Azure Integration built-in role

API Management Workspace Reader

Provides read-only access to API Management entities in a workspace, including documented diagnostic and gateway-log visibility. It uses control-plane read Actions and no DataActions, and every workspace collaborator still needs a service-scoped workspace role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ef1c2c96-4a77-49e8-b9a4-6179fe1d2fd2

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the workspace the reviewer must inspect. A parent assignment is inherited more broadly, while the companion service-scoped workspace role remains necessary for selected service-level references.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign API Management Workspace Reader on the specific workspace and the required service-scoped workspace role on the containing service. Add Reader on a dedicated workspace gateway only when gateway settings must also be visible.

Related roles (3)

Editorial sources (7)

Official Microsoft Learn documentation →