Azure AI + machine learning built-in role

Azure AI Enterprise Network Connection Approver

Approves and manages private endpoint connections from a Foundry managed network to the supported dependency resource types. Its permissions are control-plane Actions only; it grants no access to the data carried through an approved private connection.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b556d68e-0be0-4f35-a333-ad7ee1ce17ea

Control-plane actions (90)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign to the Foundry account or classic hub managed identity on each target dependency resource, or on a resource group containing only the approved targets. Parent-scope assignments are inherited and let the identity approve private endpoints on every covered target below that scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Azure AI Enterprise Network Connection Approver to the Foundry resource or classic hub managed identity on each approved private-endpoint target, or on a tightly dedicated resource group containing those targets. Do not assign it to end users or use it as a substitute for target-service data access.

Editorial sources (6)

Official Microsoft Learn documentation →