Azure Integration built-in role

DeID Data Owner

Provides full data-plane access to de-identification functionality, spanning real-time and batch operations. The published role has DataActions only, and Microsoft marks it as preview and subject to change.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 78e4b983-1a0b-472e-8b7d-8d770f7c5890

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the de-identification service whose full functionality the principal may use. Resource-group and subscription assignments are inherited by every de-identification service below them.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Reserve DeID Data Owner for a trusted integration identity that needs both real-time and batch functionality on one de-identification service. Use the real-time or batch-specific roles for narrower workflows and authorize Blob Storage separately to the service identity.

Related roles (3)

Common questions

When should I assign the DeID Data Owner Azure role?

Assign DeID Data Owner when you need to: Operate both synchronous de-identification endpoints and asynchronous batch jobs from one trusted integration identity.; and Administer de-identification data operations during a controlled implementation or validation workflow.. Practical scope: Assign directly on the de-identification service whose full functionality the principal may use. Resource-group and subscription assignments are inherited by every de-identification service below them.

What permissions does the DeID Data Owner Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.HealthDataAIServices/DeidServices/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the DeID Data Owner Azure role?

Key considerations when assigning DeID Data Owner: Full de-identification access can process protected health information through real-time endpoints and create, inspect, or delete batch workflows.; Batch storage access belongs to the de-identification service identity and can expose source and output documents within that separate scope.; and Preview behavior and permissions can change before general availability.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →