Azure Integration built-in role
API Management Developer Portal Content Editor
Customizes, edits, and publishes API Management developer portal content through Azure Resource Manager. The published role contains control-plane Actions only and no DataActions; it does not provide general API, policy, or service-infrastructure administration.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: c031e6a8-4391-4de0-8d69-4706a7ed3729
Control-plane actions (8)
Microsoft.ApiManagement/service/portalRevisions/readMicrosoft.ApiManagement/service/portalRevisions/writeMicrosoft.ApiManagement/service/contentTypes/readMicrosoft.ApiManagement/service/contentTypes/deleteMicrosoft.ApiManagement/service/contentTypes/writeMicrosoft.ApiManagement/service/contentTypes/contentItems/readMicrosoft.ApiManagement/service/contentTypes/contentItems/writeMicrosoft.ApiManagement/service/contentTypes/contentItems/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual API Management service whose developer portal the editor maintains. A resource-group or subscription assignment is inherited by every API Management service below it and broadens portal publishing authority accordingly.
Common use cases (2)
- Let a web-content team maintain and publish developer portal pages without granting API Management Service Contributor.
- Manage developer portal revisions and content items for one approved API Management instance.
Prerequisites (2)
- The API Management service and developer portal must already exist, and the assignee must be approved to publish externally visible portal content.
- API, product, policy, and service-infrastructure changes must remain with separately authorized API Management administrators.
Best practices (2)
- Assign directly on one API Management service and keep API or service administration on separate roles.
- Use a reviewed publishing workflow for portal revisions and verify links, authentication instructions, and exposed content before publication.
Security considerations (2)
- Published portal content is customer- or developer-facing and can change how API consumers discover and use APIs.
- The role does not grant runtime API access or general API Management service administration, and it has no data-plane permissions.
Assignment guidance
Assign API Management Developer Portal Content Editor to the portal content group on the specific API Management service. Use Service Reader for service-wide observation and Service Contributor only when the same principal genuinely administers APIs and service infrastructure.
Related roles (2)
- API Management Service Contributor: The broader service role manages API Management services and entities in addition to developer portal content.
- API Management Service Reader Role: Provides service and API visibility without portal content publishing authority.
Editorial sources (6)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- How to use role-based access control in Azure API Management →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.