Azure AI + machine learning built-in role
Cognitive Services Language Writer
Reads, tests, creates, modifies, and trains Azure Language projects but excludes project and deployment deletion, model deployment, deployment swapping, and selected production endpoint changes. Resource and role reads are control-plane Actions; authoring and runtime work is performed through DataActions and NotDataActions. Current Azure Language core capabilities recommended for new development are Language Detection, PII detection, Text Analytics for Health, prebuilt NER, and Custom NER. Conversational Language Understanding, Custom Text Classification, Orchestration Workflow, Custom Question Answering, Sentiment Analysis and Opinion Mining, Key Phrase Extraction, and Summarization retire from Azure Language on 2029-03-31; Entity Linking retires on 2028-09-01.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: f2310ca1-dc64-4889-bb49-c8e0fa3d47a8
Control-plane actions (3)
Microsoft.CognitiveServices/*/readMicrosoft.Authorization/roleAssignments/readMicrosoft.Authorization/roleDefinitions/read
Data-plane actions (4)
Microsoft.CognitiveServices/accounts/LanguageAuthoring/*Microsoft.CognitiveServices/accounts/ConversationalLanguageUnderstanding/*Microsoft.CognitiveServices/accounts/Language/*Microsoft.CognitiveServices/accounts/TextAnalytics/*
Excluded actions (7)
Microsoft.CognitiveServices/accounts/LanguageAuthoring/projects/publish/actionMicrosoft.CognitiveServices/accounts/ConversationalLanguageUnderstanding/projects/deployments/writeMicrosoft.CognitiveServices/accounts/TextAnalytics/QnaMaker/*Microsoft.CognitiveServices/accounts/Language/*/projects/deleteMicrosoft.CognitiveServices/accounts/Language/*/projects/deployments/writeMicrosoft.CognitiveServices/accounts/Language/*/projects/deployments/deleteMicrosoft.CognitiveServices/accounts/Language/*/projects/deployments/swap/action
Assignable scopes (1)
/
Practical scope
Assign on the individual Azure Language resource where the collaborator authors projects. Parent-scope assignments are inherited by all Language resources below the selected scope.
Common use cases (2)
- Build, modify, train, and validate continued core Custom NER projects while a separate owner controls production release.
- Modify or retrain an existing retiring-feature project only when needed to preserve service during migration or validate the replacement.
Prerequisites (2)
- Enable Microsoft Entra authentication by using a custom subdomain on the Azure Language resource.
- Define a release process in which a Language Owner reviews trained changes, and require a dated migration plan before changing any retiring-feature project.
Best practices (4)
- Use Microsoft Foundry for every net-new project that would otherwise depend on a retiring Azure Language capability.
- Use Writer for authors and keep production deployment and deletion with Language Owner.
- Do not create a replacement project on a retiring Azure Language capability; build that replacement in Microsoft Foundry.
- Use Reader for migration testers who do not modify or train source projects.
Security considerations (3)
- The role can change project training content and models, so it can affect future production behavior even though it cannot deploy those changes.
- Its NotDataActions protect deployment and deletion operations, but another additive role can grant the excluded capabilities.
- Retirement does not remove authoring access before decommissioning; a parent-scope assignment grants that access across all inherited Language resources.
Assignment guidance
Assign Cognitive Services Language Writer on the authoring resource to collaborators working on continued core Custom NER or an approved migration of an existing retiring project. Keep release and deletion with Owner. Use Microsoft Foundry for every net-new project that would otherwise depend on a retiring Azure Language capability.
Related roles (2)
- Cognitive Services Language Reader: Narrower role for read, test, export, and evaluation review without authoring changes.
- Cognitive Services Language Owner: Adds deployment, deletion, and full production lifecycle authority.
Editorial sources (15)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Azure Language service - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is Azure Language in Foundry Tools - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Migrate to Azure Language from Language Understanding (LUIS) or QnA Maker - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Conversational Language Understanding - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Custom text classification - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Orchestration workflows - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is custom question answering? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is sentiment analysis and opinion mining in Azure Language service? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is key phrase extraction in Azure Language in Foundry Tools? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is summarization? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- What is entity linking in Azure Language in Foundry Tools? - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.