Azure Web and Mobile built-in role

Azure Spring Apps Job Log Reader Role

Reads Azure Spring Apps job and execution metadata through control-plane Actions and lists execution instances and streams their logs through DataActions. Azure Spring Apps retires on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b459aa1d-e3c8-436f-ae21-c0531140f43e

Control-plane actions (3)

Data-plane actions (2)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The documented assignment is on the existing Azure Spring Apps service instance. Service-instance scope covers jobs in that instance, while resource-group, subscription, and management-group assignments are inherited by jobs in additional Spring Apps instances.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Spring Apps Job Log Reader Role directly on the existing service instance to the job operator or incident responder who needs real-time logs. Time-bound the access, secure any public endpoint, and remove the assignment when troubleshooting or migration validation ends.

Editorial sources (7)

Official Microsoft Learn documentation →