Azure Integration built-in role

API Management Workspace Contributor

Manages API Management workspace resources and reads workspace membership but cannot modify workspace members. Its workspace wildcard includes current named-value, backend, subscription-key, and tool-server secret operations; it uses control-plane Actions only and does not replace the required service-scoped role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 0c34c906-8d99-4cb7-8bb7-33f5b0a1a799

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the workspace the collaborator administers. Workspace scope limits the role to that administrative boundary, while the required service-scoped workspace role supplies access to selected service-level resources.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign API Management Workspace Contributor to the workspace administration group on one workspace only after accepting all documented workspace secret and subscription-key operations, plus the service-scoped role needed for that team's service references. Add a gateway role only for a dedicated workspace gateway and use narrower workspace roles for nonadministrative collaborators.

Related roles (3)

Common questions

When should I assign the API Management Workspace Contributor Azure role?

Assign API Management Workspace Contributor when you need to: Delegate broad workspace administration to a workspace lead while the central platform team retains API Management service infrastructure ownership.; and Manage the workspace and its entities without granting permission to change workspace membership.. Practical scope: Assign directly on the workspace the collaborator administers. Workspace scope limits the role to that administrative boundary, while the required service-scoped workspace role supplies access to selected service-level resources.

What permissions does the API Management Workspace Contributor Azure role grant?

The role definition grants 5 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiManagement/service/workspaces/*; Microsoft.Authorization/*/read; Microsoft.Insights/diagnosticSettings/*/read; Microsoft.insights/logs/read; and Microsoft.insights/logs/ApiManagementGatewayLogs/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the API Management Workspace Contributor Azure role?

Key considerations when assigning API Management Workspace Contributor: Broad workspace management can change APIs, products, policies, connections, diagnostics, and other entities within the workspace.; The workspace wildcard directly includes named-value secret, backend-secret, subscription-key, and tool-server secret-subtree retrieval, plus subscription-key regeneration.; and The role can view but not modify workspace members and does not grant central service infrastructure administration.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →