Azure Integration built-in role

API Management Workspace API Product Manager

Reads workspace entities and manages the products, subscriptions, groups, tags, and notifications used to publish APIs. Its subscription wildcard can list and regenerate subscription keys; the role contains control-plane Actions only and requires the matching service-scoped product-manager role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 73c2c328-d004-4c5e-938c-35c6f5679a1f

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the API Management workspace whose API products the manager owns. A service-scoped API Management Service Workspace API Product Manager assignment is also required for service-level product, tag, user, and group operations.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign API Management Workspace API Product Manager on the specific workspace only to a group approved to retrieve and rotate its subscription keys, and assign the matching service role on the containing service. Keep API implementation with Workspace API Developer and service lifecycle with the platform team.

Related roles (3)

Common questions

When should I assign the API Management Workspace API Product Manager Azure role?

Assign API Management Workspace API Product Manager when you need to: Let an API product team package workspace APIs into products and manage workspace subscriptions, groups, tags, and notifications.; and Separate API product publication from API implementation and central service infrastructure management.. Practical scope: Assign directly on the API Management workspace whose API products the manager owns. A service-scoped API Management Service Workspace API Product Manager assignment is also required for service-level product, tag, user, and group operations.

What permissions does the API Management Workspace API Product Manager Azure role grant?

The role definition grants 10 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiManagement/service/workspaces/*/read; Microsoft.ApiManagement/service/workspaces/products/*; Microsoft.ApiManagement/service/workspaces/subscriptions/*; Microsoft.ApiManagement/service/workspaces/groups/*; Microsoft.ApiManagement/service/workspaces/tags/*; and Microsoft.ApiManagement/service/workspaces/notifications/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the API Management Workspace API Product Manager Azure role?

Key considerations when assigning API Management Workspace API Product Manager: Product, subscription, group, and notification changes can alter how APIs are published and who can discover or subscribe to them.; The `workspaces/subscriptions/*` wildcard includes listing subscription keys and regenerating primary or secondary keys, which can disclose or invalidate client credentials.; and The role does not by itself grant service-level user-to-group operations or API implementation authority outside its documented workspace entities.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →