Azure AI + machine learning built-in role

Cognitive Services Custom Vision Labeler

For a supported existing Custom Vision workload, views projects and changes only training images, image regions, tags, and suggested labels. Resource reads are control-plane Actions; the labeling workflow uses Custom Vision DataActions. Custom Vision is supported for existing customers only until its retirement on 2028-09-25; service calls fail after that date.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 88424f51-ebe7-446f-bc41-7fa16989e96c

Control-plane actions (1)

Data-plane actions (6)

Excluded actions (1)

Assignable scopes (1)

Practical scope

For an existing workload or migration only, assign on the Custom Vision training resource containing the approved labeling project. Parent-scope assignments are inherited and extend image and tag access across every contained Custom Vision resource.

Common use cases (2)

Prerequisites (2)

Best practices (4)

Security considerations (3)

Assignment guidance

For a supported existing workload or migration only, assign Custom Vision Labeler on the specific training resource to users or groups that maintain or prepare its labeled data for transition. Do not start a net-new Custom Vision workload; evaluate Azure Machine Learning AutoML, Foundry models, or Azure Content Understanding (preview) as documented alternatives.

Related roles (2)

Common questions

When should I assign the Cognitive Services Custom Vision Labeler Azure role?

Assign Cognitive Services Custom Vision Labeler when you need to: Correct or complete labels needed to sustain an existing model while migration is in progress.; and Review annotations and export-ready dataset quality before moving training data to a documented alternative.. Practical scope: For an existing workload or migration only, assign on the Custom Vision training resource containing the approved labeling project. Parent-scope assignments are inherited and extend image and tag access across every contained Custom Vision resource.

What permissions does the Cognitive Services Custom Vision Labeler Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.CognitiveServices/*/read; Microsoft.CognitiveServices/accounts/CustomVision/*/read; Microsoft.CognitiveServices/accounts/CustomVision/projects/predictions/query/action; Microsoft.CognitiveServices/accounts/CustomVision/projects/images/*; Microsoft.CognitiveServices/accounts/CustomVision/projects/tags/*; and Microsoft.CognitiveServices/accounts/CustomVision/projects/images/suggested/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Cognitive Services Custom Vision Labeler Azure role?

Key considerations when assigning Cognitive Services Custom Vision Labeler: The role exposes training images and prediction images returned by its documented query operation and can change or delete image annotations and tags.; It cannot train, publish, or delete the project, limiting model lifecycle authority.; and Migration exports and parent-scope assignments can expose training content beyond the intended project boundary.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →