Azure AI + machine learning built-in role

Cognitive Services Custom Vision Trainer

For a supported existing Custom Vision workload, views and edits projects, trains models, and publishes, unpublishes, or exports model iterations, but cannot create, import, export, or delete the project itself. Resource reads are control-plane Actions; project and model work uses DataActions. Custom Vision is supported for existing customers only until its retirement on 2028-09-25; service calls fail after that date.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 0a5ae4ab-0d65-4eeb-be61-29fc9b54394b

Control-plane actions (1)

Data-plane actions (1)

Excluded actions (4)

Assignable scopes (1)

Practical scope

For an existing workload or migration only, assign on the Custom Vision training resource containing the projects the trainer maintains. Parent-scope assignments are inherited by every Custom Vision resource below the selected scope.

Common use cases (2)

Prerequisites (2)

Best practices (4)

Security considerations (3)

Assignment guidance

For a supported existing workload or migration only, assign Custom Vision Trainer on the training resource to model authors who maintain, export, or validate existing projects during transition. Do not start a net-new Custom Vision workload; evaluate Azure Machine Learning AutoML, Foundry models, or Azure Content Understanding (preview) as documented alternatives.

Related roles (2)

Common questions

When should I assign the Cognitive Services Custom Vision Trainer Azure role?

Assign Cognitive Services Custom Vision Trainer when you need to: Maintain and retrain an existing model during its supported transition window when continuity requires source-service changes.; and Export and compare trained model behavior while a replacement workload is built and validated.. Practical scope: For an existing workload or migration only, assign on the Custom Vision training resource containing the projects the trainer maintains. Parent-scope assignments are inherited by every Custom Vision resource below the selected scope.

What permissions does the Cognitive Services Custom Vision Trainer Azure role grant?

The role definition grants 2 combined control-plane and data-plane actions. Representative operations include: Microsoft.CognitiveServices/*/read; and Microsoft.CognitiveServices/accounts/CustomVision/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Cognitive Services Custom Vision Trainer Azure role?

Key considerations when assigning Cognitive Services Custom Vision Trainer: The role can modify training data and project configuration and can train, publish, unpublish, or export models.; Model export moves trained artifacts outside Custom Vision, and publishing can alter production prediction behavior.; and The role cannot create or delete projects, but it remains broad within every existing project in scope until assignments are removed during decommissioning.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →