Azure Integration built-in role

Azure API Center Service Contributor

Manages an Azure API Center service through the control plane, plus supporting deployments and alerts. Its service wildcard includes operations that return API security-requirement credentials. The role has no DataActions and excludes updating API analysis state. No deleted-service lifecycle behavior is asserted without current API Center product documentation.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: dd24193f-ef65-44e5-8a7e-6fa6e03f7713

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on an existing API center for service-specific administration. A direct resource assignment cannot authorize creation of another API center; the current creation quickstart requires Contributor or equivalent at the subscription and creates the service in a selected resource group.

Common use cases (2)

Prerequisites (4)

Best practices (2)

Security considerations (5)

Assignment guidance

Assign Azure API Center Service Contributor to the API catalog platform team directly on an existing API center only after accepting its API security-requirement credential authority. Use the parent-scope Contributor or equivalent documented by the creation quickstart when a new center must be created, and add Data Reader separately to portal consumers.

Related roles (3)

Common questions

When should I assign the Azure API Center Service Contributor Azure role?

Assign Azure API Center Service Contributor when you need to: Administer the catalog resources and configuration of one existing Azure API Center service.; and Configure the API center and its portal while assigning portal data access separately.. Practical scope: Assign on an existing API center for service-specific administration. A direct resource assignment cannot authorize creation of another API center; the current creation quickstart requires Contributor or equivalent at the subscription and creates the service in a selected resource group.

What permissions does the Azure API Center Service Contributor Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiCenter/services/*; Microsoft.ApiCenter/deletedServices/*; Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; Microsoft.ResourceHealth/availabilityStatuses/read; and Microsoft.Resources/deployments/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure API Center Service Contributor Azure role?

Key considerations when assigning Azure API Center Service Contributor: The role can change or delete API Center service records and supporting deployments within its effective scope.; The `Microsoft.ApiCenter/services/*` wildcard includes current `securityRequirements/getCredentials/action` operations at service and workspace API paths.; The role definition lists deleted-service operations, but current API Center product documentation reviewed for this pass does not establish a recovery or purge workflow; no lifecycle behavior is inferred from those operation strings.; and It has no API Center DataActions and its published exclusion prevents analysis-state updates.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →