Azure AI + machine learning built-in role
Cognitive Services Face Recognizer
Invokes the Face API detection, verification, identification, grouping, similarity, liveness, and session DataActions published in the canonical role definition without Face collection create or delete operations. It has no Azure resource-management Actions. The reviewed Face Limited Access page documents registration for identification and verification; this overlay makes no liveness assignment recommendation without separate official feature-access evidence.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 9894cab4-e18a-44aa-828b-cb588cd6f2d7
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (12)
Microsoft.CognitiveServices/accounts/Face/detect/actionMicrosoft.CognitiveServices/accounts/Face/verify/actionMicrosoft.CognitiveServices/accounts/Face/identify/actionMicrosoft.CognitiveServices/accounts/Face/group/actionMicrosoft.CognitiveServices/accounts/Face/findsimilars/actionMicrosoft.CognitiveServices/accounts/Face/detectliveness/multimodal/actionMicrosoft.CognitiveServices/accounts/Face/detectliveness/singlemodal/actionMicrosoft.CognitiveServices/accounts/Face/detectlivenesswithverify/singlemodal/actionMicrosoft.CognitiveServices/accounts/Face/*/sessions/actionMicrosoft.CognitiveServices/accounts/Face/*/sessions/deleteMicrosoft.CognitiveServices/accounts/Face/*/sessions/readMicrosoft.CognitiveServices/accounts/Face/*/sessions/audit/read
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Face resource that hosts the approved inference endpoint. A parent-scope assignment is inherited by every Face resource below it and broadens biometric processing authority.
Common use cases (2)
- Allow an approved application identity to perform Face detection and the registered Limited Access identification or verification scenario.
- Run the canonical detection, grouping, and similarity inference operations without granting Face collection create or delete operations.
Prerequisites (2)
- Face identification and verification require Limited Access registration, Microsoft eligibility review, an approved use case, and a supported S0 or E0 resource; detection alone does not require registration.
- Do not treat identification or verification registration as approval for liveness. Confirm liveness availability and access requirements separately before relying on those DataActions.
Best practices (3)
- Assign to the application or managed identity on the individual Face resource only after the use case is approved.
- Keep collection management and resource administration on separate identities and roles.
- Review the assignment, approved Face recognition use case, and any separately enabled liveness scenario whenever the application, population, or processing purpose changes.
Security considerations (3)
- Identification and verification are Limited Access biometric operations. The role also contains liveness and session DataActions, but the reviewed Face registration page does not establish that those operations share the same approval.
- Azure Face recognition is prohibited for use by or for U.S. police departments.
- The role has no control-plane Actions, but its DataActions can process sensitive biometric inputs and return recognition results.
Assignment guidance
Assign Face Recognizer to the runtime identity on the individual Face resource for detection or, after the applicable approval, identification or verification. No liveness assignment recommendation is made here. Do not treat RBAC assignment as a substitute for feature enablement, registration, or use-case approval.
Editorial sources (5)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Limited Access features of Face - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.