Azure AI + machine learning built-in role
Cognitive Services QnA Maker Editor
Formerly created, edited, imported, exported, trained, and tested QnA Maker knowledge bases without publishing or deleting them. Azure AI QnA Maker retired on March 31, 2025. This overlay is retained only for migration and access cleanup; it is not a recommendation for a new assignment.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: f4cc2bf9-21be-47a1-bdf1-5c5804381025
Control-plane actions (3)
Microsoft.CognitiveServices/*/readMicrosoft.Authorization/roleAssignments/readMicrosoft.Authorization/roleDefinitions/read
Data-plane actions (39)
Microsoft.CognitiveServices/accounts/QnAMaker/knowledgebases/readMicrosoft.CognitiveServices/accounts/QnAMaker/knowledgebases/download/readMicrosoft.CognitiveServices/accounts/QnAMaker/knowledgebases/create/writeMicrosoft.CognitiveServices/accounts/QnAMaker/knowledgebases/writeMicrosoft.CognitiveServices/accounts/QnAMaker/knowledgebases/generateanswer/actionMicrosoft.CognitiveServices/accounts/QnAMaker/knowledgebases/train/actionMicrosoft.CognitiveServices/accounts/QnAMaker/alterations/readMicrosoft.CognitiveServices/accounts/QnAMaker/alterations/writeMicrosoft.CognitiveServices/accounts/QnAMaker/endpointkeys/readMicrosoft.CognitiveServices/accounts/QnAMaker/endpointkeys/refreshkeys/actionMicrosoft.CognitiveServices/accounts/QnAMaker/endpointsettings/readMicrosoft.CognitiveServices/accounts/QnAMaker/endpointsettings/writeMicrosoft.CognitiveServices/accounts/QnAMaker/operations/readMicrosoft.CognitiveServices/accounts/QnAMaker.v2/knowledgebases/readMicrosoft.CognitiveServices/accounts/QnAMaker.v2/knowledgebases/download/readMicrosoft.CognitiveServices/accounts/QnAMaker.v2/knowledgebases/create/writeMicrosoft.CognitiveServices/accounts/QnAMaker.v2/knowledgebases/writeMicrosoft.CognitiveServices/accounts/QnAMaker.v2/knowledgebases/generateanswer/actionMicrosoft.CognitiveServices/accounts/QnAMaker.v2/knowledgebases/train/actionMicrosoft.CognitiveServices/accounts/QnAMaker.v2/alterations/readMicrosoft.CognitiveServices/accounts/QnAMaker.v2/alterations/writeMicrosoft.CognitiveServices/accounts/QnAMaker.v2/endpointkeys/readMicrosoft.CognitiveServices/accounts/QnAMaker.v2/endpointkeys/refreshkeys/actionMicrosoft.CognitiveServices/accounts/QnAMaker.v2/endpointsettings/readMicrosoft.CognitiveServices/accounts/QnAMaker.v2/endpointsettings/writeMicrosoft.CognitiveServices/accounts/QnAMaker.v2/operations/readMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/knowledgebases/readMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/knowledgebases/download/readMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/knowledgebases/create/writeMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/knowledgebases/writeMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/knowledgebases/generateanswer/actionMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/knowledgebases/train/actionMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/alterations/readMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/alterations/writeMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/endpointkeys/readMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/endpointkeys/refreshkeys/actionMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/endpointsettings/readMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/endpointsettings/writeMicrosoft.CognitiveServices/accounts/TextAnalytics/QnAMaker/operations/read
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Azure role assignments apply at the selected scope and are inherited by child scopes. Use the narrowest supported resource, resource-group, subscription, or management-group scope that contains the intended resources. Existing assignments for this retired service must be removed at the scope where they were created; an inherited assignment cannot be removed from a child resource.
Common use cases (2)
- Inventory principals and automation that still hold this legacy role before migration or cleanup begins. Recover and migrate existing knowledge-base content through the documented Azure Language migration path. Custom Question Answering is itself scheduled to retire on March 31, 2029, so direct new development and long-term migration planning to current Microsoft Foundry models.
- Remove stale direct or inherited assignments after the replacement workload and rollback plan have been verified.
Prerequisites (2)
- Identify the legacy resource, every direct and inherited assignment, and the principal or group that received the role.
- The cleanup administrator needs Microsoft.Authorization/roleAssignments/delete at the scope where each assignment was created.
Best practices (4)
- Do not create a new assignment for this retired service.
- Recover and migrate existing knowledge-base content through the documented Azure Language migration path. Custom Question Answering is itself scheduled to retire on March 31, 2029, so direct new development and long-term migration planning to current Microsoft Foundry models.
- Select roles for the replacement service from its current product documentation rather than carrying this legacy role forward.
- Remove assignments at their originating scopes after migration validation and retain an auditable record of the cleanup.
Security considerations (2)
- The legacy role could read endpoint keys and change knowledge-base content and endpoint settings through data-plane operations.
- A stale parent-scope assignment remains inherited by child resources until it is removed at the originating scope.
Assignment guidance
Do not assign this role. Locate existing assignments in Access control (IAM), confirm the retired workload no longer depends on them, and remove each assignment at its originating scope. Reassess access separately for the replacement service.
Editorial sources (8)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices. Retrieved 2026-07-17.
- Understand Azure role definitions - Azure RBAC | Microsoft Learn →
Supports: Security considerations. Retrieved 2026-07-17.
- Remove Azure role assignments - Azure RBAC | Microsoft Learn →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance. Retrieved 2026-07-17.
- Language understanding - Bot Service | Microsoft Learn →
Supports: Description, Common use cases, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Migrate to Azure Language from Language Understanding (LUIS) or QnA Maker - Foundry Tools | Microsoft Learn →
Supports: Description, Common use cases, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- What is custom question answering? - Foundry Tools | Microsoft Learn →
Supports: Description, Common use cases, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.