Azure AI + machine learning built-in role

Cognitive Services OpenAI User

Views an Azure OpenAI resource, available models, and existing deployments and makes inference calls with Microsoft Entra authentication. The current role matrix documents Chat, Completions, and DALL-E (preview) playground use against already deployed models; the canonical definition contains the complete DataAction inventory.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5e0bd9bd-7b93-4f28-af87-19fc36ad61bd

Control-plane actions (3)

Data-plane actions (16)

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on the individual Azure OpenAI resource used by the application or person. Parent-scope assignments are inherited by all Azure OpenAI resources below the selected scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Cognitive Services OpenAI User directly on the Azure OpenAI resource to the runtime identity or user that invokes existing deployments. Elevate to OpenAI Contributor only for deployment and fine-tuning work and grant quota and connected-resource access separately.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →