Azure Integration built-in role
Azure API Center Service Contributor
Manages an Azure API Center service through the control plane, plus supporting deployments and alerts. Its service wildcard includes operations that return API security-requirement credentials. The role has no DataActions and excludes updating API analysis state. No deleted-service lifecycle behavior is asserted without current API Center product documentation.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: dd24193f-ef65-44e5-8a7e-6fa6e03f7713
Control-plane actions (7)
Microsoft.ApiCenter/services/*Microsoft.ApiCenter/deletedServices/*Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (1)
Microsoft.ApiCenter/services/workspaces/apis/versions/definitions/updateAnalysisState/action
Assignable scopes (1)
/
Practical scope
Assign on an existing API center for service-specific administration. A direct resource assignment cannot authorize creation of another API center; the current creation quickstart requires Contributor or equivalent at the subscription and creates the service in a selected resource group.
Common use cases (2)
- Administer the catalog resources and configuration of one existing Azure API Center service.
- Configure the API center and its portal while assigning portal data access separately.
Prerequisites (4)
- The principal must be responsible for the API Center resource and catalog lifecycle rather than only catalog consumption.
- Create the API center with Contributor or equivalent parent-scope permissions as documented by the current quickstart before narrowing ongoing administration to the service resource.
- Portal users require their documented Data Reader assignment separately.
- The service administrator must be approved to retrieve credentials stored for API security requirements within the assigned API center.
Best practices (2)
- Assign on one API center and use Service Reader for observers or Data Reader for portal users.
- Protect credentials returned by API security-requirement operations and avoid parent scope when the administrator owns only one API center.
Security considerations (5)
- The role can change or delete API Center service records and supporting deployments within its effective scope.
- The `Microsoft.ApiCenter/services/*` wildcard includes current `securityRequirements/getCredentials/action` operations at service and workspace API paths.
- The role definition lists deleted-service operations, but current API Center product documentation reviewed for this pass does not establish a recovery or purge workflow; no lifecycle behavior is inferred from those operation strings.
- It has no API Center DataActions and its published exclusion prevents analysis-state updates.
- The published supporting Actions include `Microsoft.Insights/alertRules/*`; a parent-scope assignment extends that classic alert-rule wildcard to matching resources throughout the effective scope.
Assignment guidance
Assign Azure API Center Service Contributor to the API catalog platform team directly on an existing API center only after accepting its API security-requirement credential authority. Use the parent-scope Contributor or equivalent documented by the creation quickstart when a new center must be created, and add Data Reader separately to portal consumers.
Related roles (3)
- Azure API Center Service Reader: Provides control-plane observation without service changes.
- Azure API Center Data Reader: Provides portal data-plane search and specification access.
- Azure API Center Compliance Manager: Provides the analysis-state operation excluded from Service Contributor.
Editorial sources (8)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations, Related roles. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Set up and customize your API Center portal →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Quickstart: Create your API center - Azure portal →
Supports: Practical scope, Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Permissions for Integration - Microsoft.ApiCenter →
Supports: Description, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.