Azure Integration built-in role

DeID Batch Data Owner

Creates, reads, and deletes de-identification batch jobs through data-plane DataActions. Microsoft marks this role and the batch capability as preview and subject to change; it does not manage the de-identification service resource through the control plane.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 8a90fa6b-6997-4a07-8a95-30633a7c97b9

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (3)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the de-identification service that runs the approved batch jobs. Resource-group and subscription assignments are inherited by additional de-identification services and expand batch-job authority beyond one service.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign DeID Batch Data Owner to the approved batch operator on the specific de-identification service. Grant Storage Blob Data Contributor separately to the service managed identity on only the required containers, and use Batch Data Reader for status-only review.

Related roles (3)

Editorial sources (8)

Official Microsoft Learn documentation →