Azure Integration built-in role

API Management Service Reader Role

Provides read access to API Management services and entities such as APIs and policies, excludes user-key reads, but still includes the separate tenant-key read operation. It has no DataActions, and its supporting Actions also include classic alert-rule and support-ticket management.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 71522526-b88f-4d52-b57f-d31fc3546d0d

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on one API Management service for service-specific visibility. Resource-group and subscription assignments are inherited and expose every API Management service and entity below the selected scope.

Common use cases (2)

Prerequisites (3)

Best practices (4)

Security considerations (2)

Assignment guidance

Assign API Management Service Reader Role to observers on the specific API Management instance only after accepting its tenant-key read authority. Broaden to a resource group or subscription only when the same reviewer is responsible for every inherited instance and its tenant keys.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →