Azure Security built-in role
App Compliance Automation Reader
Provides control-plane read access intended for the App Compliance Automation Tool for Microsoft 365, with no write Actions or DataActions. Microsoft now marks this ACAT-specific role obsolete and directs customers to replace it with the Azure Reader role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: ffc6bbe0-e443-4c3b-bf54-26581bb2f78e
Control-plane actions (1)
*/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Existing assignments apply at the selected Azure scope and are inherited by child scopes. ACAT reports can reference resources in multiple subscriptions, so read access must cover each corresponding subscription for the report to appear; however, new assignments should use Azure Reader as Microsoft directs.
Common use cases (2)
- Temporarily support an existing ACAT read-only assignment while it is being inventoried and replaced.
- View assessments or download compliance reports only until the documented migration to Azure Reader is complete.
Prerequisites (3)
- Confirm that the principal needs only read operations and identify all subscriptions represented in the compliance report.
- Plan replacement with Azure Reader because Microsoft documents App Compliance Automation Reader as obsolete.
- The migration administrator needs Microsoft.Authorization/roleAssignments/write to add Azure Reader and Microsoft.Authorization/roleAssignments/delete to remove the obsolete assignment.
Best practices (3)
- Do not create new App Compliance Automation Reader assignments; use Azure Reader for the documented read-only workflow.
- Inventory and remove existing assignments after equivalent Azure Reader access is verified.
- Keep the replacement scope no broader than the subscriptions and resources whose ACAT reports the principal must inspect.
Security considerations (3)
- The wildcard read permission can expose control-plane configuration for every resource type in the assigned scope.
- The role has no DataActions and cannot directly read workload data through Azure RBAC data-plane permissions.
- Obsolete assignments can persist unnoticed and create duplicate cumulative access after Azure Reader is added unless the old role is removed.
Assignment guidance
Replace this obsolete role with Azure Reader at the smallest scope that covers the ACAT report resources. Verify the report and download workflow, then remove the App Compliance Automation Reader assignment so the principal does not retain duplicate inherited access.
Related roles (1)
- Reader: Microsoft explicitly directs customers to replace the obsolete App Compliance Automation Reader role with Azure Reader.
Editorial sources (6)
- Azure built-in roles for Security →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Troubleshooting guide for ACAT →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Remove Azure role assignments →
Supports: Prerequisites, Best practices, Assignment guidance. Retrieved 2026-07-16.