Azure Integration built-in role

DeID Data Owner

Provides full data-plane access to de-identification functionality, spanning real-time and batch operations. The published role has DataActions only, and Microsoft marks it as preview and subject to change.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 78e4b983-1a0b-472e-8b7d-8d770f7c5890

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the de-identification service whose full functionality the principal may use. Resource-group and subscription assignments are inherited by every de-identification service below them.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Reserve DeID Data Owner for a trusted integration identity that needs both real-time and batch functionality on one de-identification service. Use the real-time or batch-specific roles for narrower workflows and authorize Blob Storage separately to the service identity.

Related roles (3)

Editorial sources (8)

Official Microsoft Learn documentation →