Azure Integration built-in role

API Management Service Workspace API Product Manager

Provides the service-level half of an API Management workspace product-manager assignment. It includes the service workspace developer operations plus user reads and user-to-group assignment, and must be paired with a workspace-scoped role. All published permissions are control-plane Actions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: d59a3e9c-6d52-4a5a-aeed-6bf3cf0e31da

Control-plane actions (12)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the API Management service containing the target workspace. The assignment is inherited by workspace-related service resources in that service but does not replace API Management Workspace API Product Manager on the workspace itself.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign API Management Service Workspace API Product Manager on the service and API Management Workspace API Product Manager on the specific workspace to the same approved product-management group. Use the developer pair when group membership administration is unnecessary.

Related roles (2)

Common questions

When should I assign the API Management Service Workspace API Product Manager Azure role?

Assign API Management Service Workspace API Product Manager when you need to: Let a workspace product manager link APIs to service products and tags and organize users into service groups used for API and product visibility.; and Support a federated product-publication workflow that needs both service-level membership and workspace-level product management.. Practical scope: Assign on the API Management service containing the target workspace. The assignment is inherited by workspace-related service resources in that service but does not replace API Management Workspace API Product Manager on the workspace itself.

What permissions does the API Management Service Workspace API Product Manager Azure role grant?

The role definition grants 12 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiManagement/service/users/read; Microsoft.ApiManagement/service/tags/read; Microsoft.ApiManagement/service/tags/apiLinks/*; Microsoft.ApiManagement/service/tags/operationLinks/*; Microsoft.ApiManagement/service/tags/productLinks/*; and Microsoft.ApiManagement/service/products/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the API Management Service Workspace API Product Manager Azure role?

Key considerations when assigning API Management Service Workspace API Product Manager: Changing user-to-group assignments can change which APIs and products users can see in API Management.; and The role does not independently authorize workspace product changes or service infrastructure administration and grants no DataActions.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →