Azure Web and Mobile built-in role

Azure Spring Cloud Service Registry Reader

Reads user-application registration information from the managed Spring Cloud Service Registry through one DataAction and has no control-plane Actions. Azure Spring Apps retires on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: cff1b556-2399-4e7e-856d-a8f754be7b65

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the existing Azure Spring Apps service instance whose registrations the principal must inspect. Parent assignments are inherited by additional instances; service-instance scope limits discovery metadata access to one retiring deployment.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure Spring Cloud Service Registry Reader directly on the existing service instance to the external workload or migration reviewer that needs registration metadata. Use Contributor only for approved registration writes or deletes, and remove the role when migration validation is complete.

Related roles (1)

Common questions

When should I assign the Azure Spring Cloud Service Registry Reader Azure role?

Assign Azure Spring Cloud Service Registry Reader when you need to: Allow an external application, monitoring process, user, service principal, or managed identity to inspect registered applications through Microsoft Entra token authentication.; and Validate service-discovery registrations while migrating an existing Basic or Standard Azure Spring Apps workload.. Practical scope: Assign on the existing Azure Spring Apps service instance whose registrations the principal must inspect. Parent assignments are inherited by additional instances; service-instance scope limits discovery metadata access to one retiring deployment.

What permissions does the Azure Spring Cloud Service Registry Reader Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.AppPlatform/Spring/eurekaService/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Spring Cloud Service Registry Reader Azure role?

Key considerations when assigning Azure Spring Cloud Service Registry Reader: Registration information can expose application names, instances, and service-discovery topology even though the role cannot alter registrations.; The role does not manage the Spring Apps resource or write registry data, but a parent-scope assignment exposes discovery metadata across inherited instances.; and Retaining access after migration leaves unnecessary visibility on a service approaching retirement.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →