Azure Integration built-in role
API Management Workspace API Product Manager
Reads workspace entities and manages the products, subscriptions, groups, tags, and notifications used to publish APIs. Its subscription wildcard can list and regenerate subscription keys; the role contains control-plane Actions only and requires the matching service-scoped product-manager role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 73c2c328-d004-4c5e-938c-35c6f5679a1f
Control-plane actions (10)
Microsoft.ApiManagement/service/workspaces/*/readMicrosoft.ApiManagement/service/workspaces/products/*Microsoft.ApiManagement/service/workspaces/subscriptions/*Microsoft.ApiManagement/service/workspaces/groups/*Microsoft.ApiManagement/service/workspaces/tags/*Microsoft.ApiManagement/service/workspaces/notifications/*Microsoft.Authorization/*/readMicrosoft.Insights/diagnosticSettings/*/readMicrosoft.insights/logs/readMicrosoft.insights/logs/ApiManagementGatewayLogs/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign directly on the API Management workspace whose API products the manager owns. A service-scoped API Management Service Workspace API Product Manager assignment is also required for service-level product, tag, user, and group operations.
Common use cases (2)
- Let an API product team package workspace APIs into products and manage workspace subscriptions, groups, tags, and notifications.
- Separate API product publication from API implementation and central service infrastructure management.
Prerequisites (3)
- The workspace and its APIs must exist, and the collaborator must also receive API Management Service Workspace API Product Manager on the containing service.
- The platform team must approve the product, subscription, group, and notification model used by the workspace.
- The product manager must be approved to retrieve and regenerate workspace subscription keys.
Best practices (3)
- Use the API developer role for principals who edit API definitions and policies rather than products and subscriptions.
- Assign to a workspace-specific group and regularly review subscriptions and group-driven API visibility.
- Protect subscription keys and coordinate regeneration with every approved client that uses them.
Security considerations (3)
- Product, subscription, group, and notification changes can alter how APIs are published and who can discover or subscribe to them.
- The `workspaces/subscriptions/*` wildcard includes listing subscription keys and regenerating primary or secondary keys, which can disclose or invalidate client credentials.
- The role does not by itself grant service-level user-to-group operations or API implementation authority outside its documented workspace entities.
Assignment guidance
Assign API Management Workspace API Product Manager on the specific workspace only to a group approved to retrieve and rotate its subscription keys, and assign the matching service role on the containing service. Keep API implementation with Workspace API Developer and service lifecycle with the platform team.
Related roles (3)
- API Management Service Workspace API Product Manager: The required service-scoped companion for service product, tag, user, and group operations.
- API Management Workspace API Developer: Edits API definitions and development entities instead of focusing on product publication.
- API Management Workspace Reader: Provides read-only workspace visibility.
Editorial sources (8)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Federated API management with workspaces →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- How to use role-based access control in Azure API Management →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Permissions for Integration - Microsoft.ApiManagement →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.