Azure AI + machine learning built-in role
Cognitive Services Data Reader
Provides read-oriented Azure AI services data-plane access and no control-plane Actions. For Speech resources, Microsoft documents it as a preview role that can view custom-project data, models, and endpoints and use transcription and synthesis APIs without listing resource keys.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: b59867f0-fa02-499b-be73-45a86b5b3e1c
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (1)
Microsoft.CognitiveServices/*/read
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Azure AI or Speech resource whose data the principal reads. Parent-scope assignments are inherited by every supported Cognitive Services resource below that scope.
Common use cases (2)
- Give a Speech user view access to custom-project data, models, and endpoints and access to transcription and synthesis APIs without key listing.
- Provide generic read DataActions for a supported Azure AI service when its product documentation identifies this role for the workflow.
Prerequisites (2)
- The target service must support Microsoft Entra data-plane authorization; Speech token authentication requires a custom subdomain.
- Verify the product-specific interpretation of the generic read wildcard before assignment because Azure AI services expose different data planes.
Best practices (3)
- Prefer the Speech-specific User role for Speech when its documented boundary fits, because Microsoft warns that generic Cognitive Services role names can be misleading for Speech.
- Assign at the individual resource and use a product-specific role when one is available.
- Treat preview behavior as subject to change and retest application operations after role updates.
Security considerations (3)
- The role has only DataActions and can expose service data even though it cannot read or change Azure resource configuration.
- For Speech, read access includes custom-project data, models, endpoints, and transcription and synthesis APIs.
- A parent-scope assignment can expose data from multiple inherited Azure AI resources.
Assignment guidance
Assign Cognitive Services Data Reader directly on the supported Azure AI resource only after confirming the product-specific data-plane behavior. For Speech, prefer Cognitive Services Speech User when the documented Speech-specific role is suitable.
Related roles (2)
- Cognitive Services Speech User: The Speech-specific read and API role Microsoft recommends over generic Cognitive Services roles.
- Cognitive Services Speech Contributor: Adds create, edit, and delete access to Speech custom-project data, models, and endpoints.
Editorial sources (5)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Speech resources - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.