Azure AI + machine learning built-in role
Foundry Owner
Combines broad Foundry account and project management Actions with Foundry project DataActions. It can manage resources, deployments, agents, and project development and can create or delete a constrained set of role assignments, making it the broad self-service Foundry role rather than a least-privilege default.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: c883944f-8b7b-4483-af10-35834be79c4a
Control-plane actions (20)
Microsoft.AlertsManagement/actionRules/*Microsoft.AlertsManagement/alerts/*Microsoft.AlertsManagement/issues/*Microsoft.AlertsManagement/prometheusRuleGroups/*Microsoft.AlertsManagement/smartDetectorAlertRules/*Microsoft.Authorization/*/readMicrosoft.Authorization/roleAssignments/writeMicrosoft.Authorization/roleAssignments/deleteMicrosoft.CognitiveServices/*Microsoft.Insights/activityLogAlerts/*Microsoft.Insights/metricalerts/*Microsoft.Insights/scheduledqueryrules/*Microsoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/deployments/operations/readMicrosoft.Resources/subscriptions/operationresults/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourcegroups/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (1)
Microsoft.CognitiveServices/*
Excluded actions (0)
None
Conditions (1)
Condition version: 2.0
((!(ActionMatches{'Microsoft.Authorization/roleAssignments/write'})) OR (@Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{53ca6127-db72-4b80-b1b0-d745d6d5456d,3bc748fc-213d-45c1-8d91-9da5725539b9,2a1e307c-b015-4ebd-883e-5b7698a07328,73c42c96-874c-492b-b04d-ab87d138a893})) AND ((!(ActionMatches{'Microsoft.Authorization/roleAssignments/delete'})) OR (@Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{53ca6127-db72-4b80-b1b0-d745d6d5456d,3bc748fc-213d-45c1-8d91-9da5725539b9,2a1e307c-b015-4ebd-883e-5b7698a07328,73c42c96-874c-492b-b04d-ab87d138a893}))
Assignable scopes (1)
/
Practical scope
For the combined account administration and Agent Application publishing described here, assign on the individual Foundry resource. A project-scoped assignment can support project-local development but cannot administer the parent resource or satisfy the documented Agent Application publishing prerequisite. Resource-group and subscription assignments extend both planes to every inherited Foundry resource.
Common use cases (2)
- Give a trusted self-service owner both Foundry resource administration and project development, including model fine-tuning and deployment.
- Manage and publish agents while also administering the account, projects, models, and the role assignments permitted by the role condition.
Prerequisites (2)
- Confirm that one principal genuinely requires both the control-plane and data-plane capabilities that Microsoft separates between Foundry Account Owner and Foundry User.
- Plan authorization for connected resources such as storage, search, monitoring, and container registries separately.
Best practices (3)
- Use Foundry User for ordinary builders and Foundry Account Owner for control-plane-only administrators instead of assigning this combined role broadly.
- Keep combined administration and publishing access on one Foundry resource and use eligible, time-bound access for human owners where available.
- Review conditioned role assignments and connected-resource permissions together with the Foundry assignment.
Security considerations (3)
- The role combines broad management Actions, project DataActions, and conditioned role-assignment authority, concentrating resource, model, agent, and access administration.
- Project DataActions can process project data and invoke deployed capabilities, while control-plane Actions can change deployments and resource configuration.
- A parent-scope assignment expands this combined authority to every inherited Foundry account and project.
Assignment guidance
Reserve Foundry Owner at the individual Foundry resource for a trusted principal that must administer the account and build, fine-tune, deploy, or publish within its projects. Split duties between Foundry Account Owner, Foundry Project Manager, and Foundry User whenever the combined role is unnecessary.
Related roles (3)
- Foundry Account Owner: Provides account and project control-plane administration without Foundry project DataActions.
- Foundry Project Manager: Provides project management and development with delegation limited to Foundry User, without account creation.
- Foundry User: Provides project reader and development DataActions without Foundry management writes.
Editorial sources (7)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Role-based access control for Microsoft Foundry - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Microsoft Foundry architecture - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Publish your agent as an Agent Application - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.