Azure AI + machine learning built-in role

Cognitive Services Face Recognizer

Invokes the Face API detection, verification, identification, grouping, similarity, liveness, and session DataActions published in the canonical role definition without Face collection create or delete operations. It has no Azure resource-management Actions. The reviewed Face Limited Access page documents registration for identification and verification; this overlay makes no liveness assignment recommendation without separate official feature-access evidence.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 9894cab4-e18a-44aa-828b-cb588cd6f2d7

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (12)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Face resource that hosts the approved inference endpoint. A parent-scope assignment is inherited by every Face resource below it and broadens biometric processing authority.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Face Recognizer to the runtime identity on the individual Face resource for detection or, after the applicable approval, identification or verification. No liveness assignment recommendation is made here. Do not treat RBAC assignment as a substitute for feature enablement, registration, or use-case approval.

Editorial sources (5)

Official Microsoft Learn documentation →