Azure AI + machine learning built-in role

Cognitive Services Contributor

Creates, changes, deletes, and manages keys for Azure AI services through broad Cognitive Services control-plane Actions. It has no DataActions, so data-plane behavior is service-specific: Microsoft documents Azure OpenAI management capabilities for this role, but Speech data, models, endpoints, transcription, and synthesis require a Speech or Cognitive Services User data role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 25fbc0a9-bd7c-42a3-aa1a-3b75d497ee68

Control-plane actions (18)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (4)

Assignable scopes (1)

Practical scope

Assign on one Azure AI services resource for its lifecycle and key management, or at a dedicated resource group only when the principal manages every contained resource. Parent-scope roles are inherited and additive; a subscription Contributor or Owner can supersede a narrower resource assignment.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Cognitive Services Contributor only to trusted resource administrators at the individual Azure AI resource or dedicated resource group. Use OpenAI User, OpenAI Contributor, Speech User, Speech Contributor, or another product-specific role for data-plane work, and add Usages Reader separately for quota.

Related roles (3)

Editorial sources (6)

Official Microsoft Learn documentation →