Azure AI + machine learning built-in role
Azure AI Administrator
Provides the control-plane permissions that a classic Foundry hub or Azure Machine Learning workspace managed identity needs to operate the workspace and common dependencies. It has broad Actions across Machine Learning, Cognitive Services, storage, Key Vault, registries, search, monitoring, and deployments, but no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: b78c5d69-af96-48a3-bf8d-a8b4d589de94
Control-plane actions (39)
Microsoft.Authorization/*/readMicrosoft.CognitiveServices/*Microsoft.ContainerRegistry/registries/*Microsoft.DocumentDb/databaseAccounts/*Microsoft.Features/features/readMicrosoft.Features/providers/features/readMicrosoft.Features/providers/features/register/actionMicrosoft.Insights/alertRules/*Microsoft.Insights/components/*Microsoft.Insights/diagnosticSettings/*Microsoft.Insights/generateLiveToken/readMicrosoft.Insights/logDefinitions/readMicrosoft.Insights/metricAlerts/*Microsoft.Insights/metricdefinitions/readMicrosoft.Insights/metrics/readMicrosoft.Insights/scheduledqueryrules/*Microsoft.Insights/topology/readMicrosoft.Insights/transactions/readMicrosoft.Insights/webtests/*Microsoft.KeyVault/*Microsoft.MachineLearningServices/workspaces/*Microsoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/actionMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/deployments/operations/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/subscriptions/resourceGroups/writeMicrosoft.Storage/storageAccounts/*Microsoft.Support/*Microsoft.Search/searchServices/writeMicrosoft.Search/searchServices/readMicrosoft.Search/searchServices/deleteMicrosoft.Search/searchServices/indexes/*Microsoft.Search/searchServices/listAdminKeys/actionMicrosoft.Search/searchServices/privateEndpointConnections/*Microsoft.DataFactory/factories/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Microsoft assigns this role to the hub or workspace system-assigned managed identity at the resource group that contains the workspace. The resource-group assignment is inherited by every supported dependency in that group; a subscription assignment would extend the same broad control-plane authority to unrelated resources.
Common use cases (2)
- Let a newly created classic Foundry hub or Azure Machine Learning workspace managed identity provision and operate its documented dependency resources.
- Convert a pre-November 19, 2024 workspace managed identity from broad Contributor access to the narrower Azure AI Administrator role.
Prerequisites (2)
- Use the system-assigned managed identity of a classic Foundry hub or Azure Machine Learning workspace, not a human developer identity.
- Keep the workspace and the storage, Key Vault, registry, search, monitoring, and other dependencies that it administers in the intended resource-group boundary.
Best practices (3)
- Use Azure AI Administrator for the workspace managed identity instead of Contributor unless Microsoft support directs a temporary reversion for a documented compatibility problem.
- Assign at the workspace resource group and isolate unrelated resources into different groups.
- Grant external-resource data access separately to the managed identity only when the workspace workflow requires it.
Security considerations (3)
- The role can create, change, or delete many dependency resources and can manage Cognitive Services and storage keys through its broad control-plane Actions.
- It has no DataActions, so access to Key Vault secrets, storage blobs, search documents, and other dependency data remains a separate authorization plane.
- A parent-scope assignment can expose unrelated storage, Key Vault, registry, search, and Machine Learning resources to the workspace identity.
Assignment guidance
Use the platform-created Azure AI Administrator assignment for the classic hub or Azure Machine Learning workspace system-assigned managed identity at its resource group. For an older workspace, follow the documented conversion workflow; do not grant this broad dependency-management role to ordinary developers.
Related roles (2)
- Azure AI Developer: The documented user role for developing within a classic hub or project; it is not the workspace managed-identity dependency role.
- Contributor: The older, broader default for workspace managed identities that Microsoft recommends replacing with Azure AI Administrator where supported.
Editorial sources (6)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Microsoft Foundry (Hubs and Projects) (classic) - Microsoft Foundry (classic) portal | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Manage roles in your workspace - Azure Machine Learning | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.