> For the complete documentation index, see [llms.txt](https://docs.realmjoin.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.realmjoin.com/automation/connecting-azure-automation/required-permissions.md).

# Runbook Management App Permissions

How RealmJoin authenticates against your Azure Automation Account, and which Azure permissions it needs to sync and run runbooks.

This page describes the permissions RealmJoin itself needs to interact with Azure Automation and runbooks.

See [Runbook Execution Requirements](/automation/connecting-azure-automation/azure-ad-roles-and-permissions.md) for the permissions that have to be granted to the Automation Account's managed identity so the runbooks are useful in your environment — those are a separate set.

## RealmJoin Azure Resources

Tenants onboarded with the [RealmJoin PowerShell module](/automation/connecting-azure-automation.md) are accessed through RealmJoin's own multi-tenant application, **RealmJoin Azure Resources**. Running the setup creates a service principal for it in your tenant.

RealmJoin uses it to update the [Azure Automation runbooks](/automation/runbooks.md) in your tenant from [RealmJoin's shared runbook repository](https://github.com/realmjoin/realmjoin-runbooks), and to trigger runbook execution after filtering requests through [RealmJoin's RBAC](/administration-and-settings/permission.md) and [Runbook Permissions](/automation/runbooks/runbook-permissions.md).

The app has **no API permissions** in your tenant. There is no client secret on your side.

### Azure Resource Permissions

The service principal is granted **Contributor**, scoped to the Automation Account RealmJoin manages. It receives no permission on the surrounding resource group, on other resources, or on the subscription.

The same service principal is also used for the [Log Analytics](/monitoring-and-logs/log-analytics.md) integration, where it is granted its own, separate roles on the workspace and its data collection rules.

## RealmJoin Runbook Management (legacy)

Tenants configured before the PowerShell-based onboarding use an app registration called **RealmJoin Runbook Management**, created individually in your tenant. RealmJoin authenticates with its client ID and client secret, and the app is typically Contributor on the whole resource group hosting the Automation Account.

As this app is created individually for your tenant, there is no globally known Application ID as with [RealmJoin Portal's apps](/deployment/required-permissions.md). This app also has no API permissions.

{% hint style="info" %}
This path still works, but it means maintaining a client secret that expires. See [Switching to the RealmJoin managed app](/automation/connecting-azure-automation/managed-app-migration.md) to move over.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.realmjoin.com/automation/connecting-azure-automation/required-permissions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
