Azure AI + machine learning built-in role

Cognitive Services QnA Maker Reader

Formerly read, downloaded, and tested QnA Maker knowledge bases and read endpoint keys and settings. Azure AI QnA Maker retired on March 31, 2025. This overlay is retained only for migration and access cleanup; it is not a recommendation for a new assignment.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 466ccd10-b268-4a11-b098-b4849f024126

Control-plane actions (3)

Data-plane actions (18)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Azure role assignments apply at the selected scope and are inherited by child scopes. Use the narrowest supported resource, resource-group, subscription, or management-group scope that contains the intended resources. Existing assignments for this retired service must be removed at the scope where they were created; an inherited assignment cannot be removed from a child resource.

Common use cases (2)

Prerequisites (2)

Best practices (4)

Security considerations (2)

Assignment guidance

Do not assign this role. Locate existing assignments in Access control (IAM), confirm the retired workload no longer depends on them, and remove each assignment at its originating scope. Reassess access separately for the replacement service.

Common questions

When should I assign the Cognitive Services QnA Maker Reader Azure role?

Assign Cognitive Services QnA Maker Reader when you need to: Inventory principals and automation that still hold this legacy role before migration or cleanup begins. Recover and migrate existing knowledge-base content through the documented Azure Language migration path. Custom Question Answering is itself scheduled to retire on March 31, 2029, so direct new development and long-term migration planning to current Microsoft Foundry models.; and Remove stale direct or inherited assignments after the replacement workload and rollback plan have been verified.. Practical scope: Azure role assignments apply at the selected scope and are inherited by child scopes. Use the narrowest supported resource, resource-group, subscription, or management-group scope that contains the intended resources. Existing assignments for this retired service must be removed at the scope where they were created; an inherited assignment cannot be removed from a child resource.

What permissions does the Cognitive Services QnA Maker Reader Azure role grant?

The role definition grants 21 combined control-plane and data-plane actions. Representative operations include: Microsoft.CognitiveServices/*/read; Microsoft.Authorization/roleAssignments/read; Microsoft.Authorization/roleDefinitions/read; Microsoft.CognitiveServices/accounts/QnAMaker/knowledgebases/read; Microsoft.CognitiveServices/accounts/QnAMaker/knowledgebases/download/read; and Microsoft.CognitiveServices/accounts/QnAMaker/knowledgebases/generateanswer/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Cognitive Services QnA Maker Reader Azure role?

Key considerations when assigning Cognitive Services QnA Maker Reader: The legacy role exposed knowledge-base content, test answers, endpoint keys, and endpoint settings even though it could not edit or publish the knowledge base.; and A stale parent-scope assignment remains inherited by child resources until it is removed at the originating scope.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →