Azure Web and Mobile built-in role

Azure Spring Apps Application Configuration Service Log Reader Role

Streams real-time logs from documented Application Configuration Service subcomponents. It combines control-plane reads for the Azure Spring Apps instance and configuration service with a log-streaming DataAction. The logging workflow remains documented, but Application Configuration Service reached end of support on August 31, 2025, and Azure Spring Apps retires on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 6593e776-2a30-40f9-8a32-4fe28b77655d

Control-plane actions (2)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The documented assignment is on the existing Azure Spring Apps service instance. Parent-scope assignments are inherited by other instances, while service-instance scope limits managed-component log access to the one retiring deployment being diagnosed.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign the role directly on the existing Azure Spring Apps service instance to the principal troubleshooting Application Configuration Service. Keep the endpoint private or network-filtered, use the stream only for the diagnostic window, and remove the assignment when troubleshooting is complete.

Common questions

When should I assign the Azure Spring Apps Application Configuration Service Log Reader Role Azure role?

Assign Azure Spring Apps Application Configuration Service Log Reader Role when you need to: Stream logs from the application-configuration-service subcomponent while troubleshooting an existing Enterprise-plan instance.; and Stream flux-source-controller logs for an ACS Gen2 instance, where Microsoft documents that subcomponent as supported by the managed-component log workflow.. Practical scope: The documented assignment is on the existing Azure Spring Apps service instance. Parent-scope assignments are inherited by other instances, while service-instance scope limits managed-component log access to the one retiring deployment being diagnosed.

What permissions does the Azure Spring Apps Application Configuration Service Log Reader Role Azure role grant?

The role definition grants 3 combined control-plane and data-plane actions. Representative operations include: Microsoft.AppPlatform/Spring/read; Microsoft.AppPlatform/Spring/configurationServices/read; and Microsoft.AppPlatform/Spring/ApplicationConfigurationService/logstream/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Spring Apps Application Configuration Service Log Reader Role Azure role?

Key considerations when assigning Azure Spring Apps Application Configuration Service Log Reader Role: The role exposes real-time log output from the documented Application Configuration Service subcomponents even though it cannot alter the component.; Enabling the log-streaming public endpoint adds a public inbound IP to a virtual network and requires network filtering in addition to Azure RBAC authentication.; and The component no longer receives updates or customer support and may be removed if a critical vulnerability is detected; retaining log access does not change that lifecycle status.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →