Quick answer: You can programmatically start and stop a managed dedicated Azure Data Factory integration runtime from an Azure Automation PowerShell runbook by using the Automation account’s system-assigned managed identity. Grant that identity the required Azure Data Factory RBAC permission, authenticate with Connect-AzAccount -Identity, and use the Az.DataFactory cmdlets to check, start, or stop the runtime. This article focuses on managed dedicated integration runtimes, including Azure-SSIS IR.

Prerequisites:
1. An Azure subscription containing an Azure Data Factory and Azure Automation account.
2. An Azure-SSIS or other managed dedicated integration runtime that you want to start and stop.
3. Permission to enable the Automation account managed identity and assign it the required role on the Data Factory.
4. The required Az.Automation and Az.DataFactory modules available in the Automation account.

How managed identity works with Azure Automation

Azure Automation can use a system-assigned managed identity to authenticate to Azure resources without storing a client secret, certificate, or Azure Automation Run As account credential. Microsoft recommends authenticating Automation runbooks with managed identity, and the older Run As account model has been retired.

System-assigned vs. user-assigned managed identity

A system-assigned managed identity is tied to the Automation account lifecycle. A user-assigned managed identity is a separate Azure resource that can be associated with the Automation account and reused across resources. This example uses the Automation account’s system-assigned identity because it is sufficient for the runbook scenario. For a broader comparison of the two identity types, see System-Assigned vs User-Assigned Managed Identity in Azure.

The identity itself does not grant access to the Data Factory. You must explicitly assign an appropriate Azure RBAC role on the target Data Factory and follow least-privilege access.

Enable the system-assigned managed identity for Azure Automation

1. Navigate to Azure automation account resource in Azure portal.

2. Click ‘Identity’ under ‘Account Settings’ as shown in the image below.

3. Under the System assigned tab, enable Status and click Save.

Enable managed identity of Azure automation account.

Available on Microsoft Store

SSRS Reports Migration Wizard

A simple Windows tool for migrating SSRS reports, data sources, and related configurations between report servers.

Grant the Automation identity access to Azure Data Factory

1. Navigate to Data Factory resource in Azure portal and Click on Access control (IAM). Click Add -> Add role assignment as shown in the image below.

programmatically start and stop Azure Data Factory integration runtime

2. Select Add > Add role assignment and choose an RBAC role that provides the permissions required by the runbook. For this example, the original article used Data Factory Contributor. Review the permissions in your environment and use a narrower custom role when practical rather than granting broader access than the runbook needs.

3. Under the Members tab, select ‘Managed Identity’. Search for the managed identity of Azure automation account to whom you want to grant access.

programmatically start and stop Azure Data Factory integration runtime

Create the PowerShell runbook

1. In the Automation account, open Shared resources > Modules and make sure the required Az modules are available. The runbook below uses Az.Accounts, Az.Automation, and Az.DataFactory.

2. Create ‘datafactory-name’ and ‘resourcegroup-name’ variables in the automation account and assign appropriate values to them.

3. Under Process Automation > Runbooks, create a PowerShell runbook and publish it after testing.

4. The following examples authenticate with the Automation account’s managed identity, retrieve the target integration runtime, and start or stop it based on its current state.

Stop the integration runtime

# Retrieve Automation variables
$DataFactoryName = (Get-AzAutomationVariable -Name 'datafactory-name').Value
$ResourceGroup = (Get-AzAutomationVariable -Name 'resourcegroup-name').Value

# Authenticate to Azure using the Automation account managed identity
Disable-AzContextAutosave -Scope Process
$AzureContext = (Connect-AzAccount -Identity).Context
$AzureContext = Set-AzContext -SubscriptionId $AzureContext.Subscription.Id -DefaultProfile $AzureContext

# Get the managed dedicated integration runtime
$IntegrationRuntime = Get-AzDataFactoryV2IntegrationRuntime -DataFactoryName $DataFactoryName -ResourceGroupName $ResourceGroup -Status
$IRStatus = $IntegrationRuntime.State
Write-Output "Current Integration Runtime State: $IRStatus"

if ($IRStatus -eq 'Started') {
    Stop-AzDataFactoryV2IntegrationRuntime -DataFactoryName $DataFactoryName -ResourceGroupName $ResourceGroup -Name $IntegrationRuntime.Name -Force
    Write-Output "Integration Runtime '$($IntegrationRuntime.Name)' has been stopped."
}
else {
    Write-Output "Integration Runtime '$($IntegrationRuntime.Name)' is not in Started state."
}

Start the integration runtime

# Retrieve Automation variables
$DataFactoryName = (Get-AzAutomationVariable -Name 'datafactory-name').Value
$ResourceGroup = (Get-AzAutomationVariable -Name 'resourcegroup-name').Value

# Authenticate to Azure using the Automation account managed identity
Disable-AzContextAutosave -Scope Process
$AzureContext = (Connect-AzAccount -Identity).Context
$AzureContext = Set-AzContext -SubscriptionId $AzureContext.Subscription.Id -DefaultProfile $AzureContext

# Get the managed dedicated integration runtime
$IntegrationRuntime = Get-AzDataFactoryV2IntegrationRuntime -DataFactoryName $DataFactoryName -ResourceGroupName $ResourceGroup -Status
$IRStatus = $IntegrationRuntime.State
Write-Output "Current Integration Runtime State: $IRStatus"

if ($IRStatus -eq 'Stopped') {
    Start-AzDataFactoryV2IntegrationRuntime -DataFactoryName $DataFactoryName -ResourceGroupName $ResourceGroup -Name $IntegrationRuntime.Name -Force
    Write-Output "Integration Runtime '$($IntegrationRuntime.Name)' is starting."
}
else {
    Write-Output "Integration Runtime '$($IntegrationRuntime.Name)' is not in Stopped state."
}

The runbook does not store an Azure username, password, service-principal secret, or certificate. Connect-AzAccount -Identity obtains the Azure context through the Automation account’s managed identity.

Schedule the runbook

After testing the runbook, create an Automation schedule and link it to the runbook. A common pattern is to stop an Azure-SSIS IR outside business hours and start it shortly before workloads need it. This can reduce runtime infrastructure costs, but account for startup time and any dependencies that require the IR to be available.

Important: The Start-AzDataFactoryV2IntegrationRuntime and Stop-AzDataFactoryV2IntegrationRuntime cmdlets operate on managed dedicated integration runtimes. They do not mean that every Data Factory integration runtime type can be started and stopped this way.

Troubleshooting

The runbook cannot authenticate

Use Connect-AzAccount -Identity rather than an interactive sign-in or a retired Run As account. Also verify that the Automation account managed identity is enabled and that the required Az.Accounts module is available to the runbook.

The runbook gets an authorization error

Check the Data Factory’s Access control (IAM) assignments for the Automation account’s managed identity. The identity must have the permissions required for the Data Factory operation. If the runbook manages multiple factories, grant access only to the required resources.

The runtime state does not change

Confirm that the target is a managed dedicated integration runtime and inspect its current state with Get-AzDataFactoryV2IntegrationRuntime -Status. Starting an IR provisions its resources, while stopping it releases those resources. Azure-SSIS IR startup can take several minutes and can take longer when virtual network injection or other configuration adds setup time.

Related Azure Data Factory automation guides

• Automate Azure Data Factory deployment with Azure DevOps
• Connect Azure SQL from Data Factory using managed identity
• Update an Azure Key Vault secret using PowerShell

Pro tips:
1. Use least-privilege RBAC for the Automation account managed identity rather than granting broad subscription-level access.
2. Azure Automation Run As accounts were retired on 30 September 2023; use managed identity for new and migrated runbooks.
3. Keep the Az modules used by the runbook current and test module updates before production rollout.

See more

Visual Studio Marketplace

SSIS Catalog Migration Wizard

Extend Visual Studio with an easy way to migrate SSIS Catalog projects.

Kunal Rathi

With over 15 years of experience in data engineering and analytics, I've assisted countless clients in gaining valuable insights from their data. As a dedicated supporter of Data, Cloud and DevOps, I'm excited to connect with individuals who share my passion for this field. If my work resonates with you, we can talk and collaborate.