Skip to content

Update API Management Service Operator role description - #128689

Open
Maciej Treder (maciejtreder) wants to merge 1 commit into
MicrosoftDocs:mainfrom
maciejtreder:patch-8
Open

Update API Management Service Operator role description#128689
Maciej Treder (maciejtreder) wants to merge 1 commit into
MicrosoftDocs:mainfrom
maciejtreder:patch-8

Conversation

@maciejtreder

Copy link
Copy Markdown
Contributor

Clarified the API Management Service Operator role's permissions and implications regarding service restoration.

Clarified the API Management Service Operator role's permissions and implications regarding service restoration.
@prmerger-automator

Copy link
Copy Markdown
Contributor

Maciej Treder (@maciejtreder) : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change. Robert Lyon (@rolyon)

1 similar comment
@prmerger-automator

Copy link
Copy Markdown
Contributor

Maciej Treder (@maciejtreder) : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change. Robert Lyon (@rolyon)

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit 3d7125d:

✅ Validation status: passed

File Status Preview URL Details
articles/role-based-access-control/built-in-roles/integration.md ✅Succeeded

For more details, please refer to the build report.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Clarifies the permissions and real-world impact of the API Management Service Operator Role, specifically highlighting that restore-from-backup can effectively modify service entities even without direct write permissions.

Changes:

  • Expanded the role description to explain that Microsoft.ApiManagement/service/restore/action can indirectly create/modify/replace APIs and related entities.
  • Added guidance to restrict assignment of this role to principals trusted with full configuration write impact.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

## API Management Service Operator Role

Can manage service but not the APIs
Can manage service but not the APIs. Although this role does not grant write permissions on individual service entities (APIs, policies, products, etc.), the Microsoft.ApiManagement/service/restore/action permission allows a full service restore from a backup, which can create, modify, or replace those entities as a side effect. Grant this role only to principals you'd also trust with write access to all service configuration.
@v-regandowner

Copy link
Copy Markdown
Contributor

Precious Mwongera (@mwongerapk)

Can you review the proposed changes?

IMPORTANT: When the changes are ready for publication, adding a #sign-off comment is the best way to signal that the PR is ready for the review team to merge.

#label:"aq-pr-triaged"
@MicrosoftDocs/public-repo-pr-review-team

@prmerger-automator prmerger-automator Bot added the aq-pr-triaged tracking label for the PR review team label Aug 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants