Azure Integration built-in role
DeID Batch Data Owner
Creates, reads, and deletes de-identification batch jobs through data-plane DataActions. Microsoft marks this role and the batch capability as preview and subject to change; it does not manage the de-identification service resource through the control plane.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 8a90fa6b-6997-4a07-8a95-30633a7c97b9
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (3)
Microsoft.HealthDataAIServices/DeidServices/Batch/writeMicrosoft.HealthDataAIServices/DeidServices/Batch/deleteMicrosoft.HealthDataAIServices/DeidServices/Batch/read
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign directly on the de-identification service that runs the approved batch jobs. Resource-group and subscription assignments are inherited by additional de-identification services and expand batch-job authority beyond one service.
Common use cases (2)
- Create and manage asynchronous jobs that de-identify documents stored in Azure Blob Storage.
- Run a batch workflow that needs consistent surrogate values across multiple documents.
Prerequisites (3)
- A de-identification service with a managed identity and approved input and output Blob Storage locations must exist.
- Grant the de-identification service identity Storage Blob Data Contributor on the required storage boundary; this storage assignment is separate from the caller's DeID batch role.
- Review preview terms and validate the batch workflow before using it with protected health information.
Best practices (3)
- Assign on the individual de-identification service and use Batch Data Reader for principals that only inspect job status.
- Limit the service managed identity to the required storage containers and disable public storage access when the documented trusted-service path is appropriate.
- Treat the preview role and API as changeable and revalidate behavior before production updates.
Security considerations (3)
- Batch jobs read source clinical documents and write de-identified outputs, so the service identity can access both sensitive input and generated output data within its storage scope.
- The caller can create and delete batch jobs, while the service managed identity separately controls Blob Storage access.
- Preview behavior and permissions can change before general availability.
Assignment guidance
Assign DeID Batch Data Owner to the approved batch operator on the specific de-identification service. Grant Storage Blob Data Contributor separately to the service managed identity on only the required containers, and use Batch Data Reader for status-only review.
Related roles (3)
- DeID Batch Data Reader: Reads batch jobs without creating or deleting them.
- DeID Data Owner: Provides full access to all de-identification functionality, including broader real-time and batch operations.
- Storage Blob Data Contributor: The documented separate storage role for the de-identification service managed identity to read inputs and write outputs.
Editorial sources (8)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Use Azure role-based access control with the de-identification service →
Supports: Description, Practical scope, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Use managed identities with the de-identification service →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Tutorial: De-identify multiple documents with the asynchronous de-identification service →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.