Azure AI + machine learning built-in role
Cognitive Services User
Combines broad Azure AI services DataActions with control-plane resource reads and key listing. On Speech resources, Microsoft documents that it effectively provides contributor-level custom-project access and Speech APIs; the generic role name therefore understates its data-plane authority.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: a97b65f3-24c7-4388-baec-2e87135dc908
Control-plane actions (13)
Microsoft.CognitiveServices/*/readMicrosoft.CognitiveServices/accounts/listkeys/actionMicrosoft.Insights/alertRules/readMicrosoft.Insights/diagnosticSettings/readMicrosoft.Insights/logDefinitions/readMicrosoft.Insights/metricdefinitions/readMicrosoft.Insights/metrics/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/operations/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (1)
Microsoft.CognitiveServices/*
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign only on the individual Azure AI services resource whose broad data plane and keys the principal requires. Parent-scope assignments are inherited by every supported Cognitive Services resource below the selected scope.
Common use cases (2)
- Support a legacy Azure AI application that requires broad Cognitive Services data-plane access and resource key listing.
- For Speech, provide create, edit, delete, transcription, and synthesis access when a product-specific role cannot be used for an established compatibility requirement.
Prerequisites (2)
- Confirm the target service's interpretation of the generic Microsoft.CognitiveServices wildcard before assignment.
- For Speech with Microsoft Entra authentication, configure a custom subdomain; prefer the Speech-specific User or Contributor role for new assignments.
Best practices (3)
- Use product-specific roles such as Speech User, Speech Contributor, OpenAI User, or OpenAI Contributor instead of this generic wildcard role for new workloads.
- Assign at the individual resource and prefer Microsoft Entra tokens over distributing listed keys to clients.
- Treat this as a broad role and use a custom role when the application needs only selected service DataActions.
Security considerations (3)
- The wildcard DataAction can authorize broad service-specific data operations, while listKeys exposes a separate bearer-credential path.
- Microsoft warns that on Speech resources this generic role effectively grants contributor-level project access despite its User name.
- A parent-scope assignment expands both key visibility and data-plane authority across multiple inherited resources.
Assignment guidance
Avoid Cognitive Services User as a default. Assign it directly on one Azure AI resource only for a reviewed compatibility case requiring both broad DataActions and key listing; otherwise choose the documented product-specific role and keep key access separate.
Related roles (3)
- Cognitive Services Speech User: Speech-specific role Microsoft recommends for API use and view-oriented custom-project access without key listing.
- Cognitive Services Speech Contributor: Speech-specific full project role without resource key listing.
- Cognitive Services Contributor: Control-plane resource and key administrator with no DataActions in the imported definition.
Editorial sources (6)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Speech resources - Foundry Tools | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Role-based access control for Azure OpenAI (classic) - Microsoft Foundry (classic) portal | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.