Azure AI + machine learning built-in role
Cognitive Services Speech User
Uses real-time and batch transcription and synthesis APIs and views custom-project data, models, and endpoints without full custom-project create, edit, or delete authority. Resource and role visibility is provided by control-plane read Actions; Speech API and project access is provided by DataActions, with sensitive custom-voice dataset file and utterance reads excluded.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: f2dc8367-1007-4938-bd23-fe263f013447
Control-plane actions (3)
Microsoft.CognitiveServices/*/readMicrosoft.Authorization/roleAssignments/readMicrosoft.Authorization/roleDefinitions/read
Data-plane actions (19)
Microsoft.CognitiveServices/accounts/SpeechServices/*/readMicrosoft.CognitiveServices/accounts/SpeechServices/*/transcriptions/readMicrosoft.CognitiveServices/accounts/SpeechServices/*/transcriptions/writeMicrosoft.CognitiveServices/accounts/SpeechServices/*/transcriptions/deleteMicrosoft.CognitiveServices/accounts/SpeechServices/*/transcriptions/actionMicrosoft.CognitiveServices/accounts/SpeechServices/*/frontend/actionMicrosoft.CognitiveServices/accounts/SpeechServices/text-dependent/*/actionMicrosoft.CognitiveServices/accounts/SpeechServices/text-independent/*/actionMicrosoft.CognitiveServices/accounts/SpeechServices/voiceagent/realtime/*Microsoft.CognitiveServices/accounts/SpeechServices/voicelive/realtime/*Microsoft.CognitiveServices/accounts/CustomVoice/*/readMicrosoft.CognitiveServices/accounts/CustomVoice/evaluations/*Microsoft.CognitiveServices/accounts/CustomVoice/longaudiosynthesis/*Microsoft.CognitiveServices/accounts/AudioContentCreation/*Microsoft.CognitiveServices/accounts/TTSPlayer/*Microsoft.CognitiveServices/accounts/VideoTranslation/*Microsoft.CognitiveServices/accounts/CustomAvatar/*/readMicrosoft.CognitiveServices/accounts/BatchAvatar/*Microsoft.CognitiveServices/accounts/BatchTextToSpeech/*
Excluded actions (2)
Microsoft.CognitiveServices/accounts/CustomVoice/datasets/files/readMicrosoft.CognitiveServices/accounts/CustomVoice/datasets/utterances/read
Assignable scopes (1)
/
Practical scope
Assign on the individual Speech resource used by the caller. Parent-scope assignments are inherited by every Speech resource below the selected scope.
Common use cases (2)
- Transcribe or synthesize speech with Microsoft Entra authentication and use the documented real-time and batch Speech APIs.
- Inspect custom Speech project data, tests, models, and endpoints without granting full project administration.
Prerequisites (2)
- The Speech resource and required models or endpoints must already exist; Microsoft Entra authentication requires a custom subdomain.
- If the application uses custom neural voice, personal voice, custom text-to-speech avatar, or Speaker Recognition, complete the applicable Limited Access registration and approval; ordinary transcription and standard synthesis are not covered by that blanket requirement.
Best practices (3)
- Use Speech User for API callers and project viewers instead of Speech Contributor when full project changes are not required.
- Assign at the individual Speech resource and separate production callers from project authors.
- Use a custom role when the caller needs a smaller subset of Speech APIs than this broad user role provides.
Security considerations (3)
- Speech DataActions can process audio, text, transcription, synthesis, voice, avatar, and other application content even though the role cannot manage the Azure resource.
- The role does not list keys and excludes reads of custom-voice dataset files and utterances, but it still includes broad supported API operations.
- Custom neural voice, personal voice, custom text-to-speech avatar, and Speaker Recognition remain subject to their documented Limited Access controls even when RBAC permits related operations.
Assignment guidance
Assign Cognitive Services Speech User directly on the Speech resource to applications or users that call Speech APIs and view custom-project assets. Elevate to Speech Contributor only for full project authoring and deletion, and complete the applicable Limited Access registration for custom neural voice, personal voice, custom text-to-speech avatar, or Speaker Recognition when used.
Related roles (2)
- Cognitive Services Speech Contributor: Adds create, edit, and delete authority across Speech custom-project entities.
- Cognitive Services Data Reader: Generic preview read-oriented data role that Microsoft also lists for Speech resources.
Editorial sources (7)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Speech resources - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Limited Access - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Limited Access features for Foundry Tools - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.