Azure AI + machine learning built-in role

Azure AI Administrator

Provides the control-plane permissions that a classic Foundry hub or Azure Machine Learning workspace managed identity needs to operate the workspace and common dependencies. It has broad Actions across Machine Learning, Cognitive Services, storage, Key Vault, registries, search, monitoring, and deployments, but no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b78c5d69-af96-48a3-bf8d-a8b4d589de94

Control-plane actions (39)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Microsoft assigns this role to the hub or workspace system-assigned managed identity at the resource group that contains the workspace. The resource-group assignment is inherited by every supported dependency in that group; a subscription assignment would extend the same broad control-plane authority to unrelated resources.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Use the platform-created Azure AI Administrator assignment for the classic hub or Azure Machine Learning workspace system-assigned managed identity at its resource group. For an older workspace, follow the documented conversion workflow; do not grant this broad dependency-management role to ordinary developers.

Related roles (2)

Common questions

When should I assign the Azure AI Administrator Azure role?

Assign Azure AI Administrator when you need to: Let a newly created classic Foundry hub or Azure Machine Learning workspace managed identity provision and operate its documented dependency resources.; and Convert a pre-November 19, 2024 workspace managed identity from broad Contributor access to the narrower Azure AI Administrator role.. Practical scope: Microsoft assigns this role to the hub or workspace system-assigned managed identity at the resource group that contains the workspace. The resource-group assignment is inherited by every supported dependency in that group; a subscription assignment would extend the same broad control-plane authority to unrelated resources.

What permissions does the Azure AI Administrator Azure role grant?

The role definition grants 39 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.CognitiveServices/*; Microsoft.ContainerRegistry/registries/*; Microsoft.DocumentDb/databaseAccounts/*; Microsoft.Features/features/read; and Microsoft.Features/providers/features/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure AI Administrator Azure role?

Key considerations when assigning Azure AI Administrator: The role can create, change, or delete many dependency resources and can manage Cognitive Services and storage keys through its broad control-plane Actions.; It has no DataActions, so access to Key Vault secrets, storage blobs, search documents, and other dependency data remains a separate authorization plane.; and A parent-scope assignment can expose unrelated storage, Key Vault, registry, search, and Machine Learning resources to the workspace identity.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →