks: writing and starting a runbook that runs as the account's identity.
- RunAs account: the RunAs certificate and its service principal.
- Hybrid Runbook Worker: executing runbooks on on-prem or VM hosts.
The account's stored credential assets are harvested as credentials.