Azure Integration built-in role
API Management Workspace Contributor
Manages API Management workspace resources and reads workspace membership but cannot modify workspace members. Its workspace wildcard includes current named-value, backend, subscription-key, and tool-server secret operations; it uses control-plane Actions only and does not replace the required service-scoped role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 0c34c906-8d99-4cb7-8bb7-33f5b0a1a799
Control-plane actions (5)
Microsoft.ApiManagement/service/workspaces/*Microsoft.Authorization/*/readMicrosoft.Insights/diagnosticSettings/*/readMicrosoft.insights/logs/readMicrosoft.insights/logs/ApiManagementGatewayLogs/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign directly on the workspace the collaborator administers. Workspace scope limits the role to that administrative boundary, while the required service-scoped workspace role supplies access to selected service-level resources.
Common use cases (2)
- Delegate broad workspace administration to a workspace lead while the central platform team retains API Management service infrastructure ownership.
- Manage the workspace and its entities without granting permission to change workspace membership.
Prerequisites (3)
- The workspace must exist, and the collaborator must also have an appropriate service-scoped workspace role on the containing API Management service.
- If a dedicated workspace gateway is used, assign Reader, Contributor, or Owner separately at the gateway according to the collaborator's gateway duties.
- The workspace administrator must be approved to retrieve named-value, backend, subscription-key, and tool-server secrets and to regenerate subscription keys.
Best practices (3)
- Reserve this broad workspace role for workspace administrators; use API Developer, API Product Manager, or Reader for narrower duties.
- Use Microsoft Entra groups and review the service role, workspace role, and optional gateway role as one access package.
- Protect and rotate all workspace secrets and keys returned or regenerated by the wildcard operations.
Security considerations (3)
- Broad workspace management can change APIs, products, policies, connections, diagnostics, and other entities within the workspace.
- The workspace wildcard directly includes named-value secret, backend-secret, subscription-key, and tool-server secret-subtree retrieval, plus subscription-key regeneration.
- The role can view but not modify workspace members and does not grant central service infrastructure administration.
Assignment guidance
Assign API Management Workspace Contributor to the workspace administration group on one workspace only after accepting all documented workspace secret and subscription-key operations, plus the service-scoped role needed for that team's service references. Add a gateway role only for a dedicated workspace gateway and use narrower workspace roles for nonadministrative collaborators.
Related roles (3)
- API Management Workspace API Developer: Narrows workspace changes to API development entities.
- API Management Workspace API Product Manager: Narrows workspace changes to API publication and productization entities.
- API Management Workspace Reader: Provides read-only access to workspace entities.
Editorial sources (8)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Federated API management with workspaces →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- How to use role-based access control in Azure API Management →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Permissions for Integration - Microsoft.ApiManagement →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.