Azure Integration built-in role

DeID Realtime Data User

Executes requests against the de-identification service real-time endpoint through a data-plane action. It does not manage batch jobs or the service resource, and Microsoft marks the role as preview and subject to change.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: bb6577c4-ea0a-40b2-8962-ea18cb8ecd4e

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the de-identification service whose synchronous endpoint the principal may call. Parent-scope assignments extend real-time processing authority to additional services.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Assign DeID Realtime Data User to the application identity directly on the de-identification service used for synchronous requests. Add batch roles only to separate identities that run or inspect asynchronous jobs.

Related roles (2)

Common questions

When should I assign the DeID Realtime Data User Azure role?

Assign DeID Realtime Data User when you need to: Authorize an application to synchronously de-identify clinical text through one service endpoint.; and Separate real-time request execution from asynchronous batch-job administration.. Practical scope: Assign directly on the de-identification service whose synchronous endpoint the principal may call. Parent-scope assignments extend real-time processing authority to additional services.

What permissions does the DeID Realtime Data User Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.HealthDataAIServices/DeidServices/Realtime/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the DeID Realtime Data User Azure role?

Key considerations when assigning DeID Realtime Data User: The role authorizes processing of protected health information submitted to the real-time endpoint.; It does not grant batch-job or Blob Storage access, but application logs and downstream handling can still expose source or transformed data.; and Preview behavior and permissions can change before general availability.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →