Azure AI + machine learning built-in role
Foundry Account Owner
Manages Foundry accounts, projects, models, and their Azure control-plane configuration. The role has no DataActions, but it can create and delete role assignments subject to its built-in condition, which limits delegation to the documented Foundry User, container-registry, and monitoring roles.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: e47c6f54-e4a2-4754-9501-8e0985b135e1
Control-plane actions (20)
Microsoft.Authorization/*/readMicrosoft.Authorization/roleAssignments/writeMicrosoft.Authorization/roleAssignments/deleteMicrosoft.CognitiveServices/*Microsoft.Features/features/readMicrosoft.Features/providers/features/readMicrosoft.Features/providers/features/register/actionMicrosoft.Insights/alertRules/*Microsoft.Insights/diagnosticSettings/*Microsoft.Insights/logDefinitions/readMicrosoft.Insights/metricdefinitions/readMicrosoft.Insights/metrics/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/deployments/operations/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Conditions (1)
Condition version: 2.0
((!(ActionMatches{'Microsoft.Authorization/roleAssignments/write'})) OR (@Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{53ca6127-db72-4b80-b1b0-d745d6d5456d,3bc748fc-213d-45c1-8d91-9da5725539b9,2a1e307c-b015-4ebd-883e-5b7698a07328,73c42c96-874c-492b-b04d-ab87d138a893})) AND ((!(ActionMatches{'Microsoft.Authorization/roleAssignments/delete'})) OR (@Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{53ca6127-db72-4b80-b1b0-d745d6d5456d,3bc748fc-213d-45c1-8d91-9da5725539b9,2a1e307c-b015-4ebd-883e-5b7698a07328,73c42c96-874c-492b-b04d-ab87d138a893}))
Assignable scopes (1)
/
Practical scope
Assign on the Foundry account when the principal owns account and project provisioning. An account-scope assignment is inherited by its projects; a broader resource-group or subscription assignment reaches every inherited Foundry account and project. The role does not grant Foundry project data-plane development access.
Common use cases (2)
- Create and manage Foundry accounts and projects, manage model deployments, and configure account-level resources without building agents in the project data plane.
- Delegate the limited set of Foundry User, container-registry, and monitoring roles allowed by the role definition condition.
Prerequisites (2)
- Use a Microsoft Entra principal responsible for Foundry account administration and confirm that project data-plane development is not part of the same assignment.
- Plan the connected storage, search, monitoring, container-registry, and other resource permissions separately because resources created outside Foundry retain their own authorization.
Best practices (3)
- Keep this high-privilege role at the individual Foundry account instead of a resource group or subscription when one account is the administrative boundary.
- Assign Foundry User directly to project developers instead of giving them account ownership.
- Use a custom role when the administrator needs only a narrower subset of account management or key-rotation operations.
Security considerations (3)
- The role can create, change, and delete Foundry accounts, projects, model deployments, keys, and other control-plane resources.
- Its conditioned role-assignment Actions delegate only the role IDs allowed by the definition; they are still access-management authority and require regular review.
- The absence of DataActions means this role alone does not authorize building agents or invoking project endpoints.
Assignment guidance
Assign Foundry Account Owner on the individual Foundry account to the platform administrator who manages accounts, projects, models, and the permitted downstream role assignments. Add Foundry User separately only if that administrator also needs project data-plane development access.
Related roles (2)
- Foundry Owner: Adds project DataActions and is the documented highly privileged self-service role for a principal that both administers and develops in Foundry.
- Foundry User: The project development role that Foundry Account Owner can assign under its built-in condition.
Editorial sources (6)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Microsoft Foundry - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Microsoft Foundry architecture - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.