Azure AI + machine learning built-in role

Cognitive Services User

Combines broad Azure AI services DataActions with control-plane resource reads and key listing. On Speech resources, Microsoft documents that it effectively provides contributor-level custom-project access and Speech APIs; the generic role name therefore understates its data-plane authority.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a97b65f3-24c7-4388-baec-2e87135dc908

Control-plane actions (13)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign only on the individual Azure AI services resource whose broad data plane and keys the principal requires. Parent-scope assignments are inherited by every supported Cognitive Services resource below the selected scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Avoid Cognitive Services User as a default. Assign it directly on one Azure AI resource only for a reviewed compatibility case requiring both broad DataActions and key listing; otherwise choose the documented product-specific role and keep key access separate.

Related roles (3)

Editorial sources (6)

Official Microsoft Learn documentation →