Azure Integration built-in role

DeID Batch Data Reader

Reads de-identification batch jobs through a data-plane DataAction and explicitly excludes batch write and delete operations. Microsoft marks this role and the batch capability as preview and subject to change.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b73a14ee-91f5-41b7-bd81-920e12466be9

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (2)

Assignable scopes (1)

Practical scope

Assign directly on the de-identification service whose batch jobs the reviewer may inspect. Parent-scope assignments are inherited by additional services and broaden job visibility.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Assign DeID Batch Data Reader to the monitoring or privacy-review group on the specific de-identification service. Use Batch Data Owner only for approved job creation and deletion, and grant storage access separately to the service identity.

Related roles (2)

Common questions

When should I assign the DeID Batch Data Reader Azure role?

Assign DeID Batch Data Reader when you need to: Monitor asynchronous de-identification job status and results without creating or deleting jobs.; and Give a privacy reviewer visibility into approved batch processing on one de-identification service.. Practical scope: Assign directly on the de-identification service whose batch jobs the reviewer may inspect. Parent-scope assignments are inherited by additional services and broaden job visibility.

What permissions does the DeID Batch Data Reader Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.HealthDataAIServices/DeidServices/Batch/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the DeID Batch Data Reader Azure role?

Key considerations when assigning DeID Batch Data Reader: Batch job metadata can reveal storage locations, processing state, errors, and operational context for sensitive health-data workflows.; The role cannot create or delete batch jobs and does not grant Blob Storage access by itself.; and Preview behavior and permissions can change before general availability.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →