Azure AI + machine learning built-in role
Cognitive Services Speech Contributor
Provides full Speech project data-plane access, including creating, editing, and deleting data, tests, models, endpoints, transcriptions, synthesis assets, custom voice assets, and other supported Speech entities. It has resource and role read Actions but does not list resource keys; Speech work is authorized through broad DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 0e75ca1e-0464-4b4d-8b93-68208a576181
Control-plane actions (3)
Microsoft.CognitiveServices/*/readMicrosoft.Authorization/roleAssignments/readMicrosoft.Authorization/roleDefinitions/read
Data-plane actions (8)
Microsoft.CognitiveServices/accounts/SpeechServices/*Microsoft.CognitiveServices/accounts/CustomVoice/*Microsoft.CognitiveServices/accounts/AudioContentCreation/*Microsoft.CognitiveServices/accounts/TTSPlayer/*Microsoft.CognitiveServices/accounts/VideoTranslation/*Microsoft.CognitiveServices/accounts/CustomAvatar/*Microsoft.CognitiveServices/accounts/BatchAvatar/*Microsoft.CognitiveServices/accounts/BatchTextToSpeech/*
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual Speech resource used for project authoring and APIs. A parent assignment is inherited by every Speech resource below that scope and broadens access to their projects, models, endpoints, and APIs.
Common use cases (2)
- Build and administer custom speech, custom voice, transcription, synthesis, avatar, and related Speech projects.
- Use real-time and batch Speech APIs while also creating, changing, and deleting custom-project entities.
Prerequisites (2)
- The Speech resource must exist; Microsoft Entra token authentication requires a custom subdomain.
- Custom neural voice, personal voice, custom text-to-speech avatar, and all Speaker Recognition features require the applicable Limited Access registration and approval; ordinary transcription and standard synthesis are not covered by that blanket requirement.
Best practices (3)
- Use the Speech-specific Contributor role instead of generic Cognitive Services roles for full Speech project administration.
- Assign at the individual Speech resource and use Speech User or Data Reader when project writes and deletes are unnecessary.
- Separate resources by application or environment when different teams should not share custom models and endpoints.
Security considerations (3)
- The broad Speech DataActions can change or delete project data, models, endpoints, transcriptions, synthesis assets, and custom voice or avatar content.
- The role does not list resource keys, but it can access Speech APIs with Microsoft Entra tokens.
- Custom neural voice, personal voice, custom text-to-speech avatar, and Speaker Recognition carry documented Limited Access controls; do not generalize those controls to every Speech API.
Assignment guidance
Assign Cognitive Services Speech Contributor on the specific Speech resource to trusted project authors who manage custom assets and APIs. Give view-oriented users Speech User or Data Reader, and complete the applicable Limited Access registration before using custom neural voice, personal voice, custom text-to-speech avatar, or Speaker Recognition.
Related roles (3)
- Cognitive Services Speech User: Provides Speech APIs and view-oriented custom-project access without full project authoring.
- Cognitive Services Data Reader: Generic preview data-reader alternative that Microsoft lists as view-only for Speech projects and APIs.
- Cognitive Services User: Generic role that Microsoft says effectively provides contributor-level Speech data access and can list keys.
Editorial sources (7)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Speech resources - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Limited Access - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Limited Access features for Foundry Tools - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.