Azure Integration built-in role
API Management Service Operator Role
Manages API Management service infrastructure, including deletion, scaling, VPN, custom-domain, backup, restore, hostname, and certificate operations, while not granting write access to APIs and policies. Its service read wildcard excludes user-key reads but still includes the separate tenant-key read operation; the role has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: e022efe7-f5ba-4159-bbe4-b44f577e9b61
Control-plane actions (15)
Microsoft.ApiManagement/service/*/readMicrosoft.ApiManagement/service/backup/actionMicrosoft.ApiManagement/service/deleteMicrosoft.ApiManagement/service/managedeployments/actionMicrosoft.ApiManagement/service/readMicrosoft.ApiManagement/service/restore/actionMicrosoft.ApiManagement/service/updatecertificate/actionMicrosoft.ApiManagement/service/updatehostname/actionMicrosoft.ApiManagement/service/writeMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (1)
Microsoft.ApiManagement/service/users/keys/read
Assignable scopes (1)
/
Practical scope
Assign on an existing API Management service operated by the platform team. Creating a new instance or recovering a soft-deleted instance addresses a service under a resource group, so create-or-update authority must be inherited from the resource group or a parent scope; direct scope on an existing instance covers that instance only.
Common use cases (3)
- Let an infrastructure operations team scale, back up, restore, and maintain an API Management instance without editing its APIs or policies.
- Create or recover an API Management instance only when the operator role is assigned at the containing resource group or a parent scope.
- Separate service availability and network administration from API design and publication.
Prerequisites (4)
- For existing-service operations, the API Management service must already exist.
- For creation or soft-delete recovery, the principal needs the role at the containing resource group or a parent scope before the target service exists.
- Backup, restore, certificate, hostname, VPN, scaling, and deletion procedures must be approved and tested for the target service.
- The operator must be approved to retrieve API Management tenant keys within the assignment scope.
Best practices (3)
- Use this role instead of Service Contributor when the principal operates infrastructure but does not author APIs or policies.
- Assign directly on one service and protect destructive or availability-affecting operations with change control.
- Protect and rotate tenant keys exposed by the documented `service/tenants/keys/read` operation.
Security considerations (4)
- The role can delete, restore, scale, and reconfigure service networking, hostnames, and certificates, which can interrupt or redirect API traffic.
- Listing or purging soft-deleted instances uses subscription-level deleted-service permissions documented separately; this role does not include those permissions.
- It does not authorize API entity writes, user-key reads, or API data-plane access, but `Microsoft.ApiManagement/service/*/read` still matches the documented tenant-key read operation.
- The published supporting Actions also include `Microsoft.Insights/alertRules/*` and `Microsoft.Support/*`; a parent-scope assignment extends those wildcards to matching resources throughout the effective scope.
Assignment guidance
Assign API Management Service Operator Role on an existing API Management instance for service operations only after accepting its tenant-key read authority. Use a dedicated resource-group assignment only when the same group must create or recover the instance. Keep API and policy authoring with Service Contributor or workspace roles, and use Service Reader when no lifecycle operation is required.
Related roles (2)
- API Management Service Contributor: Adds full API entity and policy administration to service-lifecycle authority.
- API Management Service Reader Role: Provides observation without service-lifecycle changes.
Editorial sources (9)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations, Related roles. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- How to use role-based access control in Azure API Management →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Permissions for Integration - Microsoft.ApiManagement →
Supports: Description, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Quickstart: Create a new Azure API Management instance by using the Azure portal →
Supports: Practical scope, Common use cases, Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- API Management soft-delete →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.