Azure Web and Mobile built-in role

Azure Spring Apps Application Configuration Service Config File Pattern Reader Role

Reads configuration content selected by an Application Configuration Service config-file pattern, while using control-plane reads to discover the Azure Spring Apps instance and configuration service. The content read is a DataAction. Application Configuration Service reached end of support on August 31, 2025, and Azure Spring Apps retires on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 25211fc6-dc78-40b6-b205-e4ac934fd9fd

Control-plane actions (2)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The documented assignment is on the existing Azure Spring Apps service instance. A resource-group, subscription, or management-group assignment is inherited by additional Spring Apps instances, so service-instance scope keeps configuration-content access bounded to one retiring deployment.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign the reader directly on the existing Azure Spring Apps service instance only to a principal that must read Application Configuration Service content for troubleshooting or migration validation. Record an expiry tied to that work and remove the assignment after the replacement configuration is validated.

Common questions

When should I assign the Azure Spring Apps Application Configuration Service Config File Pattern Reader Role Azure role?

Assign Azure Spring Apps Application Configuration Service Config File Pattern Reader Role when you need to: Read repository-backed configuration content supplied by Application Configuration Service while troubleshooting an existing Enterprise-plan application.; and Review existing configuration content and patterns while validating the documented migration to Config Server for Spring in Azure Container Apps.. Practical scope: The documented assignment is on the existing Azure Spring Apps service instance. A resource-group, subscription, or management-group assignment is inherited by additional Spring Apps instances, so service-instance scope keeps configuration-content access bounded to one retiring deployment.

What permissions does the Azure Spring Apps Application Configuration Service Config File Pattern Reader Role Azure role grant?

The role definition grants 3 combined control-plane and data-plane actions. Representative operations include: Microsoft.AppPlatform/Spring/read; Microsoft.AppPlatform/Spring/configurationServices/read; and Microsoft.AppPlatform/Spring/ApplicationConfigurationService/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Spring Apps Application Configuration Service Config File Pattern Reader Role Azure role?

Key considerations when assigning Azure Spring Apps Application Configuration Service Config File Pattern Reader Role: The DataAction exposes the configuration-file content that Application Configuration Service pulled from upstream Git repositories, including content that can also be exported to a local folder.; Application Configuration Service no longer receives updates or customer support, and Microsoft reserves the right to remove it if a critical vulnerability is detected.; and A parent-scope assignment exposes configuration content from every inherited Azure Spring Apps instance where the component remains present.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (9)

Official Microsoft Learn documentation →