Azure AI + machine learning built-in role

Cognitive Services Language Reader

Reads, tests, exports, and reviews Azure Language projects and evaluation results without authoring, deploying, or deleting them. Resource and role reads are control-plane Actions; project reads, tests, exports, and supported runtime analysis are DataActions. Current Azure Language core capabilities recommended for new development are Language Detection, PII detection, Text Analytics for Health, prebuilt NER, and Custom NER. Conversational Language Understanding, Custom Text Classification, Orchestration Workflow, Custom Question Answering, Sentiment Analysis and Opinion Mining, Key Phrase Extraction, and Summarization retire from Azure Language on 2029-03-31; Entity Linking retires on 2028-09-01.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 7628b7b8-a8b2-4cdc-b46f-e9b35248918e

Control-plane actions (3)

Data-plane actions (16)

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on the individual Azure Language resource containing the projects the reviewer validates. Parent-scope assignments are inherited by every Language resource below the selected scope.

Common use cases (2)

Prerequisites (2)

Best practices (4)

Security considerations (3)

Assignment guidance

Assign Cognitive Services Language Reader on the specific resource to reviewers of continued core workloads or approved migration work. Elevate only for documented authoring or release duties. Use Microsoft Foundry for every net-new project that would otherwise depend on a retiring Azure Language capability.

Related roles (2)

Common questions

When should I assign the Cognitive Services Language Reader Azure role?

Assign Cognitive Services Language Reader when you need to: Validate continued core Language Detection, PII, Text Analytics for Health, prebuilt NER, or Custom NER workloads without changing them.; and Review and export an existing retiring-feature project only for migration assessment, parity testing, or decommissioning evidence.. Practical scope: Assign on the individual Azure Language resource containing the projects the reviewer validates. Parent-scope assignments are inherited by every Language resource below the selected scope.

What permissions does the Cognitive Services Language Reader Azure role grant?

The role definition grants 19 combined control-plane and data-plane actions. Representative operations include: Microsoft.CognitiveServices/*/read; Microsoft.Authorization/roleAssignments/read; Microsoft.Authorization/roleDefinitions/read; Microsoft.CognitiveServices/accounts/LanguageAuthoring/*/read; Microsoft.CognitiveServices/accounts/ConversationalLanguageUnderstanding/*/read; and Microsoft.CognitiveServices/accounts/ConversationalLanguageUnderstanding/projects/export/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Cognitive Services Language Reader Azure role?

Key considerations when assigning Cognitive Services Language Reader: Read and test DataActions can expose project assets, evaluation results, exported project content, and runtime analysis results.; The role cannot author, deploy, or delete projects, but additive broader assignments can grant those operations.; and Retirement does not automatically remove assignments or exported data, so access cleanup remains part of decommissioning.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (15)

Official Microsoft Learn documentation →