Azure AI + machine learning built-in role

Cognitive Services Speech Contributor

Provides full Speech project data-plane access, including creating, editing, and deleting data, tests, models, endpoints, transcriptions, synthesis assets, custom voice assets, and other supported Speech entities. It has resource and role read Actions but does not list resource keys; Speech work is authorized through broad DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 0e75ca1e-0464-4b4d-8b93-68208a576181

Control-plane actions (3)

Data-plane actions (8)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Speech resource used for project authoring and APIs. A parent assignment is inherited by every Speech resource below that scope and broadens access to their projects, models, endpoints, and APIs.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Cognitive Services Speech Contributor on the specific Speech resource to trusted project authors who manage custom assets and APIs. Give view-oriented users Speech User or Data Reader, and complete the applicable Limited Access registration before using custom neural voice, personal voice, custom text-to-speech avatar, or Speaker Recognition.

Related roles (3)

Common questions

When should I assign the Cognitive Services Speech Contributor Azure role?

Assign Cognitive Services Speech Contributor when you need to: Build and administer custom speech, custom voice, transcription, synthesis, avatar, and related Speech projects.; and Use real-time and batch Speech APIs while also creating, changing, and deleting custom-project entities.. Practical scope: Assign on the individual Speech resource used for project authoring and APIs. A parent assignment is inherited by every Speech resource below that scope and broadens access to their projects, models, endpoints, and APIs.

What permissions does the Cognitive Services Speech Contributor Azure role grant?

The role definition grants 11 combined control-plane and data-plane actions. Representative operations include: Microsoft.CognitiveServices/*/read; Microsoft.Authorization/roleAssignments/read; Microsoft.Authorization/roleDefinitions/read; Microsoft.CognitiveServices/accounts/SpeechServices/*; Microsoft.CognitiveServices/accounts/CustomVoice/*; and Microsoft.CognitiveServices/accounts/AudioContentCreation/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Cognitive Services Speech Contributor Azure role?

Key considerations when assigning Cognitive Services Speech Contributor: The broad Speech DataActions can change or delete project data, models, endpoints, transcriptions, synthesis assets, and custom voice or avatar content.; The role does not list resource keys, but it can access Speech APIs with Microsoft Entra tokens.; and Custom neural voice, personal voice, custom text-to-speech avatar, and Speaker Recognition carry documented Limited Access controls; do not generalize those controls to every Speech API.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →