Azure AI + machine learning built-in role
Cognitive Services Language Reader
Reads, tests, exports, and reviews Azure Language projects and evaluation results without authoring, deploying, or deleting them. Resource and role reads are control-plane Actions; project reads, tests, exports, and supported runtime analysis are DataActions. Current Azure Language core capabilities recommended for new development are Language Detection, PII detection, Text Analytics for Health, prebuilt NER, and Custom NER. Conversational Language Understanding, Custom Text Classification, Orchestration Workflow, Custom Question Answering, Sentiment Analysis and Opinion Mining, Key Phrase Extraction, and Summarization retire from Azure Language on 2029-03-31; Entity Linking retires on 2028-09-01.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 7628b7b8-a8b2-4cdc-b46f-e9b35248918e
Control-plane actions (3)
Microsoft.CognitiveServices/*/readMicrosoft.Authorization/roleAssignments/readMicrosoft.Authorization/roleDefinitions/read
Data-plane actions (16)
Microsoft.CognitiveServices/accounts/LanguageAuthoring/*/readMicrosoft.CognitiveServices/accounts/ConversationalLanguageUnderstanding/*/readMicrosoft.CognitiveServices/accounts/ConversationalLanguageUnderstanding/projects/export/actionMicrosoft.CognitiveServices/accounts/Language/*/readMicrosoft.CognitiveServices/accounts/Language/*/projects/export/actionMicrosoft.CognitiveServices/accounts/Language/query-text/actionMicrosoft.CognitiveServices/accounts/Language/query-dataverse/actionMicrosoft.CognitiveServices/accounts/Language/analyze-text/jobs/actionMicrosoft.CognitiveServices/accounts/Language/analyze-text/actionMicrosoft.CognitiveServices/accounts/Language/analyze-text/jobscancel/actionMicrosoft.CognitiveServices/accounts/Language/analyze-conversations/actionMicrosoft.CognitiveServices/accounts/Language/analyze-conversations/jobscancel/actionMicrosoft.CognitiveServices/accounts/Language/analyze-conversations/jobs/actionMicrosoft.CognitiveServices/accounts/Language/query-knowledgebases/actionMicrosoft.CognitiveServices/accounts/Language/generate/actionMicrosoft.CognitiveServices/accounts/TextAnalytics/*
Excluded actions (1)
Microsoft.CognitiveServices/accounts/TextAnalytics/QnaMaker/*
Assignable scopes (1)
/
Practical scope
Assign on the individual Azure Language resource containing the projects the reviewer validates. Parent-scope assignments are inherited by every Language resource below the selected scope.
Common use cases (2)
- Validate continued core Language Detection, PII, Text Analytics for Health, prebuilt NER, or Custom NER workloads without changing them.
- Review and export an existing retiring-feature project only for migration assessment, parity testing, or decommissioning evidence.
Prerequisites (2)
- Enable Microsoft Entra authentication by using a custom subdomain on the Azure Language resource.
- The project must already exist, the reviewer must be approved to view its content, and any retiring-feature review must be tied to a migration plan.
Best practices (4)
- Use Microsoft Foundry for every net-new project that would otherwise depend on a retiring Azure Language capability.
- Use Language Reader for testers and reviewers instead of Writer or Owner.
- Use exports from retiring projects only for approved migration and protect them as copies of project content.
- Review inherited Contributor and Owner roles because they take priority over the intended read-only migration boundary.
Security considerations (3)
- Read and test DataActions can expose project assets, evaluation results, exported project content, and runtime analysis results.
- The role cannot author, deploy, or delete projects, but additive broader assignments can grant those operations.
- Retirement does not automatically remove assignments or exported data, so access cleanup remains part of decommissioning.
Assignment guidance
Assign Cognitive Services Language Reader on the specific resource to reviewers of continued core workloads or approved migration work. Elevate only for documented authoring or release duties. Use Microsoft Foundry for every net-new project that would otherwise depend on a retiring Azure Language capability.
Related roles (2)
- Cognitive Services Language Writer: Adds authoring and training while retaining the production deployment and deletion restrictions.
- Cognitive Services Language Owner: Adds full deployment, deletion, and production gatekeeper authority.
Editorial sources (15)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Azure Language service - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is Azure Language in Foundry Tools - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Migrate to Azure Language from Language Understanding (LUIS) or QnA Maker - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Conversational Language Understanding - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Custom text classification - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Orchestration workflows - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is custom question answering? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is sentiment analysis and opinion mining in Azure Language service? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is key phrase extraction in Azure Language in Foundry Tools? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is summarization? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is entity linking in Azure Language in Foundry Tools? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.