Azure Web and Mobile built-in role

Azure Spring Cloud Config Server Contributor

Reads, writes, and deletes content in the managed Spring Cloud Config Server through DataActions only. It does not manage the Azure Spring Apps resource through the control plane. Azure Spring Apps Basic, Standard, and Enterprise plans retire on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a06f5c24-21a7-4e1a-aa2b-f19eb6684f5b

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (3)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the existing Azure Spring Apps service instance whose managed Config Server the principal must access. A parent-scope assignment is inherited by Config Servers in additional Spring Apps instances, so service-instance scope is the practical boundary for one retiring deployment.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

For an existing external Config Server workflow, assign the Contributor directly on the Azure Spring Apps service instance to the application or migration identity that must change content. Use Reader for inspection-only access, document the migration deadline, and remove the assignment when the dependency is retired.

Related roles (1)

Editorial sources (7)

Official Microsoft Learn documentation →