Remediation steps for API Management minimum API version should be set to 2019-12-01 or higher

Daniel Hajsadr 0 Reputation points
2025-01-23T12:41:18.9+00:00

I saw Microsoft offered to highlight the necessity of this remediation:
the underlying cause for this recommendation is an issue identified with 2019-12-01 version where users with read-only permissions are able to view the service secrets. An alternate recommendation is to deny the secret access to the read-only users.

Microsoft then mentions to go to Management API settings and Select Yes for Prevent users with read-only permissions from accessing service secrets. However, I don't see this option at all. The only option available is Enforce minimum API version

Azure API Management
Azure API Management
An Azure service that provides a hybrid, multi-cloud management platform for APIs.
2,282 questions
{count} votes

1 answer

Sort by: Most helpful
  1. LeelaRajeshSayana-MSFT 17,101 Reputation points
    2025-01-24T00:11:53.6866667+00:00

    Hi @Daniel Hajsadr Thank you for reporting the issue. This is a documentation bug. We have brought this issue to our product team's attention. We will work on making changes to the documentation. Apologies for confusion created.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.