Azure AI + machine learning built-in role
Azure AI Developer
Develops within a classic Foundry hub or Azure Machine Learning workspace without creating or deleting the hub or workspace itself. The role combines broad workspace Actions with Azure AI service DataActions for OpenAI, Speech, Content Safety, and model-as-a-service operations.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 64702f94-c441-49e6-a78b-ef80e0188fee
Control-plane actions (7)
Microsoft.MachineLearningServices/workspaces/*/readMicrosoft.MachineLearningServices/workspaces/*/actionMicrosoft.MachineLearningServices/workspaces/*/deleteMicrosoft.MachineLearningServices/workspaces/*/writeMicrosoft.MachineLearningServices/locations/*/readMicrosoft.Authorization/*/readMicrosoft.Resources/deployments/*
Data-plane actions (4)
Microsoft.CognitiveServices/accounts/OpenAI/*Microsoft.CognitiveServices/accounts/SpeechServices/*Microsoft.CognitiveServices/accounts/ContentSafety/*Microsoft.CognitiveServices/accounts/MaaS/*
Excluded actions (10)
Microsoft.MachineLearningServices/workspaces/deleteMicrosoft.MachineLearningServices/workspaces/writeMicrosoft.MachineLearningServices/workspaces/listKeys/actionMicrosoft.MachineLearningServices/workspaces/hubs/writeMicrosoft.MachineLearningServices/workspaces/hubs/deleteMicrosoft.MachineLearningServices/workspaces/featurestores/writeMicrosoft.MachineLearningServices/workspaces/featurestores/deleteMicrosoft.MachineLearningServices/workspaces/evaluations/results/labels/readMicrosoft.MachineLearningServices/workspaces/evaluations/results/reasonings/readMicrosoft.MachineLearningServices/workspaces/simulations/results/images/read
Assignable scopes (1)
/
Practical scope
Assign at the classic hub or project/workspace used by the developer. Project access also receives Reader on the parent hub and the Inference Deployment Operator role for resource-group deployments; a resource-group assignment broadens development authority to every inherited workspace.
Common use cases (2)
- Create classic Foundry projects and shared project resources, build and deploy models, and use the supported AI service data planes within an existing hub.
- Develop in an Azure Machine Learning workspace while leaving workspace creation, deletion, and hub-level permission management with administrators.
Prerequisites (2)
- An existing classic Foundry hub or Azure Machine Learning workspace and its approved dependency resources are required.
- Grant separate roles on external storage, search, container registries, Key Vault, or other connected services when the workflow accesses them.
Best practices (3)
- Assign at project or workspace scope instead of the resource group when the developer works in only one workspace.
- Use AzureML Data Scientist for an Azure Machine Learning user who does not need the broader classic Foundry AI-service DataActions or project-creation capabilities.
- Review inherited Reader and Inference Deployment Operator assignments together with this role so the developer's effective access is understood.
Security considerations (3)
- The role can create, update, and delete many workspace assets and can invoke or manage supported AI service data-plane operations.
- Its NotActions protect the workspace, hub, feature-store root resources, and selected sensitive evaluation results, but additive roles can grant excluded operations separately.
- Connected-resource roles can expose data and credentials outside the workspace boundary.
Assignment guidance
Assign Azure AI Developer on the existing classic project, hub, or Azure Machine Learning workspace only when the principal needs the documented development and AI-service capabilities. Use narrower AzureML or current Foundry roles where they fit, and grant external-resource permissions separately.
Related roles (3)
- Azure AI Administrator: The managed-identity role for operating the classic hub or workspace and its common dependencies, not an ordinary developer role.
- Azure AI Inference Deployment Operator: The companion role Microsoft assigns to classic project members for resource-group deployment operations.
- AzureML Data Scientist: A workspace-focused alternative that excludes compute creation and workspace modification.
Editorial sources (6)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Microsoft Foundry (Hubs and Projects) (classic) - Microsoft Foundry (classic) portal | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Manage roles in your workspace - Azure Machine Learning | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.