Azure AI + machine learning built-in role

Foundry Owner

Combines broad Foundry account and project management Actions with Foundry project DataActions. It can manage resources, deployments, agents, and project development and can create or delete a constrained set of role assignments, making it the broad self-service Foundry role rather than a least-privilege default.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: c883944f-8b7b-4483-af10-35834be79c4a

Control-plane actions (20)

Data-plane actions (1)

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

For the combined account administration and Agent Application publishing described here, assign on the individual Foundry resource. A project-scoped assignment can support project-local development but cannot administer the parent resource or satisfy the documented Agent Application publishing prerequisite. Resource-group and subscription assignments extend both planes to every inherited Foundry resource.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Reserve Foundry Owner at the individual Foundry resource for a trusted principal that must administer the account and build, fine-tune, deploy, or publish within its projects. Split duties between Foundry Account Owner, Foundry Project Manager, and Foundry User whenever the combined role is unnecessary.

Related roles (3)

Common questions

When should I assign the Foundry Owner Azure role?

Assign Foundry Owner when you need to: Give a trusted self-service owner both Foundry resource administration and project development, including model fine-tuning and deployment.; and Manage and publish agents while also administering the account, projects, models, and the role assignments permitted by the role condition.. Practical scope: For the combined account administration and Agent Application publishing described here, assign on the individual Foundry resource. A project-scoped assignment can support project-local development but cannot administer the parent resource or satisfy the documented Agent Application publishing prerequisite. Resource-group and subscription assignments extend both planes to every inherited Foundry resource.

What permissions does the Foundry Owner Azure role grant?

The role definition grants 21 combined control-plane and data-plane actions. Representative operations include: Microsoft.AlertsManagement/actionRules/*; Microsoft.AlertsManagement/alerts/*; Microsoft.AlertsManagement/issues/*; Microsoft.AlertsManagement/prometheusRuleGroups/*; Microsoft.AlertsManagement/smartDetectorAlertRules/*; and Microsoft.Authorization/*/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Foundry Owner Azure role?

Key considerations when assigning Foundry Owner: The role combines broad management Actions, project DataActions, and conditioned role-assignment authority, concentrating resource, model, agent, and access administration.; Project DataActions can process project data and invoke deployed capabilities, while control-plane Actions can change deployments and resource configuration.; and A parent-scope assignment expands this combined authority to every inherited Foundry account and project.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →