Azure Integration built-in role
API Management Workspace Reader
Provides read-only access to API Management entities in a workspace, including documented diagnostic and gateway-log visibility. It uses control-plane read Actions and no DataActions, and every workspace collaborator still needs a service-scoped workspace role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: ef1c2c96-4a77-49e8-b9a4-6179fe1d2fd2
Control-plane actions (5)
Microsoft.ApiManagement/service/workspaces/*/readMicrosoft.Authorization/*/readMicrosoft.Insights/diagnosticSettings/*/readMicrosoft.insights/logs/readMicrosoft.insights/logs/ApiManagementGatewayLogs/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign directly on the workspace the reviewer must inspect. A parent assignment is inherited more broadly, while the companion service-scoped workspace role remains necessary for selected service-level references.
Common use cases (2)
- Let auditors, service owners, or support staff inspect one workspace and its API entities without changing them.
- Review workspace APIs and diagnostics while central platform and workspace teams retain all write authority.
Prerequisites (2)
- The workspace must exist, and the reviewer must also receive an appropriate service-scoped workspace role on the containing service.
- Service- and workspace-level diagnostic settings must be configured when the reviewer needs workspace gateway logs in Log Analytics.
Best practices (2)
- Assign on one workspace and use a Microsoft Entra group for reviewers with the same visibility boundary.
- Elevate to an API Developer, API Product Manager, or Workspace Contributor role only for a documented write workflow.
Security considerations (2)
- Read access can expose workspace API definitions, policies, products, diagnostics, and gateway logs.
- The role cannot modify workspace entities, membership, or central API Management service infrastructure and has no DataActions.
Assignment guidance
Assign API Management Workspace Reader on the specific workspace and the required service-scoped workspace role on the containing service. Add Reader on a dedicated workspace gateway only when gateway settings must also be visible.
Related roles (3)
- API Management Workspace Contributor: Adds broad workspace management while still excluding member modification.
- API Management Workspace API Developer: Adds API-development changes within the workspace.
- API Management Workspace API Product Manager: Adds API publication and productization changes within the workspace.
Editorial sources (7)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Federated API management with workspaces →
Supports: Description, Practical scope, Common use cases, Prerequisites, Assignment guidance, Related roles. Retrieved 2026-07-17.
- How to use role-based access control in Azure API Management →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.