Azure Security built-in role

App Compliance Automation Reader

Provides control-plane read access intended for the App Compliance Automation Tool for Microsoft 365, with no write Actions or DataActions. Microsoft now marks this ACAT-specific role obsolete and directs customers to replace it with the Azure Reader role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ffc6bbe0-e443-4c3b-bf54-26581bb2f78e

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Existing assignments apply at the selected Azure scope and are inherited by child scopes. ACAT reports can reference resources in multiple subscriptions, so read access must cover each corresponding subscription for the report to appear; however, new assignments should use Azure Reader as Microsoft directs.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Replace this obsolete role with Azure Reader at the smallest scope that covers the ACAT report resources. Verify the report and download workflow, then remove the App Compliance Automation Reader assignment so the principal does not retain duplicate inherited access.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →