Azure Automation Hybrid Woker permission automatically removed

Carlo Berchtold 0 Reputation points
2025-08-08T07:54:19.86+00:00

We are experiencing a recurring issue with two installed instances of the Azure Automation Hybrid Worker extension. For several months, both extensions have exhibited the same behavior: approximately twice per month, the custom credential permissions are inexplicably removed from the following paths:

  • C:\ProgramData\AzureConnectedMachineAgent\Tokens — Read access
  • C:\Packages\Plugins\Microsoft.Azure.Automation.HybridWorker.HybridWorkerForWindows — Read and Execute access

The issue results in jobs being suspended.

Initially, we suspected this might be triggered by Windows Updates or extension upgrades, but after some checks, these events do not correlate with the permission resets. The root cause remains unclear, and the behavior appears to be non-deterministic and unrelated to any scheduled system or extension-level changes.

Azure Automation
Azure Automation
An Azure service that is used to automate, configure, and install updates across hybrid environments.
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.