Azure Security built-in role

App Compliance Automation Reader

Provides control-plane read access intended for the App Compliance Automation Tool for Microsoft 365, with no write Actions or DataActions. Microsoft now marks this ACAT-specific role obsolete and directs customers to replace it with the Azure Reader role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ffc6bbe0-e443-4c3b-bf54-26581bb2f78e

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Existing assignments apply at the selected Azure scope and are inherited by child scopes. ACAT reports can reference resources in multiple subscriptions, so read access must cover each corresponding subscription for the report to appear; however, new assignments should use Azure Reader as Microsoft directs.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Replace this obsolete role with Azure Reader at the smallest scope that covers the ACAT report resources. Verify the report and download workflow, then remove the App Compliance Automation Reader assignment so the principal does not retain duplicate inherited access.

Related roles (1)

Common questions

When should I assign the App Compliance Automation Reader Azure role?

Assign App Compliance Automation Reader when you need to: Temporarily support an existing ACAT read-only assignment while it is being inventoried and replaced.; and View assessments or download compliance reports only until the documented migration to Azure Reader is complete.. Practical scope: Existing assignments apply at the selected Azure scope and are inherited by child scopes. ACAT reports can reference resources in multiple subscriptions, so read access must cover each corresponding subscription for the report to appear; however, new assignments should use Azure Reader as Microsoft directs.

What permissions does the App Compliance Automation Reader Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: */read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the App Compliance Automation Reader Azure role?

Key considerations when assigning App Compliance Automation Reader: The wildcard read permission can expose control-plane configuration for every resource type in the assigned scope.; The role has no DataActions and cannot directly read workload data through Azure RBAC data-plane permissions.; and Obsolete assignments can persist unnoticed and create duplicate cumulative access after Azure Reader is added unless the old role is removed.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →