Azure Integration built-in role

DeID Batch Data Owner

Creates, reads, and deletes de-identification batch jobs through data-plane DataActions. Microsoft marks this role and the batch capability as preview and subject to change; it does not manage the de-identification service resource through the control plane.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 8a90fa6b-6997-4a07-8a95-30633a7c97b9

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (3)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the de-identification service that runs the approved batch jobs. Resource-group and subscription assignments are inherited by additional de-identification services and expand batch-job authority beyond one service.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign DeID Batch Data Owner to the approved batch operator on the specific de-identification service. Grant Storage Blob Data Contributor separately to the service managed identity on only the required containers, and use Batch Data Reader for status-only review.

Related roles (3)

Common questions

When should I assign the DeID Batch Data Owner Azure role?

Assign DeID Batch Data Owner when you need to: Create and manage asynchronous jobs that de-identify documents stored in Azure Blob Storage.; and Run a batch workflow that needs consistent surrogate values across multiple documents.. Practical scope: Assign directly on the de-identification service that runs the approved batch jobs. Resource-group and subscription assignments are inherited by additional de-identification services and expand batch-job authority beyond one service.

What permissions does the DeID Batch Data Owner Azure role grant?

The role definition grants 3 combined control-plane and data-plane actions. Representative operations include: Microsoft.HealthDataAIServices/DeidServices/Batch/write; Microsoft.HealthDataAIServices/DeidServices/Batch/delete; and Microsoft.HealthDataAIServices/DeidServices/Batch/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the DeID Batch Data Owner Azure role?

Key considerations when assigning DeID Batch Data Owner: Batch jobs read source clinical documents and write de-identified outputs, so the service identity can access both sensitive input and generated output data within its storage scope.; The caller can create and delete batch jobs, while the service managed identity separately controls Blob Storage access.; and Preview behavior and permissions can change before general availability.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →