Azure AI + machine learning built-in role

Foundry Account Owner

Manages Foundry accounts, projects, models, and their Azure control-plane configuration. The role has no DataActions, but it can create and delete role assignments subject to its built-in condition, which limits delegation to the documented Foundry User, container-registry, and monitoring roles.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: e47c6f54-e4a2-4754-9501-8e0985b135e1

Control-plane actions (20)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Assign on the Foundry account when the principal owns account and project provisioning. An account-scope assignment is inherited by its projects; a broader resource-group or subscription assignment reaches every inherited Foundry account and project. The role does not grant Foundry project data-plane development access.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Foundry Account Owner on the individual Foundry account to the platform administrator who manages accounts, projects, models, and the permitted downstream role assignments. Add Foundry User separately only if that administrator also needs project data-plane development access.

Related roles (2)

Common questions

When should I assign the Foundry Account Owner Azure role?

Assign Foundry Account Owner when you need to: Create and manage Foundry accounts and projects, manage model deployments, and configure account-level resources without building agents in the project data plane.; and Delegate the limited set of Foundry User, container-registry, and monitoring roles allowed by the role definition condition.. Practical scope: Assign on the Foundry account when the principal owns account and project provisioning. An account-scope assignment is inherited by its projects; a broader resource-group or subscription assignment reaches every inherited Foundry account and project. The role does not grant Foundry project data-plane development access.

What permissions does the Foundry Account Owner Azure role grant?

The role definition grants 20 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Authorization/roleAssignments/write; Microsoft.Authorization/roleAssignments/delete; Microsoft.CognitiveServices/*; Microsoft.Features/features/read; and Microsoft.Features/providers/features/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Foundry Account Owner Azure role?

Key considerations when assigning Foundry Account Owner: The role can create, change, and delete Foundry accounts, projects, model deployments, keys, and other control-plane resources.; Its conditioned role-assignment Actions delegate only the role IDs allowed by the definition; they are still access-management authority and require regular review.; and The absence of DataActions means this role alone does not authorize building agents or invoking project endpoints.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →