Azure Integration built-in role

API Management Service Contributor

Provides full control-plane administration for API Management services and entities, including APIs and policies. Its `Microsoft.ApiManagement/service/*` wildcard includes current secret- and key-returning operations across service and workspace entities; it has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 312a565d-c81f-4fd8-895a-4e21e48d571c

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on an existing API Management service when the administrator manages only that instance. Creating a new instance or recovering a soft-deleted instance addresses a service resource under a resource group, so create-or-update authority must be inherited from the resource group or a parent scope; an assignment only on an existing instance does not authorize those parent-scope lifecycle operations.

Common use cases (3)

Prerequisites (3)

Best practices (3)

Security considerations (5)

Assignment guidance

Reserve API Management Service Contributor for API platform administrators who are approved for all documented service and workspace secret/key operations. Assign it on an existing service for service-and-API administration; use a dedicated resource-group assignment only when the same principal must create or recover the instance. Use Operator for service infrastructure without API entity changes, Reader for observation, and workspace roles for delegated teams.

Related roles (3)

Editorial sources (9)

Official Microsoft Learn documentation →