Azure AI + machine learning built-in role

Cognitive Services Language Owner

Provides full read, test, write, train, deploy, and delete access for Azure Language projects and can list resource keys. Resource, role, and key reads are control-plane Actions; Language authoring and runtime capabilities are DataActions, with legacy QnA Maker operations excluded. Current Azure Language core capabilities recommended for new development are Language Detection, PII detection, Text Analytics for Health, prebuilt NER, and Custom NER. Conversational Language Understanding, Custom Text Classification, Orchestration Workflow, Custom Question Answering, Sentiment Analysis and Opinion Mining, Key Phrase Extraction, and Summarization retire from Azure Language on 2029-03-31; Entity Linking retires on 2028-09-01.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: f07febfe-79bc-46b1-8b37-790e26e6e498

Control-plane actions (4)

Data-plane actions (4)

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on the individual Azure Language resource that contains the production projects the owner governs. Resource-group, subscription, or management-group assignments are inherited by every Language resource below that scope.

Common use cases (2)

Prerequisites (2)

Best practices (4)

Security considerations (3)

Assignment guidance

Assign Cognitive Services Language Owner on the production Language resource only to gatekeepers for continued core workloads or approved migration work. Give authors Writer and testers Reader. Use Microsoft Foundry for every net-new project that would otherwise depend on a retiring Azure Language capability.

Related roles (2)

Common questions

When should I assign the Cognitive Services Language Owner Azure role?

Assign Cognitive Services Language Owner when you need to: Act as the production gatekeeper for continued core Azure Language workloads, including Custom NER authoring and supported prebuilt runtime features.; and Maintain, export, deploy, or remove an existing retiring-feature project only as part of continuity and migration before its documented retirement date.. Practical scope: Assign on the individual Azure Language resource that contains the production projects the owner governs. Resource-group, subscription, or management-group assignments are inherited by every Language resource below that scope.

What permissions does the Cognitive Services Language Owner Azure role grant?

The role definition grants 8 combined control-plane and data-plane actions. Representative operations include: Microsoft.CognitiveServices/*/read; Microsoft.CognitiveServices/accounts/listkeys/action; Microsoft.Authorization/roleAssignments/read; Microsoft.Authorization/roleDefinitions/read; Microsoft.CognitiveServices/accounts/LanguageAuthoring/*; and Microsoft.CognitiveServices/accounts/ConversationalLanguageUnderstanding/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Cognitive Services Language Owner Azure role?

Key considerations when assigning Cognitive Services Language Owner: The role can alter and delete projects, trained models, and deployments and can directly affect production Language endpoints.; The list-keys Action exposes a key-based credential path in addition to Microsoft Entra DataActions.; and A role assignment does not extend a retiring feature beyond its retirement date; inherited Owner or Contributor assignments can still override the separation intended during migration.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (15)

Official Microsoft Learn documentation →