Azure Automation Runbook Execution via High-Privilege Managed Identity

Detects execution of Azure Automation runbook jobs by managed identities that have recently been assigned high-privilege roles (Owner, Contributor, or User Access Administrator). This behavior is indicative of potential privilege escalation or abuse of existing high-privilege identities to execute unauthorized automation tasks.