Azure AI + machine learning built-in role
Cognitive Services Custom Vision Trainer
For a supported existing Custom Vision workload, views and edits projects, trains models, and publishes, unpublishes, or exports model iterations, but cannot create, import, export, or delete the project itself. Resource reads are control-plane Actions; project and model work uses DataActions. Custom Vision is supported for existing customers only until its retirement on 2028-09-25; service calls fail after that date.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 0a5ae4ab-0d65-4eeb-be61-29fc9b54394b
Control-plane actions (1)
Microsoft.CognitiveServices/*/read
Data-plane actions (1)
Microsoft.CognitiveServices/accounts/CustomVision/*
Excluded actions (4)
Microsoft.CognitiveServices/accounts/CustomVision/projects/actionMicrosoft.CognitiveServices/accounts/CustomVision/projects/deleteMicrosoft.CognitiveServices/accounts/CustomVision/projects/import/actionMicrosoft.CognitiveServices/accounts/CustomVision/projects/export/read
Assignable scopes (1)
/
Practical scope
For an existing workload or migration only, assign on the Custom Vision training resource containing the projects the trainer maintains. Parent-scope assignments are inherited by every Custom Vision resource below the selected scope.
Common use cases (2)
- Maintain and retrain an existing model during its supported transition window when continuity requires source-service changes.
- Export and compare trained model behavior while a replacement workload is built and validated.
Prerequisites (2)
- A supported existing project, its training data, and an approved migration plan must already exist.
- Training data, tags, evaluation criteria, replacement target, and rollback plan must be approved.
Best practices (4)
- Microsoft directs customers to make a transition plan by 2026-09-25 and complete migration before retirement.
- Do not start a net-new Custom Vision workload; evaluate Azure Machine Learning AutoML, Foundry models, or Azure Content Understanding (preview) as documented alternatives.
- Use Trainer instead of Contributor for model authors who should not create or delete projects.
- Separate production deployment responsibility with the Deployment role when release approval must be independent from training.
Security considerations (3)
- The role can modify training data and project configuration and can train, publish, unpublish, or export models.
- Model export moves trained artifacts outside Custom Vision, and publishing can alter production prediction behavior.
- The role cannot create or delete projects, but it remains broad within every existing project in scope until assignments are removed during decommissioning.
Assignment guidance
For a supported existing workload or migration only, assign Custom Vision Trainer on the training resource to model authors who maintain, export, or validate existing projects during transition. Do not start a net-new Custom Vision workload; evaluate Azure Machine Learning AutoML, Foundry models, or Azure Content Understanding (preview) as documented alternatives.
Related roles (2)
- Cognitive Services Custom Vision Contributor: Adds project creation and deletion to the Trainer capabilities.
- Cognitive Services Custom Vision Deployment: Narrower release role for publishing and exporting without project authoring.
Editorial sources (6)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure role-based access control - Custom Vision - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Migrate from Custom Vision Service - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.