Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
powershell_heavy
windows_tools
missing_linux_example
windows_first
Summary
The documentation page exclusively uses PowerShell scripts and cmdlets (Connect-AzAccount, Get-AzResourceGroup, etc.) for all examples and migration steps, which are native to Windows and commonly used in Windows environments. There is no mention of Linux shell equivalents (such as Azure CLI/bash), nor are there examples for Linux-based automation workers. All tooling and migration scripts referenced are PowerShell-based, and the workflow assumes familiarity with Windows/PowerShell patterns. No Linux-first or cross-platform guidance is provided.
Recommendations
  • Add equivalent Azure CLI (az) examples for authentication and resource management using managed identities, suitable for Linux and cross-platform environments.
  • Include guidance and sample scripts for runbooks written in Python or Bash, which are supported in Azure Automation and commonly used on Linux.
  • Explicitly mention how Linux-based hybrid runbook workers can authenticate using managed identities, with step-by-step instructions.
  • Reference cross-platform tools and patterns (such as az CLI, REST API usage) alongside PowerShell, and avoid assuming PowerShell as the default.
  • Reorder examples or provide tabs for both Windows/PowerShell and Linux/CLI approaches, ensuring parity and discoverability for Linux users.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-13 06:17 #107 completed Biased Biased
2026-01-12 00:00 #99 completed Biased Biased
2026-01-11 06:20 #98 completed Biased Biased
2026-01-11 00:00 #95 cancelled Clean Clean
2026-01-10 00:00 #92 completed Biased Biased
2026-01-09 00:00 #87 cancelled Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-29 18:00 #48 cancelled Biased Biased
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean

Flagged Code Snippets

---

### View client ID of user assigned identity

1. In your Automation account, under **Account Settings**, select **Identity**. 
1. In **User assigned** tab, select user assigned identity.

    :::image type="content" source="./media/migrate-run-as-account-managed-identity/user-assigned-inline.png" alt-text="Screenshot that shows the navigation path to view client ID." lightbox="./media/migrate-run-as-account-managed-identity/user-assigned-expanded.png":::

1. Go to **Overview**> **Essentials**, to view the **Client ID**.

    :::image type="content" source="./media/migrate-run-as-account-managed-identity/view-client-id-inline.png" alt-text="Screenshot that shows how to view a client ID." lightbox="./media/migrate-run-as-account-managed-identity/view-client-id-expanded.png":::


## Graphical runbooks

### Check if a Run As account is used in graphical runbooks

1. Check each of the activities within the runbook to see if it uses the Run As account when it calls any logon cmdlets or aliases, such as `Add-AzRmAccount/Connect-AzRmAccount/Add-AzAccount/Connect-AzAccount`.
    
    :::image type="content" source="./media/migrate-run-as-account-managed-identity/check-graphical-runbook-use-run-as-inline.png" alt-text="Screenshot that illustrates checking if a graphical runbook uses a Run As account." lightbox="./media/migrate-run-as-account-managed-identity/check-graphical-runbook-use-run-as-expanded.png":::

1. Examine the parameters that the cmdlet uses.

    :::image type="content" source="./media/migrate-run-as-account-managed-identity/activity-parameter-configuration.png" alt-text="Screenshot that shows examining the parameters used by a cmdlet.":::

    For use with the Run As account, the cmdlet uses the `ServicePrincipalCertificate` parameter set to `ApplicationId`. `CertificateThumbprint` will be from `RunAsAccountConnection`.

    :::image type="content" source="./media/migrate-run-as-account-managed-identity/parameter-sets-inline.png" alt-text="Screenshot that shows parameter sets." lightbox="./media/migrate-run-as-account-managed-identity/parameter-sets-expanded.png":::
 
### Edit a graphical runbook to use a managed identity

You must test the managed identity to verify that the graphical runbook is working as expected. Create a copy of your production runbook to use the managed identity, and then update your test graphical runbook code to authenticate by using the managed identity. You can add this functionality to a graphical runbook by adding the `Connect-AzAccount` cmdlet.

The following steps include an example to show how a graphical runbook that uses a Run As account can use managed identities:

1. Sign in to the [Azure portal](https://portal.azure.com).
1. Open the Automation account, and then select **Process Automation** > **Runbooks**.
1. Select a runbook. For example, select the **Start Azure V2 VMs** runbook from the list, and then select **Edit** or go to **Browse Gallery** and select **Start Azure V2 VMs**.

    :::image type="content" source="./media/migrate-run-as-account-managed-identity/edit-graphical-runbook-inline.png" alt-text="Screenshot of editing a graphical runbook." lightbox="./media/migrate-run-as-account-managed-identity/edit-graphical-runbook-expanded.png":::

1. Replace the Run As connection that uses `AzureRunAsConnection` and the connection asset that internally uses the PowerShell `Get-AutomationConnection` cmdlet with the `Connect-AzAccount` cmdlet.

1. Select **Delete** to delete the `Get Run As Connection` and `Connect to Azure` activities.
    
    :::image type="content" source="./media/migrate-run-as-account-managed-identity/connect-azure-graphical-runbook-inline.png" alt-text="Screenshot to connect to the Azure activities." lightbox="./media/migrate-run-as-account-managed-identity/connect-azure-graphical-runbook-expanded.png":::
    
    
1. In the left panel, under **RUNBOOK CONTROL**, select **Code** and then select **Add to canvas**.

    :::image type="content" source="./media/migrate-run-as-account-managed-identity/add-canvas-graphical-runbook-inline.png" alt-text="Screenshot to select code and add it to the canvas." lightbox="./media/migrate-run-as-account-managed-identity/add-canvas-graphical-runbook-expanded.png":::

1. Edit the code activity, assign any appropriate label name, and select **Author activity logic**.

    :::image type="content" source="./media/migrate-run-as-account-managed-identity/author-activity-log-graphical-runbook-inline.png" alt-text="Screenshot to edit code activity." lightbox="./media/migrate-run-as-account-managed-identity/author-activity-log-graphical-runbook-expanded.png":::

1. In the **Code Editor** page, enter the following PowerShell code and select **OK**.