Azure AI + machine learning built-in role
Cognitive Services Contributor
Creates, changes, deletes, and manages keys for Azure AI services through broad Cognitive Services control-plane Actions. It has no DataActions, so data-plane behavior is service-specific: Microsoft documents Azure OpenAI management capabilities for this role, but Speech data, models, endpoints, transcription, and synthesis require a Speech or Cognitive Services User data role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 25fbc0a9-bd7c-42a3-aa1a-3b75d497ee68
Control-plane actions (18)
Microsoft.Authorization/*/readMicrosoft.CognitiveServices/*Microsoft.Features/features/readMicrosoft.Features/providers/features/readMicrosoft.Features/providers/features/register/actionMicrosoft.Insights/alertRules/*Microsoft.Insights/diagnosticSettings/*Microsoft.Insights/logDefinitions/readMicrosoft.Insights/metricdefinitions/readMicrosoft.Insights/metrics/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/deployments/operations/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (4)
Microsoft.CognitiveServices/raiPolicy/writeMicrosoft.CognitiveServices/raiPolicy/deleteMicrosoft.CognitiveServices/raiExternalSafetyProviders/writeMicrosoft.CognitiveServices/raiExternalSafetyProviders/delete
Assignable scopes (1)
/
Practical scope
Assign on one Azure AI services resource for its lifecycle and key management, or at a dedicated resource group only when the principal manages every contained resource. Parent-scope roles are inherited and additive; a subscription Contributor or Owner can supersede a narrower resource assignment.
Common use cases (2)
- Create and administer Azure OpenAI or other Cognitive Services resources and manage their resource keys within an approved scope.
- Manage Azure OpenAI deployments, fine-tuning, content filters, and resource configuration when full Cognitive Services control-plane authority is required.
Prerequisites (2)
- Confirm that resource creation, deletion, configuration, or key management is required; data-plane-only users should receive a service-specific user role instead.
- Grant Cognitive Services Usages Reader separately at subscription scope when the administrator must view or edit quota through the Foundry portal.
Best practices (3)
- Assign on the individual Azure AI resource or a dedicated resource group and use service-specific roles for developers, inference callers, and data readers.
- Prefer Microsoft Entra authentication for data-plane clients instead of distributing resource keys.
- Do not describe this broad contributor role as least privilege for inference, project authoring, or view-only work.
Security considerations (3)
- The role can create, change, and delete Azure AI resources and can view, copy, or regenerate resource keys, which are bearer credentials for key-authenticated access.
- Its definition excludes writing or deleting responsible-AI policy and external safety-provider resources, but other broad resource operations remain.
- No DataActions are present; nevertheless, possession of retrieved keys can provide a separate data-plane access path.
Assignment guidance
Assign Cognitive Services Contributor only to trusted resource administrators at the individual Azure AI resource or dedicated resource group. Use OpenAI User, OpenAI Contributor, Speech User, Speech Contributor, or another product-specific role for data-plane work, and add Usages Reader separately for quota.
Related roles (3)
- Cognitive Services OpenAI Contributor: Provides Azure OpenAI deployment, fine-tuning, and inference capabilities without resource creation or key management.
- Cognitive Services Usages Reader: The subscription-scoped companion role for viewing quota allocations.
- Cognitive Services Speech Contributor: The Speech-specific data-plane role Microsoft recommends for full Speech project access.
Editorial sources (6)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Azure OpenAI (classic) - Microsoft Foundry (classic) portal | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Role-based access control for Speech resources - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.