Azure Integration built-in role
DeID Batch Data Reader
Reads de-identification batch jobs through a data-plane DataAction and explicitly excludes batch write and delete operations. Microsoft marks this role and the batch capability as preview and subject to change.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: b73a14ee-91f5-41b7-bd81-920e12466be9
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (1)
Microsoft.HealthDataAIServices/DeidServices/Batch/read
Excluded actions (2)
Microsoft.HealthDataAIServices/DeidServices/Batch/writeMicrosoft.HealthDataAIServices/DeidServices/Batch/delete
Assignable scopes (1)
/
Practical scope
Assign directly on the de-identification service whose batch jobs the reviewer may inspect. Parent-scope assignments are inherited by additional services and broaden job visibility.
Common use cases (2)
- Monitor asynchronous de-identification job status and results without creating or deleting jobs.
- Give a privacy reviewer visibility into approved batch processing on one de-identification service.
Prerequisites (2)
- The de-identification service and batch jobs to inspect must already exist.
- The reviewer must be approved to see batch metadata associated with protected health information processing and accept the preview boundary.
Best practices (2)
- Use Batch Data Reader instead of Batch Data Owner for monitoring and review duties.
- Assign on the individual service and revalidate the preview role as the service evolves.
Security considerations (3)
- Batch job metadata can reveal storage locations, processing state, errors, and operational context for sensitive health-data workflows.
- The role cannot create or delete batch jobs and does not grant Blob Storage access by itself.
- Preview behavior and permissions can change before general availability.
Assignment guidance
Assign DeID Batch Data Reader to the monitoring or privacy-review group on the specific de-identification service. Use Batch Data Owner only for approved job creation and deletion, and grant storage access separately to the service identity.
Related roles (2)
- DeID Batch Data Owner: Adds batch-job creation and deletion to the read access.
- DeID Data Owner: Provides full access to all de-identification functionality.
Editorial sources (7)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Use Azure role-based access control with the de-identification service →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Tutorial: De-identify multiple documents with the asynchronous de-identification service →
Supports: Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.