Azure AI + machine learning built-in role

Foundry Owner

Combines broad Foundry account and project management Actions with Foundry project DataActions. It can manage resources, deployments, agents, and project development and can create or delete a constrained set of role assignments, making it the broad self-service Foundry role rather than a least-privilege default.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: c883944f-8b7b-4483-af10-35834be79c4a

Control-plane actions (20)

Data-plane actions (1)

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

For the combined account administration and Agent Application publishing described here, assign on the individual Foundry resource. A project-scoped assignment can support project-local development but cannot administer the parent resource or satisfy the documented Agent Application publishing prerequisite. Resource-group and subscription assignments extend both planes to every inherited Foundry resource.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Reserve Foundry Owner at the individual Foundry resource for a trusted principal that must administer the account and build, fine-tune, deploy, or publish within its projects. Split duties between Foundry Account Owner, Foundry Project Manager, and Foundry User whenever the combined role is unnecessary.

Related roles (3)

Editorial sources (7)

Official Microsoft Learn documentation →