Azure Web and Mobile built-in role

Azure Spring Apps Connect Role

Opens an authenticated shell connection to an Azure Spring Apps application instance for advanced troubleshooting. The role has one data-plane connect DataAction and no control-plane Actions. Azure Spring Apps is in retirement and is scheduled to retire on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 80558df3-64f9-4c0f-b32d-e5094b036b0b

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Microsoft documents assignment on the existing Azure Spring Apps service instance. That assignment permits connection to app deployments in the instance; assigning at a parent resource group, subscription, or management group is inherited by additional service instances.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Spring Apps Connect Role directly on the service instance to a named incident responder or migration engineer for a documented window. Remove it immediately after the shell session and use the retirement plan to eliminate the continuing need for access.

Common questions

When should I assign the Azure Spring Apps Connect Role Azure role?

Assign Azure Spring Apps Connect Role when you need to: Run JDK and common Linux diagnostic tools inside an existing application instance to investigate memory, CPU, storage, network latency, or back-end connectivity.; and Perform time-bounded shell troubleshooting needed to stabilize or migrate an Azure Spring Apps workload before retirement.. Practical scope: Microsoft documents assignment on the existing Azure Spring Apps service instance. That assignment permits connection to app deployments in the instance; assigning at a parent resource group, subscription, or management group is inherited by additional service instances.

What permissions does the Azure Spring Apps Connect Role Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.AppPlatform/Spring/apps/deployments/connect/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Spring Apps Connect Role Azure role?

Key considerations when assigning Azure Spring Apps Connect Role: Shell access lets the principal inspect the running process, file system, environment, network connectivity, and runtime state available to the non-root application user.; The shell runs as non-root and blocks some Linux capabilities, but it can still expose application secrets and reach back-end services available to the workload.; and A parent-scope assignment extends connect authority to deployments in every inherited Azure Spring Apps service instance.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →