Azure AI + machine learning built-in role

Cognitive Services Face Recognizer

Invokes the Face API detection, verification, identification, grouping, similarity, liveness, and session DataActions published in the canonical role definition without Face collection create or delete operations. It has no Azure resource-management Actions. The reviewed Face Limited Access page documents registration for identification and verification; this overlay makes no liveness assignment recommendation without separate official feature-access evidence.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 9894cab4-e18a-44aa-828b-cb588cd6f2d7

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (12)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Face resource that hosts the approved inference endpoint. A parent-scope assignment is inherited by every Face resource below it and broadens biometric processing authority.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Face Recognizer to the runtime identity on the individual Face resource for detection or, after the applicable approval, identification or verification. No liveness assignment recommendation is made here. Do not treat RBAC assignment as a substitute for feature enablement, registration, or use-case approval.

Common questions

When should I assign the Cognitive Services Face Recognizer Azure role?

Assign Cognitive Services Face Recognizer when you need to: Allow an approved application identity to perform Face detection and the registered Limited Access identification or verification scenario.; and Run the canonical detection, grouping, and similarity inference operations without granting Face collection create or delete operations.. Practical scope: Assign on the individual Face resource that hosts the approved inference endpoint. A parent-scope assignment is inherited by every Face resource below it and broadens biometric processing authority.

What permissions does the Cognitive Services Face Recognizer Azure role grant?

The role definition grants 12 combined control-plane and data-plane actions. Representative operations include: Microsoft.CognitiveServices/accounts/Face/detect/action; Microsoft.CognitiveServices/accounts/Face/verify/action; Microsoft.CognitiveServices/accounts/Face/identify/action; Microsoft.CognitiveServices/accounts/Face/group/action; Microsoft.CognitiveServices/accounts/Face/findsimilars/action; and Microsoft.CognitiveServices/accounts/Face/detectliveness/multimodal/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Cognitive Services Face Recognizer Azure role?

Key considerations when assigning Cognitive Services Face Recognizer: Identification and verification are Limited Access biometric operations. The role also contains liveness and session DataActions, but the reviewed Face registration page does not establish that those operations share the same approval.; Azure Face recognition is prohibited for use by or for U.S. police departments.; and The role has no control-plane Actions, but its DataActions can process sensitive biometric inputs and return recognition results.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →