Azure Web and Mobile built-in role
Azure Spring Apps Application Configuration Service Config File Pattern Reader Role
Reads configuration content selected by an Application Configuration Service config-file pattern, while using control-plane reads to discover the Azure Spring Apps instance and configuration service. The content read is a DataAction. Application Configuration Service reached end of support on August 31, 2025, and Azure Spring Apps retires on March 31, 2028.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 25211fc6-dc78-40b6-b205-e4ac934fd9fd
Control-plane actions (2)
Microsoft.AppPlatform/Spring/readMicrosoft.AppPlatform/Spring/configurationServices/read
Data-plane actions (1)
Microsoft.AppPlatform/Spring/ApplicationConfigurationService/read
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The documented assignment is on the existing Azure Spring Apps service instance. A resource-group, subscription, or management-group assignment is inherited by additional Spring Apps instances, so service-instance scope keeps configuration-content access bounded to one retiring deployment.
Common use cases (2)
- Read repository-backed configuration content supplied by Application Configuration Service while troubleshooting an existing Enterprise-plan application.
- Review existing configuration content and patterns while validating the documented migration to Config Server for Spring in Azure Container Apps.
Prerequisites (2)
- An existing Azure Spring Apps Enterprise instance must have Application Configuration Service enabled and a configuration service and app binding already configured.
- For the Container Apps migration workflow, an Azure Container Apps environment, a Config Server for Spring component, and a target container app must be planned in addition to the existing Application Configuration Service instance.
Best practices (3)
- Do not establish new long-lived reliance on Application Configuration Service; migrate to Config Server for Spring in Azure Container Apps or another supported replacement.
- Assign the role only for the transition window on the individual service instance and remove it after configuration validation or migration.
- Treat retrieved configuration as potentially sensitive and avoid copying configuration content into tickets, chat, or unprotected logs.
Security considerations (3)
- The DataAction exposes the configuration-file content that Application Configuration Service pulled from upstream Git repositories, including content that can also be exported to a local folder.
- Application Configuration Service no longer receives updates or customer support, and Microsoft reserves the right to remove it if a critical vulnerability is detected.
- A parent-scope assignment exposes configuration content from every inherited Azure Spring Apps instance where the component remains present.
Assignment guidance
Assign the reader directly on the existing Azure Spring Apps service instance only to a principal that must read Application Configuration Service content for troubleshooting or migration validation. Record an expiry tied to that work and remove the assignment after the replacement configuration is validated.
Editorial sources (9)
- Azure built-in roles for Web and Mobile - Azure RBAC | Microsoft Learn →
Supports: Description, Common use cases, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Use Application Configuration Service for Tanzu →
Supports: Description, Practical scope, Common use cases, Prerequisites, Security considerations. Retrieved 2026-07-17.
- Migrate Application Configuration Service to Config Server for Spring in Azure Container Apps →
Supports: Common use cases, Prerequisites, Best practices, Assignment guidance. Retrieved 2026-07-17.
- Deprecation of Tanzu components →
Supports: Description, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Azure Spring Apps retirement announcement →
Supports: Description, Best practices. Retrieved 2026-07-17.