Azure Integration built-in role

API Management Service Operator Role

Manages API Management service infrastructure, including deletion, scaling, VPN, custom-domain, backup, restore, hostname, and certificate operations, while not granting write access to APIs and policies. Its service read wildcard excludes user-key reads but still includes the separate tenant-key read operation; the role has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: e022efe7-f5ba-4159-bbe4-b44f577e9b61

Control-plane actions (15)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on an existing API Management service operated by the platform team. Creating a new instance or recovering a soft-deleted instance addresses a service under a resource group, so create-or-update authority must be inherited from the resource group or a parent scope; direct scope on an existing instance covers that instance only.

Common use cases (3)

Prerequisites (4)

Best practices (3)

Security considerations (4)

Assignment guidance

Assign API Management Service Operator Role on an existing API Management instance for service operations only after accepting its tenant-key read authority. Use a dedicated resource-group assignment only when the same group must create or recover the instance. Keep API and policy authoring with Service Contributor or workspace roles, and use Service Reader when no lifecycle operation is required.

Related roles (2)

Editorial sources (9)

Official Microsoft Learn documentation →