Azure Integration built-in role
Azure API Center Data Reader
Provides API Center data-plane reads, workspace search, and API specification export for the API Center portal. It has DataActions only and does not manage the API Center resource through Azure Resource Manager.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: c7244dfb-f447-457d-b2ba-3999044d1706
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (3)
Microsoft.ApiCenter/services/*/readMicrosoft.ApiCenter/services/workspaces/apis/versions/definitions/exportSpecification/actionMicrosoft.ApiCenter/services/workspaces/search/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign directly on the API center whose catalog the principal may search. Resource-group and subscription assignments are inherited by all API centers below them and expose each inherited catalog through the data plane.
Common use cases (2)
- Allow an authenticated developer or stakeholder to sign in to the API Center portal and discover APIs in one catalog.
- Let an API Center administrator use the portal data path without granting service write access.
Prerequisites (2)
- The API Center portal and Microsoft Entra sign-in must be configured, and the API center must contain catalog data to discover.
- Assign the role to each approved user or group; configuring the portal automatically assigns only the configuring user.
Best practices (2)
- Assign the role to a Microsoft Entra group scoped to the individual API center to simplify user lifecycle.
- Use Service Reader separately only when the same principal also needs Azure Resource Manager metadata for the API center.
Security considerations (2)
- The role exposes API catalog records, search results, and exportable API specifications through the data plane.
- It does not create or modify API Center resources and has no control-plane Actions.
Assignment guidance
Assign Azure API Center Data Reader to the approved portal-user group directly on the API center. Keep API Center resource administration and analysis-state updates on separate roles.
Related roles (2)
- Azure API Center Service Reader: Reads API Center resource metadata through the control plane rather than the portal data plane.
- Azure API Center Compliance Manager: Adds the control-plane analysis-state update operation that this data-plane reader does not have.
Editorial sources (6)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations, Related roles. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Set up and customize your API Center portal →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.