Azure AI + machine learning built-in role
Cognitive Services Custom Vision Deployment
For a supported existing Custom Vision workload, publishes, unpublishes, and exports models and can view projects without changing project definitions, training images, or tags. Resource reads are control-plane Actions; model deployment and inference operations are DataActions. Custom Vision is supported for existing customers only until its retirement on 2028-09-25; service calls fail after that date.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 5c4089e1-6d96-4d2f-b296-c1bc7137275f
Control-plane actions (1)
Microsoft.CognitiveServices/*/read
Data-plane actions (7)
Microsoft.CognitiveServices/accounts/CustomVision/*/readMicrosoft.CognitiveServices/accounts/CustomVision/projects/predictions/*Microsoft.CognitiveServices/accounts/CustomVision/projects/iterations/publish/*Microsoft.CognitiveServices/accounts/CustomVision/projects/iterations/export/*Microsoft.CognitiveServices/accounts/CustomVision/projects/quicktest/*Microsoft.CognitiveServices/accounts/CustomVision/classify/*Microsoft.CognitiveServices/accounts/CustomVision/detect/*
Excluded actions (1)
Microsoft.CognitiveServices/accounts/CustomVision/projects/export/read
Assignable scopes (1)
/
Practical scope
For an existing workload or migration only, assign on the Custom Vision training resource that contains the models the deployer releases or exports. A parent assignment is inherited by all Custom Vision resources below it and broadens deployment authority.
Common use cases (2)
- Maintain a supported existing deployment by publishing or unpublishing an approved iteration without granting project authoring.
- Export a trained model and validate prediction behavior as part of a controlled migration workflow.
Prerequisites (2)
- A supported existing Custom Vision project and trained model iteration must already exist and be approved for release, export, or migration validation.
- The replacement target and rollback plan must be defined before changing an existing production deployment.
Best practices (4)
- Microsoft directs customers to make a transition plan by 2026-09-25 and complete migration before retirement.
- Do not start a net-new Custom Vision workload; evaluate Azure Machine Learning AutoML, Foundry models, or Azure Content Understanding (preview) as documented alternatives.
- Separate deployment from training and labeling when production release requires an independent approver.
- Use Reader when the principal only reviews a project and does not publish or export models.
Security considerations (3)
- Publishing changes which model version serves prediction requests, while unpublishing can interrupt a production endpoint.
- Model export can move trained artifacts outside the managed Custom Vision service boundary.
- Retirement makes continuity dependent on completing and validating the replacement before 2028-09-25.
Assignment guidance
For a supported existing workload or migration only, assign Custom Vision Deployment on the training resource to the release identity responsible for publishing, unpublishing, exporting, or migration validation. Do not start a net-new Custom Vision workload; evaluate Azure Machine Learning AutoML, Foundry models, or Azure Content Understanding (preview) as documented alternatives.
Related roles (2)
- Cognitive Services Custom Vision Trainer: Authors and trains models and also has publish, unpublish, and export capability.
- Cognitive Services Custom Vision Reader: View-only alternative without release or inference operations.
Editorial sources (6)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure role-based access control - Custom Vision - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Migrate from Custom Vision Service - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.