Azure AI + machine learning built-in role

Azure AI Enterprise Network Connection Approver

Approves and manages private endpoint connections from a Foundry managed network to the supported dependency resource types. Its permissions are control-plane Actions only; it grants no access to the data carried through an approved private connection.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b556d68e-0be0-4f35-a333-ad7ee1ce17ea

Control-plane actions (90)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign to the Foundry account or classic hub managed identity on each target dependency resource, or on a resource group containing only the approved targets. Parent-scope assignments are inherited and let the identity approve private endpoints on every covered target below that scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure AI Enterprise Network Connection Approver to the Foundry resource or classic hub managed identity on each approved private-endpoint target, or on a tightly dedicated resource group containing those targets. Do not assign it to end users or use it as a substitute for target-service data access.

Common questions

When should I assign the Azure AI Enterprise Network Connection Approver Azure role?

Assign Azure AI Enterprise Network Connection Approver when you need to: Allow a Foundry managed identity to automatically approve managed private endpoints to supported resources such as Storage, AI Search, Key Vault, Cosmos DB, registries, databases, monitoring, and API Management.; and Authorize the Foundry managed network to establish a private endpoint to an approved Application Gateway for private on-premises connectivity.. Practical scope: Assign to the Foundry account or classic hub managed identity on each target dependency resource, or on a resource group containing only the approved targets. Parent-scope assignments are inherited and let the identity approve private endpoints on every covered target below that scope.

What permissions does the Azure AI Enterprise Network Connection Approver Azure role grant?

The role definition grants 90 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiManagement/service/privateEndpointConnections/read; Microsoft.ApiManagement/service/privateEndpointConnections/write; Microsoft.ApiManagement/service/privateLinkResources/read; Microsoft.ApiManagement/service/read; Microsoft.ContainerRegistry/registries/privateEndpointConnectionsApproval/action; and Microsoft.ContainerRegistry/registries/privateEndpointConnections/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure AI Enterprise Network Connection Approver Azure role?

Key considerations when assigning Azure AI Enterprise Network Connection Approver: The role can approve or reject private endpoint connections across many dependency service types, changing which private network paths may be established.; It does not authorize reads or writes to the connected service data plane; those permissions must be granted separately.; and A resource-group or subscription assignment can authorize private connections to unrelated supported resources in the inherited scope.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →