Azure AI + machine learning built-in role

Azure AI Administrator

Provides the control-plane permissions that a classic Foundry hub or Azure Machine Learning workspace managed identity needs to operate the workspace and common dependencies. It has broad Actions across Machine Learning, Cognitive Services, storage, Key Vault, registries, search, monitoring, and deployments, but no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b78c5d69-af96-48a3-bf8d-a8b4d589de94

Control-plane actions (39)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Microsoft assigns this role to the hub or workspace system-assigned managed identity at the resource group that contains the workspace. The resource-group assignment is inherited by every supported dependency in that group; a subscription assignment would extend the same broad control-plane authority to unrelated resources.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Use the platform-created Azure AI Administrator assignment for the classic hub or Azure Machine Learning workspace system-assigned managed identity at its resource group. For an older workspace, follow the documented conversion workflow; do not grant this broad dependency-management role to ordinary developers.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →