Azure Integration built-in role
API Management Service Workspace API Product Manager
Provides the service-level half of an API Management workspace product-manager assignment. It includes the service workspace developer operations plus user reads and user-to-group assignment, and must be paired with a workspace-scoped role. All published permissions are control-plane Actions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: d59a3e9c-6d52-4a5a-aeed-6bf3cf0e31da
Control-plane actions (12)
Microsoft.ApiManagement/service/users/readMicrosoft.ApiManagement/service/tags/readMicrosoft.ApiManagement/service/tags/apiLinks/*Microsoft.ApiManagement/service/tags/operationLinks/*Microsoft.ApiManagement/service/tags/productLinks/*Microsoft.ApiManagement/service/products/readMicrosoft.ApiManagement/service/products/apiLinks/*Microsoft.ApiManagement/service/groups/readMicrosoft.ApiManagement/service/groups/users/*Microsoft.ApiManagement/service/readMicrosoft.ApiManagement/service/authorizationServers/readMicrosoft.Authorization/*/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the API Management service containing the target workspace. The assignment is inherited by workspace-related service resources in that service but does not replace API Management Workspace API Product Manager on the workspace itself.
Common use cases (2)
- Let a workspace product manager link APIs to service products and tags and organize users into service groups used for API and product visibility.
- Support a federated product-publication workflow that needs both service-level membership and workspace-level product management.
Prerequisites (2)
- The workspace and its publication model must exist, and the same principal must receive API Management Workspace API Product Manager on that workspace.
- The platform team must define which service groups the product manager may change and how those groups affect API and product visibility.
Best practices (2)
- Use the service workspace developer role instead when the collaborator does not assign users to groups.
- Assign through a Microsoft Entra group, review membership changes, and audit both companion role assignments together.
Security considerations (2)
- Changing user-to-group assignments can change which APIs and products users can see in API Management.
- The role does not independently authorize workspace product changes or service infrastructure administration and grants no DataActions.
Assignment guidance
Assign API Management Service Workspace API Product Manager on the service and API Management Workspace API Product Manager on the specific workspace to the same approved product-management group. Use the developer pair when group membership administration is unnecessary.
Related roles (2)
- API Management Workspace API Product Manager: The required workspace-scoped companion role for publishing and productizing workspace APIs.
- API Management Service Workspace API Developer: Omits user reads and user-to-group assignment while retaining service product and tag linking.
Editorial sources (7)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Federated API management with workspaces →
Supports: Description, Practical scope, Common use cases, Prerequisites, Assignment guidance, Related roles. Retrieved 2026-07-17.
- How to use role-based access control in Azure API Management →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.