Azure AI + machine learning built-in role
Azure AI Enterprise Network Connection Approver
Approves and manages private endpoint connections from a Foundry managed network to the supported dependency resource types. Its permissions are control-plane Actions only; it grants no access to the data carried through an approved private connection.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: b556d68e-0be0-4f35-a333-ad7ee1ce17ea
Control-plane actions (90)
Microsoft.ApiManagement/service/privateEndpointConnections/readMicrosoft.ApiManagement/service/privateEndpointConnections/writeMicrosoft.ApiManagement/service/privateLinkResources/readMicrosoft.ApiManagement/service/readMicrosoft.ContainerRegistry/registries/privateEndpointConnectionsApproval/actionMicrosoft.ContainerRegistry/registries/privateEndpointConnections/readMicrosoft.ContainerRegistry/registries/privateEndpointConnections/writeMicrosoft.Cache/redis/readMicrosoft.Cache/redis/privateEndpointConnections/readMicrosoft.Cache/redis/privateEndpointConnections/writeMicrosoft.Cache/redis/privateLinkResources/readMicrosoft.Cache/redis/privateEndpointConnectionsApproval/actionMicrosoft.Cache/redisEnterprise/readMicrosoft.Cache/redisEnterprise/privateEndpointConnections/readMicrosoft.Cache/redisEnterprise/privateEndpointConnections/writeMicrosoft.Cache/redisEnterprise/privateLinkResources/readMicrosoft.Cache/redisEnterprise/privateEndpointConnectionsApproval/actionMicrosoft.CognitiveServices/accounts/readMicrosoft.CognitiveServices/accounts/privateEndpointConnections/readMicrosoft.CognitiveServices/accounts/privateEndpointConnections/writeMicrosoft.CognitiveServices/accounts/privateLinkResources/readMicrosoft.DBforPostgreSQL/flexibleServers/privateEndpointConnectionsApproval/actionMicrosoft.DBforPostgreSQL/flexibleServers/privateEndpointConnections/readMicrosoft.DBforPostgreSQL/flexibleServers/privateEndpointConnections/writeMicrosoft.DBforPostgreSQL/flexibleServers/privateLinkResources/readMicrosoft.DBforPostgreSQL/flexibleServers/readMicrosoft.DBforPostgreSQL/serverGroupsv2/privateEndpointConnectionsApproval/actionMicrosoft.DBforPostgreSQL/serverGroupsv2/privateEndpointConnections/readMicrosoft.DBforPostgreSQL/serverGroupsv2/privateEndpointConnections/writeMicrosoft.DBforPostgreSQL/serverGroupsv2/privateLinkResources/readMicrosoft.DBforMySQL/flexibleServers/privateEndpointConnectionsApproval/actionMicrosoft.DBforMySQL/flexibleServers/privateEndpointConnections/readMicrosoft.DBforMySQL/flexibleServers/privateEndpointConnections/writeMicrosoft.DBforMySQL/flexibleServers/privateLinkResources/readMicrosoft.DBforMySQL/flexibleServers/readMicrosoft.DocumentDB/databaseAccounts/privateEndpointConnectionsApproval/actionMicrosoft.DocumentDB/databaseAccounts/privateEndpointConnections/operationResults/readMicrosoft.DocumentDB/databaseAccounts/privateEndpointConnections/readMicrosoft.DocumentDB/databaseAccounts/privateEndpointConnections/writeMicrosoft.DocumentDB/databaseAccounts/privateLinkResources/readMicrosoft.DocumentDB/databaseAccounts/readMicrosoft.KeyVault/vaults/privateEndpointConnectionsApproval/actionMicrosoft.KeyVault/vaults/privateEndpointConnections/readMicrosoft.KeyVault/vaults/privateEndpointConnections/writeMicrosoft.KeyVault/vaults/privateLinkResources/readMicrosoft.KeyVault/vaults/readMicrosoft.MachineLearningServices/registries/privateEndpointConnectionsApproval/actionMicrosoft.MachineLearningServices/registries/privateEndpointConnections/readMicrosoft.MachineLearningServices/registries/privateEndpointConnections/writeMicrosoft.MachineLearningServices/registries/privateLinkResources/readMicrosoft.MachineLearningServices/registries/readMicrosoft.MachineLearningServices/workspaces/privateEndpointConnectionsApproval/actionMicrosoft.MachineLearningServices/workspaces/privateEndpointConnections/readMicrosoft.MachineLearningServices/workspaces/privateEndpointConnections/writeMicrosoft.MachineLearningServices/workspaces/privateLinkResources/readMicrosoft.MachineLearningServices/workspaces/readMicrosoft.Storage/storageAccounts/privateEndpointConnections/readMicrosoft.Storage/storageAccounts/privateEndpointConnections/writeMicrosoft.Storage/storageAccounts/privateLinkResources/readMicrosoft.Storage/storageAccounts/readMicrosoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/actionMicrosoft.Sql/servers/privateEndpointConnectionsApproval/actionMicrosoft.Sql/servers/privateEndpointConnections/readMicrosoft.Sql/servers/privateEndpointConnections/writeMicrosoft.Sql/servers/privateLinkResources/readMicrosoft.Sql/servers/readMicrosoft.EventHub/namespaces/privateEndpointConnectionsApproval/actionMicrosoft.EventHub/namespaces/privateEndpointConnections/readMicrosoft.EventHub/namespaces/privateEndpointConnections/writeMicrosoft.EventHub/namespaces/privateLinkResources/readMicrosoft.EventHub/namespaces/readMicrosoft.Search/searchServices/privateEndpointConnectionsApproval/actionMicrosoft.Search/searchServices/privateEndpointConnections/readMicrosoft.Search/searchServices/privateEndpointConnections/writeMicrosoft.Search/searchServices/sharedPrivateLinkResources/readMicrosoft.Search/searchServices/readMicrosoft.Insights/privatelinkscopes/privateEndpointConnectionsApproval/actionMicrosoft.Insights/privatelinkscopes/privateEndpointConnections/readMicrosoft.Insights/privatelinkscopes/privateEndpointConnections/writeMicrosoft.Insights/privatelinkscopes/privateEndpointConnections/operationResults/readMicrosoft.Insights/privatelinkscopes/privateLinkResources/readMicrosoft.Insights/privatelinkscopes/readMicrosoft.Network/privateLinkServices/privateEndpointConnectionsApproval/actionMicrosoft.Network/privateLinkServices/privateEndpointConnections/readMicrosoft.Network/privateLinkServices/privateEndpointConnections/writeMicrosoft.Network/privateLinkServices/readMicrosoft.Network/applicationGateways/privateEndpointConnections/readMicrosoft.Network/applicationGateways/privateEndpointConnections/writeMicrosoft.Network/applicationGateways/privateLinkResources/readMicrosoft.Network/applicationGateways/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign to the Foundry account or classic hub managed identity on each target dependency resource, or on a resource group containing only the approved targets. Parent-scope assignments are inherited and let the identity approve private endpoints on every covered target below that scope.
Common use cases (2)
- Allow a Foundry managed identity to automatically approve managed private endpoints to supported resources such as Storage, AI Search, Key Vault, Cosmos DB, registries, databases, monitoring, and API Management.
- Authorize the Foundry managed network to establish a private endpoint to an approved Application Gateway for private on-premises connectivity.
Prerequisites (2)
- Configure the Foundry resource or classic hub managed network and obtain its system-assigned or user-assigned managed identity.
- Register Microsoft.Network and confirm that every target resource type is covered by this built-in role; use a custom scoped role for unsupported targets.
Best practices (3)
- Assign the role to the Foundry managed identity only on the target resources or dedicated target resource groups used by that managed network.
- Use a custom role containing only the required private-endpoint approval operations for target types not covered by the built-in role.
- Remove the assignment when the managed private endpoint or Foundry environment is decommissioned.
Security considerations (3)
- The role can approve or reject private endpoint connections across many dependency service types, changing which private network paths may be established.
- It does not authorize reads or writes to the connected service data plane; those permissions must be granted separately.
- A resource-group or subscription assignment can authorize private connections to unrelated supported resources in the inherited scope.
Assignment guidance
Assign Azure AI Enterprise Network Connection Approver to the Foundry resource or classic hub managed identity on each approved private-endpoint target, or on a tightly dedicated resource group containing those targets. Do not assign it to end users or use it as a substitute for target-service data access.
Editorial sources (6)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Configure managed virtual network for Microsoft Foundry - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- How to configure a managed network for a hub (classic) - Microsoft Foundry (classic) portal | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.