Azure Web and Mobile built-in role
Azure Spring Apps Job Log Reader Role
Reads Azure Spring Apps job and execution metadata through control-plane Actions and lists execution instances and streams their logs through DataActions. Azure Spring Apps retires on March 31, 2028.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: b459aa1d-e3c8-436f-ae21-c0531140f43e
Control-plane actions (3)
Microsoft.AppPlatform/Spring/readMicrosoft.AppPlatform/Spring/jobs/readMicrosoft.AppPlatform/Spring/jobs/executions/read
Data-plane actions (2)
Microsoft.AppPlatform/Spring/jobs/executions/logstream/actionMicrosoft.AppPlatform/Spring/jobs/executions/listInstances/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The documented assignment is on the existing Azure Spring Apps service instance. Service-instance scope covers jobs in that instance, while resource-group, subscription, and management-group assignments are inherited by jobs in additional Spring Apps instances.
Common use cases (2)
- List instances for an Azure Spring Apps job execution and stream their real-time logs during troubleshooting.
- Inspect job execution logs needed to stabilize or migrate an existing Enterprise-plan workload before service retirement.
Prerequisites (2)
- An existing Enterprise-plan Azure Spring Apps instance and job execution must be available, and Azure CLI must include the Azure Spring Apps extension.
- For a virtual-network-injected instance, access must originate from the private network unless a public data-plane endpoint is deliberately enabled and protected.
Best practices (3)
- Use real-time log streaming for operational troubleshooting and diagnostics settings for retained analysis.
- Assign directly on the service instance for the required period and filter network traffic if a public endpoint is enabled.
- Remove the assignment after diagnosis and migrate jobs off Azure Spring Apps before March 31, 2028.
Security considerations (3)
- Job logs can reveal execution inputs, failures, endpoints, and other operational details even though the role cannot change or start the job.
- Enabling a public data-plane endpoint adds public inbound reachability and requires network security controls in addition to Azure RBAC.
- A parent-scope assignment exposes job execution metadata and log streams across every inherited Spring Apps instance.
Assignment guidance
Assign Azure Spring Apps Job Log Reader Role directly on the existing service instance to the job operator or incident responder who needs real-time logs. Time-bound the access, secure any public endpoint, and remove the assignment when troubleshooting or migration validation ends.
Editorial sources (7)
- Azure built-in roles for Web and Mobile - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Stream Azure Spring Apps job logs in real time →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Azure Spring Apps retirement announcement →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.