Azure Web and Mobile built-in role

Azure Spring Cloud Config Server Reader

Reads content from the managed Spring Cloud Config Server through one DataAction and has no control-plane Actions. Azure Spring Apps Basic, Standard, and Enterprise plans retire on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: d04c6db6-4947-4782-9e91-30a88feb7be7

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the existing Azure Spring Apps service instance whose Config Server content the principal must read. A parent assignment is inherited by additional service instances, while service-instance scope limits content access to one retiring deployment.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Spring Cloud Config Server Reader directly on the existing service instance to the external workload or migration reviewer that needs configuration content. Use Contributor only for approved writes or deletes, and remove the assignment when migration validation is complete.

Related roles (1)

Common questions

When should I assign the Azure Spring Cloud Config Server Reader Azure role?

Assign Azure Spring Cloud Config Server Reader when you need to: Let an external application, migration utility, user, service principal, or managed identity read managed Config Server content with a Microsoft Entra token.; and Inspect configuration content while validating migration from an existing Basic or Standard Azure Spring Apps deployment.. Practical scope: Assign on the existing Azure Spring Apps service instance whose Config Server content the principal must read. A parent assignment is inherited by additional service instances, while service-instance scope limits content access to one retiring deployment.

What permissions does the Azure Spring Cloud Config Server Reader Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.AppPlatform/Spring/configService/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Spring Cloud Config Server Reader Azure role?

Key considerations when assigning Azure Spring Cloud Config Server Reader: Centralized configuration can expose application topology, endpoints, feature state, or other sensitive operational values even though the role is read-only.; The role does not change Config Server content or manage the Spring Apps resource, but a parent-scope assignment exposes content across inherited instances.; and Retaining the role after migration leaves unnecessary read access on a service approaching retirement.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →