Azure Integration built-in role

API Management Workspace Contributor

Manages API Management workspace resources and reads workspace membership but cannot modify workspace members. Its workspace wildcard includes current named-value, backend, subscription-key, and tool-server secret operations; it uses control-plane Actions only and does not replace the required service-scoped role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 0c34c906-8d99-4cb7-8bb7-33f5b0a1a799

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the workspace the collaborator administers. Workspace scope limits the role to that administrative boundary, while the required service-scoped workspace role supplies access to selected service-level resources.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign API Management Workspace Contributor to the workspace administration group on one workspace only after accepting all documented workspace secret and subscription-key operations, plus the service-scoped role needed for that team's service references. Add a gateway role only for a dedicated workspace gateway and use narrower workspace roles for nonadministrative collaborators.

Related roles (3)

Editorial sources (8)

Official Microsoft Learn documentation →