Azure Integration built-in role

API Management Service Contributor

Provides full control-plane administration for API Management services and entities, including APIs and policies. Its `Microsoft.ApiManagement/service/*` wildcard includes current secret- and key-returning operations across service and workspace entities; it has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 312a565d-c81f-4fd8-895a-4e21e48d571c

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on an existing API Management service when the administrator manages only that instance. Creating a new instance or recovering a soft-deleted instance addresses a service resource under a resource group, so create-or-update authority must be inherited from the resource group or a parent scope; an assignment only on an existing instance does not authorize those parent-scope lifecycle operations.

Common use cases (3)

Prerequisites (3)

Best practices (3)

Security considerations (5)

Assignment guidance

Reserve API Management Service Contributor for API platform administrators who are approved for all documented service and workspace secret/key operations. Assign it on an existing service for service-and-API administration; use a dedicated resource-group assignment only when the same principal must create or recover the instance. Use Operator for service infrastructure without API entity changes, Reader for observation, and workspace roles for delegated teams.

Related roles (3)

Common questions

When should I assign the API Management Service Contributor Azure role?

Assign API Management Service Contributor when you need to: Administer the configuration of an existing API Management service together with its APIs, products, policies, and related entities.; Create or recover an API Management instance only when the principal has the required role at the containing resource group or a parent scope.; and Operate a central API platform where the same trusted team owns service configuration and API publication.. Practical scope: Assign on an existing API Management service when the administrator manages only that instance. Creating a new instance or recovering a soft-deleted instance addresses a service resource under a resource group, so create-or-update authority must be inherited from the resource group or a parent scope; an assignment only on an existing instance does not authorize those parent-scope lifecycle operations.

What permissions does the API Management Service Contributor Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiManagement/service/*; Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; Microsoft.ResourceHealth/availabilityStatuses/read; Microsoft.Resources/deployments/*; and Microsoft.Resources/subscriptions/resourceGroups/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the API Management Service Contributor Azure role?

Key considerations when assigning API Management Service Contributor: The role can change and delete an existing service and its API entities, policies, networking, domains, and scale configuration; at resource-group or subscription scope, the same authority applies to inherited API Management services and can support service creation or recovery.; Listing or purging soft-deleted API Management instances uses subscription-level deleted-service permissions documented separately; this role must not be described as granting that deleted-service authority.; The service wildcard directly includes documented secret retrieval for authorization servers, backends, client applications, identity and OpenID Connect providers, named values, portal settings, properties, tenant access, tool servers, and their workspace equivalents.; and It also includes documented gateway, subscription, tenant, and user key reads or regeneration. Microsoft separately warns that entity write access can reveal credentials in write responses even when a list-secrets operation is withheld.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (9)

Official Microsoft Learn documentation →