Azure Integration built-in role

API Management Workspace Reader

Provides read-only access to API Management entities in a workspace, including documented diagnostic and gateway-log visibility. It uses control-plane read Actions and no DataActions, and every workspace collaborator still needs a service-scoped workspace role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ef1c2c96-4a77-49e8-b9a4-6179fe1d2fd2

Control-plane actions (5)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the workspace the reviewer must inspect. A parent assignment is inherited more broadly, while the companion service-scoped workspace role remains necessary for selected service-level references.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign API Management Workspace Reader on the specific workspace and the required service-scoped workspace role on the containing service. Add Reader on a dedicated workspace gateway only when gateway settings must also be visible.

Related roles (3)

Common questions

When should I assign the API Management Workspace Reader Azure role?

Assign API Management Workspace Reader when you need to: Let auditors, service owners, or support staff inspect one workspace and its API entities without changing them.; and Review workspace APIs and diagnostics while central platform and workspace teams retain all write authority.. Practical scope: Assign directly on the workspace the reviewer must inspect. A parent assignment is inherited more broadly, while the companion service-scoped workspace role remains necessary for selected service-level references.

What permissions does the API Management Workspace Reader Azure role grant?

The role definition grants 5 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiManagement/service/workspaces/*/read; Microsoft.Authorization/*/read; Microsoft.Insights/diagnosticSettings/*/read; Microsoft.insights/logs/read; and Microsoft.insights/logs/ApiManagementGatewayLogs/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the API Management Workspace Reader Azure role?

Key considerations when assigning API Management Workspace Reader: Read access can expose workspace API definitions, policies, products, diagnostics, and gateway logs.; and The role cannot modify workspace entities, membership, or central API Management service infrastructure and has no DataActions.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →