Azure AI + machine learning built-in role

Cognitive Services Speech User

Uses real-time and batch transcription and synthesis APIs and views custom-project data, models, and endpoints without full custom-project create, edit, or delete authority. Resource and role visibility is provided by control-plane read Actions; Speech API and project access is provided by DataActions, with sensitive custom-voice dataset file and utterance reads excluded.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: f2dc8367-1007-4938-bd23-fe263f013447

Control-plane actions (3)

Data-plane actions (19)

Excluded actions (2)

Assignable scopes (1)

Practical scope

Assign on the individual Speech resource used by the caller. Parent-scope assignments are inherited by every Speech resource below the selected scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Cognitive Services Speech User directly on the Speech resource to applications or users that call Speech APIs and view custom-project assets. Elevate to Speech Contributor only for full project authoring and deletion, and complete the applicable Limited Access registration for custom neural voice, personal voice, custom text-to-speech avatar, or Speaker Recognition when used.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →