Azure AI + machine learning built-in role
Cognitive Services Usages Reader
Reads Azure AI services usage and quota information. The role contains one subscription-level control-plane Action and no DataActions, resource administration, model deployment, or inference access.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: bba48692-92b0-4667-a9ad-c31c7b334ac2
Control-plane actions (1)
Microsoft.CognitiveServices/locations/usages/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Microsoft requires this role at subscription scope; it is not available as a resource-level quota role. The assignment exposes usage information for Azure AI services locations in that subscription.
Common use cases (2)
- View Azure OpenAI quota allocations in the Foundry portal.
- Add quota visibility to an OpenAI User, OpenAI Contributor, or Cognitive Services Contributor assignment without granting the broader subscription Reader role.
Prerequisites (2)
- The principal must already have the product role required for its Azure OpenAI or Azure AI service duties because Usages Reader provides little value by itself.
- The role-assignment administrator must be able to create an assignment at subscription scope.
Best practices (3)
- Use Cognitive Services Usages Reader instead of subscription Reader when quota visibility is the only additional requirement.
- Combine it with the resource-scoped product role and review the subscription assignment when responsibilities change.
- Do not use it as a substitute for model deployment, inference, or resource-management roles.
Security considerations (3)
- The role exposes usage and quota allocation metadata across the subscription but cannot change quota or use Azure AI data planes.
- Subscription scope is mandatory, so the principal sees usage information beyond one Azure AI resource.
- Other assigned roles determine whether the principal can deploy models, invoke them, manage resources, or edit quota allocations.
Assignment guidance
Assign Cognitive Services Usages Reader at subscription scope only to principals that must view Azure AI quota. Pair it with the appropriate resource-scoped OpenAI or Cognitive Services role and remove it when quota visibility is no longer needed.
Related roles (3)
- Cognitive Services OpenAI User: Common resource-scoped companion role for inference users that also need quota visibility.
- Cognitive Services OpenAI Contributor: Common resource-scoped companion role for model developers that also need quota visibility.
- Reader: Subscription Reader provides equivalent quota visibility but also grants broader subscription read access.
Editorial sources (5)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Azure OpenAI (classic) - Microsoft Foundry (classic) portal | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.