Azure AI + machine learning built-in role

Cognitive Services Language Writer

Reads, tests, creates, modifies, and trains Azure Language projects but excludes project and deployment deletion, model deployment, deployment swapping, and selected production endpoint changes. Resource and role reads are control-plane Actions; authoring and runtime work is performed through DataActions and NotDataActions. Current Azure Language core capabilities recommended for new development are Language Detection, PII detection, Text Analytics for Health, prebuilt NER, and Custom NER. Conversational Language Understanding, Custom Text Classification, Orchestration Workflow, Custom Question Answering, Sentiment Analysis and Opinion Mining, Key Phrase Extraction, and Summarization retire from Azure Language on 2029-03-31; Entity Linking retires on 2028-09-01.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: f2310ca1-dc64-4889-bb49-c8e0fa3d47a8

Control-plane actions (3)

Data-plane actions (4)

Excluded actions (7)

Assignable scopes (1)

Practical scope

Assign on the individual Azure Language resource where the collaborator authors projects. Parent-scope assignments are inherited by all Language resources below the selected scope.

Common use cases (2)

Prerequisites (2)

Best practices (4)

Security considerations (3)

Assignment guidance

Assign Cognitive Services Language Writer on the authoring resource to collaborators working on continued core Custom NER or an approved migration of an existing retiring project. Keep release and deletion with Owner. Use Microsoft Foundry for every net-new project that would otherwise depend on a retiring Azure Language capability.

Related roles (2)

Common questions

When should I assign the Cognitive Services Language Writer Azure role?

Assign Cognitive Services Language Writer when you need to: Build, modify, train, and validate continued core Custom NER projects while a separate owner controls production release.; and Modify or retrain an existing retiring-feature project only when needed to preserve service during migration or validate the replacement.. Practical scope: Assign on the individual Azure Language resource where the collaborator authors projects. Parent-scope assignments are inherited by all Language resources below the selected scope.

What permissions does the Cognitive Services Language Writer Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.CognitiveServices/*/read; Microsoft.Authorization/roleAssignments/read; Microsoft.Authorization/roleDefinitions/read; Microsoft.CognitiveServices/accounts/LanguageAuthoring/*; Microsoft.CognitiveServices/accounts/ConversationalLanguageUnderstanding/*; and Microsoft.CognitiveServices/accounts/Language/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Cognitive Services Language Writer Azure role?

Key considerations when assigning Cognitive Services Language Writer: The role can change project training content and models, so it can affect future production behavior even though it cannot deploy those changes.; Its NotDataActions protect deployment and deletion operations, but another additive role can grant the excluded capabilities.; and Retirement does not remove authoring access before decommissioning; a parent-scope assignment grants that access across all inherited Language resources.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (15)

Official Microsoft Learn documentation →