Azure AI + machine learning built-in role

Cognitive Services Contributor

Creates, changes, deletes, and manages keys for Azure AI services through broad Cognitive Services control-plane Actions. It has no DataActions, so data-plane behavior is service-specific: Microsoft documents Azure OpenAI management capabilities for this role, but Speech data, models, endpoints, transcription, and synthesis require a Speech or Cognitive Services User data role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 25fbc0a9-bd7c-42a3-aa1a-3b75d497ee68

Control-plane actions (18)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (4)

Assignable scopes (1)

Practical scope

Assign on one Azure AI services resource for its lifecycle and key management, or at a dedicated resource group only when the principal manages every contained resource. Parent-scope roles are inherited and additive; a subscription Contributor or Owner can supersede a narrower resource assignment.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Cognitive Services Contributor only to trusted resource administrators at the individual Azure AI resource or dedicated resource group. Use OpenAI User, OpenAI Contributor, Speech User, Speech Contributor, or another product-specific role for data-plane work, and add Usages Reader separately for quota.

Related roles (3)

Common questions

When should I assign the Cognitive Services Contributor Azure role?

Assign Cognitive Services Contributor when you need to: Create and administer Azure OpenAI or other Cognitive Services resources and manage their resource keys within an approved scope.; and Manage Azure OpenAI deployments, fine-tuning, content filters, and resource configuration when full Cognitive Services control-plane authority is required.. Practical scope: Assign on one Azure AI services resource for its lifecycle and key management, or at a dedicated resource group only when the principal manages every contained resource. Parent-scope roles are inherited and additive; a subscription Contributor or Owner can supersede a narrower resource assignment.

What permissions does the Cognitive Services Contributor Azure role grant?

The role definition grants 18 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.CognitiveServices/*; Microsoft.Features/features/read; Microsoft.Features/providers/features/read; Microsoft.Features/providers/features/register/action; and Microsoft.Insights/alertRules/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Cognitive Services Contributor Azure role?

Key considerations when assigning Cognitive Services Contributor: The role can create, change, and delete Azure AI resources and can view, copy, or regenerate resource keys, which are bearer credentials for key-authenticated access.; Its definition excludes writing or deleting responsible-AI policy and external safety-provider resources, but other broad resource operations remain.; and No DataActions are present; nevertheless, possession of retrieved keys can provide a separate data-plane access path.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →