Azure Web and Mobile built-in role

Azure Spring Apps Application Configuration Service Config File Pattern Reader Role

Reads configuration content selected by an Application Configuration Service config-file pattern, while using control-plane reads to discover the Azure Spring Apps instance and configuration service. The content read is a DataAction. Application Configuration Service reached end of support on August 31, 2025, and Azure Spring Apps retires on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 25211fc6-dc78-40b6-b205-e4ac934fd9fd

Control-plane actions (2)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The documented assignment is on the existing Azure Spring Apps service instance. A resource-group, subscription, or management-group assignment is inherited by additional Spring Apps instances, so service-instance scope keeps configuration-content access bounded to one retiring deployment.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign the reader directly on the existing Azure Spring Apps service instance only to a principal that must read Application Configuration Service content for troubleshooting or migration validation. Record an expiry tied to that work and remove the assignment after the replacement configuration is validated.

Editorial sources (9)

Official Microsoft Learn documentation →