Azure Web and Mobile built-in role
Azure Spring Apps Application Configuration Service Log Reader Role
Streams real-time logs from documented Application Configuration Service subcomponents. It combines control-plane reads for the Azure Spring Apps instance and configuration service with a log-streaming DataAction. The logging workflow remains documented, but Application Configuration Service reached end of support on August 31, 2025, and Azure Spring Apps retires on March 31, 2028.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 6593e776-2a30-40f9-8a32-4fe28b77655d
Control-plane actions (2)
Microsoft.AppPlatform/Spring/readMicrosoft.AppPlatform/Spring/configurationServices/read
Data-plane actions (1)
Microsoft.AppPlatform/Spring/ApplicationConfigurationService/logstream/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The documented assignment is on the existing Azure Spring Apps service instance. Parent-scope assignments are inherited by other instances, while service-instance scope limits managed-component log access to the one retiring deployment being diagnosed.
Common use cases (2)
- Stream logs from the application-configuration-service subcomponent while troubleshooting an existing Enterprise-plan instance.
- Stream flux-source-controller logs for an ACS Gen2 instance, where Microsoft documents that subcomponent as supported by the managed-component log workflow.
Prerequisites (2)
- An existing Enterprise-plan Azure Spring Apps instance must still contain Application Configuration Service, and Azure CLI must have the Azure Spring Apps extension version 1.24.0 or later.
- For a virtual-network-injected instance, use private access by default; if a public log-stream endpoint is enabled, protect it with the documented network controls.
Best practices (3)
- Use diagnostics settings for ongoing analysis and reserve real-time log streaming for time-bounded troubleshooting.
- Keep log streaming private for virtual-network-injected instances when possible; if a public endpoint is unavoidable, filter inbound traffic with a network security group.
- Remove this assignment after diagnosis and migrate off Application Configuration Service rather than retaining access to a component that no longer receives updates or customer support.
Security considerations (3)
- The role exposes real-time log output from the documented Application Configuration Service subcomponents even though it cannot alter the component.
- Enabling the log-streaming public endpoint adds a public inbound IP to a virtual network and requires network filtering in addition to Azure RBAC authentication.
- The component no longer receives updates or customer support and may be removed if a critical vulnerability is detected; retaining log access does not change that lifecycle status.
Assignment guidance
Assign the role directly on the existing Azure Spring Apps service instance to the principal troubleshooting Application Configuration Service. Keep the endpoint private or network-filtered, use the stream only for the diagnostic window, and remove the assignment when troubleshooting is complete.
Editorial sources (8)
- Azure built-in roles for Web and Mobile - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Stream Azure Spring Apps managed component logs in real time →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Deprecation of Tanzu components →
Supports: Description, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Azure Spring Apps retirement announcement →
Supports: Description, Best practices. Retrieved 2026-07-17.