Azure Integration built-in role
DeID Data Owner
Provides full data-plane access to de-identification functionality, spanning real-time and batch operations. The published role has DataActions only, and Microsoft marks it as preview and subject to change.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 78e4b983-1a0b-472e-8b7d-8d770f7c5890
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (1)
Microsoft.HealthDataAIServices/DeidServices/*
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign directly on the de-identification service whose full functionality the principal may use. Resource-group and subscription assignments are inherited by every de-identification service below them.
Common use cases (2)
- Operate both synchronous de-identification endpoints and asynchronous batch jobs from one trusted integration identity.
- Administer de-identification data operations during a controlled implementation or validation workflow.
Prerequisites (3)
- A de-identification service must exist and the principal must authenticate with Microsoft Entra ID.
- For batch jobs, configure a service managed identity and grant its required Blob Storage access separately.
- Review preview terms and approve the service for the intended protected health information workflow.
Best practices (3)
- Use Realtime Data User or the batch-specific roles when a principal does not need all de-identification functionality.
- Assign on one service and limit the service managed identity to required storage containers.
- Revalidate the preview role and API behavior before production changes.
Security considerations (3)
- Full de-identification access can process protected health information through real-time endpoints and create, inspect, or delete batch workflows.
- Batch storage access belongs to the de-identification service identity and can expose source and output documents within that separate scope.
- Preview behavior and permissions can change before general availability.
Assignment guidance
Reserve DeID Data Owner for a trusted integration identity that needs both real-time and batch functionality on one de-identification service. Use the real-time or batch-specific roles for narrower workflows and authorize Blob Storage separately to the service identity.
Related roles (3)
- DeID Realtime Data User: Limits access to execution of real-time de-identification requests.
- DeID Batch Data Owner: Limits management authority to asynchronous batch jobs.
- DeID Batch Data Reader: Limits batch access to job reads.
Editorial sources (8)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Use Azure role-based access control with the de-identification service →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Use managed identities with the de-identification service →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Tutorial: De-identify multiple documents with the asynchronous de-identification service →
Supports: Common use cases, Prerequisites, Security considerations. Retrieved 2026-07-17.