Azure AI + machine learning built-in role

Foundry Project Manager

Manages a Foundry project, builds and develops in it, and publishes agents. The current Foundry RBAC matrix explicitly marks model management unavailable. It can create and delete role assignments only for Foundry User under the canonical condition, and it does not create Foundry accounts.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: eadc314b-1a2d-4efa-be10-5d325db5065e

Control-plane actions (9)

Data-plane actions (1)

Excluded actions (0)

None

Conditions (1)

Assignable scopes (1)

Practical scope

Assign on an individual Foundry project to manage that existing project, develop in it, and delegate Foundry User. Assign on the Foundry resource when the lead manages or creates projects across that resource or maintains the supported legacy Agent Application publishing flow; project scope alone does not provide that resource-wide boundary or satisfy that legacy publishing prerequisite.

Common use cases (4)

Prerequisites (3)

Best practices (4)

Security considerations (3)

Assignment guidance

Assign Foundry Project Manager on a specific project to a lead who manages that project, its development, and contributors. Assign it on the Foundry resource when the lead creates or manages projects across that resource or maintains a supported legacy Agent Application during migration. New agents use the stable endpoint and identity created with the agent. Give ordinary builders Foundry User; place model deployment and account administration with the documented owner or deployment roles.

Related roles (3)

Common questions

When should I assign the Foundry Project Manager Azure role?

Assign Foundry Project Manager when you need to: Let a project lead manage project configuration and build and develop in the project without granting account ownership or model management.; Create and lead projects across one Foundry resource when the role is assigned at that resource scope.; Maintain or migrate a supported legacy Agent Application when the project lead also has Foundry Project Manager on the parent Foundry resource.; and Delegate Foundry User to project contributors without granting account-wide Foundry ownership.. Practical scope: Assign on an individual Foundry project to manage that existing project, develop in it, and delegate Foundry User. Assign on the Foundry resource when the lead manages or creates projects across that resource or maintains the supported legacy Agent Application publishing flow; project scope alone does not provide that resource-wide boundary or satisfy that legacy publishing prerequisite.

What permissions does the Foundry Project Manager Azure role grant?

The role definition grants 10 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/roleAssignments/write; Microsoft.Authorization/roleAssignments/delete; Microsoft.CognitiveServices/accounts/*/read; Microsoft.CognitiveServices/accounts/projects/*; Microsoft.CognitiveServices/locations/*/read; and Microsoft.Authorization/*/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Foundry Project Manager Azure role?

Key considerations when assigning Foundry Project Manager: The role can change project resources, exercise broad project DataActions, delegate Foundry User access, and maintain the supported legacy Agent Application flow, but it is not a model-management role.; The built-in condition limits role assignment to Foundry User but does not eliminate the need to govern who receives project data-plane access.; and A parent-scope assignment grants the same project-management authority across every inherited project.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (9)

Official Microsoft Learn documentation →