Azure Integration built-in role

API Management Service Reader Role

Provides read access to API Management services and entities such as APIs and policies, excludes user-key reads, but still includes the separate tenant-key read operation. It has no DataActions, and its supporting Actions also include classic alert-rule and support-ticket management.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 71522526-b88f-4d52-b57f-d31fc3546d0d

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on one API Management service for service-specific visibility. Resource-group and subscription assignments are inherited and expose every API Management service and entity below the selected scope.

Common use cases (2)

Prerequisites (3)

Best practices (4)

Security considerations (2)

Assignment guidance

Assign API Management Service Reader Role to observers on the specific API Management instance only after accepting its tenant-key read authority. Broaden to a resource group or subscription only when the same reviewer is responsible for every inherited instance and its tenant keys.

Related roles (2)

Common questions

When should I assign the API Management Service Reader Role Azure role?

Assign API Management Service Reader Role when you need to: Let auditors, support staff, or API stakeholders inspect service configuration, APIs, products, and policies without changing them.; and Support inventory and troubleshooting that requires API Management metadata but not service or API modification.. Practical scope: Assign on one API Management service for service-specific visibility. Resource-group and subscription assignments are inherited and expose every API Management service and entity below the selected scope.

What permissions does the API Management Service Reader Role Azure role grant?

The role definition grants 8 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiManagement/service/*/read; Microsoft.ApiManagement/service/read; Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; Microsoft.ResourceHealth/availabilityStatuses/read; and Microsoft.Resources/deployments/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the API Management Service Reader Role Azure role?

Key considerations when assigning API Management Service Reader Role: Read access can expose API definitions, policies, backend configuration metadata, and service topology. The user-key read is excluded, but `Microsoft.ApiManagement/service/*/read` still matches the distinct tenant-key read operation.; and The role cannot modify API Management service or API entities and grants no runtime API data-plane access, but its supporting Actions can manage classic alert rules and create or update support tickets within the effective scope.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →