Azure AI + machine learning built-in role

Cognitive Services Data Reader

Provides read-oriented Azure AI services data-plane access and no control-plane Actions. For Speech resources, Microsoft documents it as a preview role that can view custom-project data, models, and endpoints and use transcription and synthesis APIs without listing resource keys.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b59867f0-fa02-499b-be73-45a86b5b3e1c

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure AI or Speech resource whose data the principal reads. Parent-scope assignments are inherited by every supported Cognitive Services resource below that scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Cognitive Services Data Reader directly on the supported Azure AI resource only after confirming the product-specific data-plane behavior. For Speech, prefer Cognitive Services Speech User when the documented Speech-specific role is suitable.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →