Azure Web and Mobile built-in role
Azure Spring Cloud Service Registry Reader
Reads user-application registration information from the managed Spring Cloud Service Registry through one DataAction and has no control-plane Actions. Azure Spring Apps retires on March 31, 2028.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: cff1b556-2399-4e7e-856d-a8f754be7b65
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (1)
Microsoft.AppPlatform/Spring/eurekaService/read
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the existing Azure Spring Apps service instance whose registrations the principal must inspect. Parent assignments are inherited by additional instances; service-instance scope limits discovery metadata access to one retiring deployment.
Common use cases (2)
- Allow an external application, monitoring process, user, service principal, or managed identity to inspect registered applications through Microsoft Entra token authentication.
- Validate service-discovery registrations while migrating an existing Basic or Standard Azure Spring Apps workload.
Prerequisites (2)
- An existing Basic or Standard Azure Spring Apps instance must expose the managed Service Registry endpoint; applications running inside the service normally use automatically injected platform certificates.
- The external principal must obtain a Microsoft Entra token and be approved to view application registration metadata.
Best practices (3)
- Use Reader rather than Service Registry Contributor when registration changes are unnecessary.
- Assign directly on the service instance, protect bearer tokens, and remove the assignment when monitoring or migration validation ends.
- Migrate service discovery off Azure Spring Apps before March 31, 2028.
Security considerations (3)
- Registration information can expose application names, instances, and service-discovery topology even though the role cannot alter registrations.
- The role does not manage the Spring Apps resource or write registry data, but a parent-scope assignment exposes discovery metadata across inherited instances.
- Retaining access after migration leaves unnecessary visibility on a service approaching retirement.
Assignment guidance
Assign Azure Spring Cloud Service Registry Reader directly on the existing service instance to the external workload or migration reviewer that needs registration metadata. Use Contributor only for approved registration writes or deletes, and remove the role when migration validation is complete.
Related roles (1)
- Azure Spring Cloud Service Registry Contributor: Adds write and delete access to managed Service Registry application registrations.
Editorial sources (7)
- Azure built-in roles for Web and Mobile - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Access Config Server and Service Registry →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure Spring Apps retirement announcement →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.