diff --git a/articles/role-based-access-control/built-in-roles/integration.md b/articles/role-based-access-control/built-in-roles/integration.md index 7be6fb89f51e1..763804f3c9d1d 100644 --- a/articles/role-based-access-control/built-in-roles/integration.md +++ b/articles/role-based-access-control/built-in-roles/integration.md @@ -126,7 +126,7 @@ Can manage service and the APIs ## API Management Service Operator Role -Can manage service but not the APIs +Can manage service but not the APIs. Although this role does not grant write permissions on individual service entities (APIs, policies, products, etc.), the Microsoft.ApiManagement/service/restore/action permission allows a full service restore from a backup, which can create, modify, or replace those entities as a side effect. Grant this role only to principals you'd also trust with write access to all service configuration. [Learn more](/azure/api-management/api-management-role-based-access-control) @@ -3168,4 +3168,4 @@ Services Hub Operator allows you to perform all read, write, and deletion operat ## Next steps -- [Assign Azure roles using the Azure portal](/azure/role-based-access-control/role-assignments-portal) \ No newline at end of file +- [Assign Azure roles using the Azure portal](/azure/role-based-access-control/role-assignments-portal)