Azure Web and Mobile built-in role

Azure Spring Apps Application Configuration Service Log Reader Role

Streams real-time logs from documented Application Configuration Service subcomponents. It combines control-plane reads for the Azure Spring Apps instance and configuration service with a log-streaming DataAction. The logging workflow remains documented, but Application Configuration Service reached end of support on August 31, 2025, and Azure Spring Apps retires on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 6593e776-2a30-40f9-8a32-4fe28b77655d

Control-plane actions (2)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The documented assignment is on the existing Azure Spring Apps service instance. Parent-scope assignments are inherited by other instances, while service-instance scope limits managed-component log access to the one retiring deployment being diagnosed.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign the role directly on the existing Azure Spring Apps service instance to the principal troubleshooting Application Configuration Service. Keep the endpoint private or network-filtered, use the stream only for the diagnostic window, and remove the assignment when troubleshooting is complete.

Editorial sources (8)

Official Microsoft Learn documentation →