Azure Integration built-in role
API Management Service Reader Role
Provides read access to API Management services and entities such as APIs and policies, excludes user-key reads, but still includes the separate tenant-key read operation. It has no DataActions, and its supporting Actions also include classic alert-rule and support-ticket management.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 71522526-b88f-4d52-b57f-d31fc3546d0d
Control-plane actions (8)
Microsoft.ApiManagement/service/*/readMicrosoft.ApiManagement/service/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (1)
Microsoft.ApiManagement/service/users/keys/read
Assignable scopes (1)
/
Practical scope
Assign on one API Management service for service-specific visibility. Resource-group and subscription assignments are inherited and expose every API Management service and entity below the selected scope.
Common use cases (2)
- Let auditors, support staff, or API stakeholders inspect service configuration, APIs, products, and policies without changing them.
- Support inventory and troubleshooting that requires API Management metadata but not service or API modification.
Prerequisites (3)
- The service and entities to review must already exist.
- The reviewer must be approved to see API definitions, policies, products, and operational configuration in the assigned service.
- The reviewer must be approved to retrieve API Management tenant keys within the assignment scope.
Best practices (4)
- Assign on the individual service rather than a parent scope when the reviewer supports only one API platform.
- Use Operator only for approved service-lifecycle duties and Contributor only for API or service changes.
- Protect and rotate tenant keys exposed by the documented `service/tenants/keys/read` operation.
- Keep the assignment on the API Management service so its supporting alert and support operations do not inherit across unrelated resources.
Security considerations (2)
- Read access can expose API definitions, policies, backend configuration metadata, and service topology. The user-key read is excluded, but `Microsoft.ApiManagement/service/*/read` still matches the distinct tenant-key read operation.
- The role cannot modify API Management service or API entities and grants no runtime API data-plane access, but its supporting Actions can manage classic alert rules and create or update support tickets within the effective scope.
Assignment guidance
Assign API Management Service Reader Role to observers on the specific API Management instance only after accepting its tenant-key read authority. Broaden to a resource group or subscription only when the same reviewer is responsible for every inherited instance and its tenant keys.
Related roles (2)
- API Management Service Operator Role: Adds service-lifecycle operations without API entity writes.
- API Management Service Contributor: Adds complete service and API entity administration.
Editorial sources (7)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations, Related roles. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- How to use role-based access control in Azure API Management →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Permissions for Integration - Microsoft.ApiManagement →
Supports: Description, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.