Skip to main content
idle · azure

Azure Automation accounts that ran no jobs and no update deployments for 30 days

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an Azure Automation account when both its `TotalJob` and `TotalUpdateDeploymentRuns` metrics stay at zero across at least 30 distinct days, and the account still shows a monthly cost. No runbook job has run and no update deployment has fired, so whatever the account bills for is not being used.

Signal and threshold

How ZopNight evaluates Azure Automation accounts that ran no jobs and no update deployments for 30 days.
Field Value
Rule IDsRC-1374
Categoryidle
Severitylow
MetricTotalJob, TotalUpdateDeploymentRuns
Thresholdboth = 0
Evaluation window30d
SourceZopNight
Permissions usedMicrosoft.Automation/automationAccounts/read · Microsoft.Automation/automationAccounts/jobs/read · Microsoft.Insights/Metrics/Read

What an Automation account is charged for

Azure Automation pricing splits the service into process automation, billed per job run-time minute for runbooks and per hour for watchers, and configuration management, billed per registered node. Each month includes free units, such as 500 job run-time minutes, and only usage above them is charged. Configuration management charges start when a node is registered and stop only when it is unregistered.

That makes an abandoned account easy to miss: the runbooks stopped, but a watcher or a set of registered nodes can keep billing long after anyone looked at it.

Checking job and update activity

Terminal window
az automation account list --query "[].{name:name, rg:resourceGroup, location:location}" -o table
az monitor metrics list --resource <automation-account-resource-id> \
--metric TotalJob TotalUpdateDeploymentRuns --offset 30d --interval PT24H --aggregation Total

TotalJob counts runbook jobs; TotalUpdateDeploymentRuns counts update deployment runs. Zero on both, every day, is the idle pattern. az automation account commands come from the Azure CLI automation extension.

What has to be zero, and for how long

  1. Both metric series are present for the account.
  2. Both read zero, on average and on peak, across the 30-day window.
  3. Each series spans at least 30 distinct days, so a new account is not judged on a few days.
  4. The account has a known monthly cost above zero.

The update deployment series matters: an account that runs no runbooks but still orchestrates patching is working, and is not flagged.

When the account is left alone

A single job or update run in the window ends the check. So does a missing metric or a history shorter than 30 days; ZopNight does not treat absent data as inactivity. An account with no cost in ZopNight’s billing data has nothing to save and produces no finding.

Saving is the account’s whole charge

Terminal window
saving = current monthly cost attributed to the Automation account
cost after fix = 0

Cleaning up an idle Automation account

  1. In the portal, open the account and review Runbooks, Schedules, Watcher tasks and any registered nodes to see what it was set up for.
  2. Export runbooks you may want again (portal: the runbook, then Export).
  3. Unregister nodes and remove watchers if you want to keep the account for later use.
  4. Otherwise delete it: az automation account delete --resource-group my-rg --name my-automation.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·