Azure AI + machine learning built-in role
Cognitive Services Language Owner
Provides full read, test, write, train, deploy, and delete access for Azure Language projects and can list resource keys. Resource, role, and key reads are control-plane Actions; Language authoring and runtime capabilities are DataActions, with legacy QnA Maker operations excluded. Current Azure Language core capabilities recommended for new development are Language Detection, PII detection, Text Analytics for Health, prebuilt NER, and Custom NER. Conversational Language Understanding, Custom Text Classification, Orchestration Workflow, Custom Question Answering, Sentiment Analysis and Opinion Mining, Key Phrase Extraction, and Summarization retire from Azure Language on 2029-03-31; Entity Linking retires on 2028-09-01.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: f07febfe-79bc-46b1-8b37-790e26e6e498
Control-plane actions (4)
Microsoft.CognitiveServices/*/readMicrosoft.CognitiveServices/accounts/listkeys/actionMicrosoft.Authorization/roleAssignments/readMicrosoft.Authorization/roleDefinitions/read
Data-plane actions (4)
Microsoft.CognitiveServices/accounts/LanguageAuthoring/*Microsoft.CognitiveServices/accounts/ConversationalLanguageUnderstanding/*Microsoft.CognitiveServices/accounts/Language/*Microsoft.CognitiveServices/accounts/TextAnalytics/*
Excluded actions (1)
Microsoft.CognitiveServices/accounts/TextAnalytics/QnaMaker/*
Assignable scopes (1)
/
Practical scope
Assign on the individual Azure Language resource that contains the production projects the owner governs. Resource-group, subscription, or management-group assignments are inherited by every Language resource below that scope.
Common use cases (2)
- Act as the production gatekeeper for continued core Azure Language workloads, including Custom NER authoring and supported prebuilt runtime features.
- Maintain, export, deploy, or remove an existing retiring-feature project only as part of continuity and migration before its documented retirement date.
Prerequisites (2)
- Enable Microsoft Entra authentication by using a custom subdomain on the Azure Language resource.
- Classify every target project as a continued core capability or a retiring capability with a funded migration plan, and confirm that the assignee owns production deployment and deletion decisions.
Best practices (4)
- Use Microsoft Foundry for every net-new project that would otherwise depend on a retiring Azure Language capability.
- Keep Language Owner with production gatekeepers and assign Language Writer to collaborators who train changes but must not deploy or delete them.
- Inventory retiring-feature projects and remove their assignments after migration and decommissioning.
- Use Language Reader for validation and evaluation reviewers on continued core workloads or migration work.
Security considerations (3)
- The role can alter and delete projects, trained models, and deployments and can directly affect production Language endpoints.
- The list-keys Action exposes a key-based credential path in addition to Microsoft Entra DataActions.
- A role assignment does not extend a retiring feature beyond its retirement date; inherited Owner or Contributor assignments can still override the separation intended during migration.
Assignment guidance
Assign Cognitive Services Language Owner on the production Language resource only to gatekeepers for continued core workloads or approved migration work. Give authors Writer and testers Reader. Use Microsoft Foundry for every net-new project that would otherwise depend on a retiring Azure Language capability.
Related roles (2)
- Cognitive Services Language Writer: Authors, trains, and tests Language projects but cannot deploy or delete production project resources.
- Cognitive Services Language Reader: Validates, tests, and reviews Language projects without authoring or deployment changes.
Editorial sources (15)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Azure Language service - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is Azure Language in Foundry Tools - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Migrate to Azure Language from Language Understanding (LUIS) or QnA Maker - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Conversational Language Understanding - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Custom text classification - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Orchestration workflows - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is custom question answering? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is sentiment analysis and opinion mining in Azure Language service? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is key phrase extraction in Azure Language in Foundry Tools? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is summarization? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is entity linking in Azure Language in Foundry Tools? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.