Azure Automation accounts that ran no jobs and no update deployments for 30 days
What does ZopNight detect here?
ZopNight flags an Azure Automation account when both its `TotalJob` and `TotalUpdateDeploymentRuns` metrics stay at zero across at least 30 distinct days, and the account still shows a monthly cost. No runbook job has run and no update deployment has fired, so whatever the account bills for is not being used.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1374 |
| Category | idle |
| Severity | low |
| Metric | TotalJob, TotalUpdateDeploymentRuns |
| Threshold | both = 0 |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.Automation/automationAccounts/read · Microsoft.Automation/automationAccounts/jobs/read · Microsoft.Insights/Metrics/Read |
Where it applies
What an Automation account is charged for
Azure Automation pricing splits the service into process automation, billed per job run-time minute for runbooks and per hour for watchers, and configuration management, billed per registered node. Each month includes free units, such as 500 job run-time minutes, and only usage above them is charged. Configuration management charges start when a node is registered and stop only when it is unregistered.
That makes an abandoned account easy to miss: the runbooks stopped, but a watcher or a set of registered nodes can keep billing long after anyone looked at it.
Checking job and update activity
az automation account list --query "[].{name:name, rg:resourceGroup, location:location}" -o table
az monitor metrics list --resource <automation-account-resource-id> \ --metric TotalJob TotalUpdateDeploymentRuns --offset 30d --interval PT24H --aggregation TotalTotalJob counts runbook jobs; TotalUpdateDeploymentRuns counts update deployment runs.
Zero on both, every day, is the idle pattern. az automation account commands come from the
Azure CLI automation extension.
What has to be zero, and for how long
- Both metric series are present for the account.
- Both read zero, on average and on peak, across the 30-day window.
- Each series spans at least 30 distinct days, so a new account is not judged on a few days.
- The account has a known monthly cost above zero.
The update deployment series matters: an account that runs no runbooks but still orchestrates patching is working, and is not flagged.
When the account is left alone
A single job or update run in the window ends the check. So does a missing metric or a history shorter than 30 days; ZopNight does not treat absent data as inactivity. An account with no cost in ZopNight’s billing data has nothing to save and produces no finding.
Saving is the account’s whole charge
saving = current monthly cost attributed to the Automation accountcost after fix = 0Cleaning up an idle Automation account
- In the portal, open the account and review Runbooks, Schedules, Watcher tasks and any registered nodes to see what it was set up for.
- Export runbooks you may want again (portal: the runbook, then Export).
- Unregister nodes and remove watchers if you want to keep the account for later use.
- Otherwise delete it:
az automation account delete --resource-group my-rg --name my-automation.