Azure Integration built-in role
API Management Service Workspace API Developer
Provides the service-level half of an API Management workspace API developer assignment: it reads service tags, products, and authorization servers and can link workspace APIs and tags to service products. The role uses control-plane Actions only and must be paired with a workspace-scoped role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 9565a273-41b9-4368-97d2-aeb0c976a9b3
Control-plane actions (9)
Microsoft.ApiManagement/service/tags/readMicrosoft.ApiManagement/service/tags/apiLinks/*Microsoft.ApiManagement/service/tags/operationLinks/*Microsoft.ApiManagement/service/tags/productLinks/*Microsoft.ApiManagement/service/products/readMicrosoft.ApiManagement/service/products/apiLinks/*Microsoft.ApiManagement/service/readMicrosoft.ApiManagement/service/authorizationServers/readMicrosoft.Authorization/*/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the API Management service that contains the collaborator's workspace. This service-scoped assignment does not replace the required workspace-scoped API Management Workspace API Developer role; parent assignments are inherited by all contained services.
Common use cases (2)
- Allow a workspace API developer to associate workspace APIs with service-level products and tags.
- Enable a federated workspace team to reference the documented service-level resources needed by its API editing workflow.
Prerequisites (2)
- The API Management workspace must exist and the collaborator must also receive API Management Workspace API Developer on that workspace.
- If the workspace uses a workspace gateway, assign the separately required Reader, Contributor, or Owner role on that gateway according to gateway duties.
Best practices (2)
- Assign this role only on the containing API Management service and pair it with the matching workspace developer role.
- Use Microsoft Entra groups for workspace teams and review both service- and workspace-scoped assignments together.
Security considerations (2)
- The role can change API-to-product and tag relationships at service level, affecting API organization and product exposure.
- It does not by itself grant permission to edit workspace APIs or manage the service infrastructure, and it has no DataActions.
Assignment guidance
Assign API Management Service Workspace API Developer on the containing service and API Management Workspace API Developer on the specific workspace to the same collaborator or group. Add a gateway role only when the collaborator manages or views a dedicated workspace gateway.
Related roles (2)
- API Management Workspace API Developer: The required workspace-scoped companion role that authorizes API editing inside the workspace.
- API Management Service Workspace API Product Manager: Adds user reads and user-to-group assignment for the product-management workflow.
Editorial sources (7)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Federated API management with workspaces →
Supports: Description, Practical scope, Common use cases, Prerequisites, Assignment guidance, Related roles. Retrieved 2026-07-17.
- How to use role-based access control in Azure API Management →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.