Azure AI + machine learning built-in role
Foundry Project Manager
Manages a Foundry project, builds and develops in it, and publishes agents. The current Foundry RBAC matrix explicitly marks model management unavailable. It can create and delete role assignments only for Foundry User under the canonical condition, and it does not create Foundry accounts.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: eadc314b-1a2d-4efa-be10-5d325db5065e
Control-plane actions (9)
Microsoft.Authorization/roleAssignments/writeMicrosoft.Authorization/roleAssignments/deleteMicrosoft.CognitiveServices/accounts/*/readMicrosoft.CognitiveServices/accounts/projects/*Microsoft.CognitiveServices/locations/*/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (1)
Microsoft.CognitiveServices/*
Excluded actions (0)
None
Conditions (1)
Condition version: 2.0
((!(ActionMatches{'Microsoft.Authorization/roleAssignments/write'})) OR (@Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{53ca6127-db72-4b80-b1b0-d745d6d5456d})) AND ((!(ActionMatches{'Microsoft.Authorization/roleAssignments/delete'})) OR (@Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{53ca6127-db72-4b80-b1b0-d745d6d5456d}))
Assignable scopes (1)
/
Practical scope
Assign on an individual Foundry project to manage that existing project, develop in it, and delegate Foundry User. Assign on the Foundry resource when the lead manages or creates projects across that resource or maintains the supported legacy Agent Application publishing flow; project scope alone does not provide that resource-wide boundary or satisfy that legacy publishing prerequisite.
Common use cases (4)
- Let a project lead manage project configuration and build and develop in the project without granting account ownership or model management.
- Create and lead projects across one Foundry resource when the role is assigned at that resource scope.
- Maintain or migrate a supported legacy Agent Application when the project lead also has Foundry Project Manager on the parent Foundry resource.
- Delegate Foundry User to project contributors without granting account-wide Foundry ownership.
Prerequisites (3)
- The Foundry resource must exist. For a project-scoped assignment, the target project must also exist and the lead must be responsible for its management and development.
- For a supported legacy Agent Application, assign Foundry Project Manager on the Foundry resource and reassign downstream resource permissions to its distinct identity. New agents receive a stable endpoint and identity at creation and should use the new model.
- Connected storage, search, monitoring, and other resources require their own documented role assignments.
Best practices (4)
- Use project scope for one existing project; use Foundry resource scope only for documented resource-wide project leadership or a supported legacy Agent Application workflow.
- Migrate existing Agent Applications to the new agent endpoint model after validating the replacement identity, endpoint, and downstream RBAC assignments.
- Review every Foundry User assignment created by project managers and remove it when project participation ends.
- Use Foundry Account Owner or Foundry Owner for the model-management responsibilities assigned to those roles by the current matrix.
Security considerations (3)
- The role can change project resources, exercise broad project DataActions, delegate Foundry User access, and maintain the supported legacy Agent Application flow, but it is not a model-management role.
- The built-in condition limits role assignment to Foundry User but does not eliminate the need to govern who receives project data-plane access.
- A parent-scope assignment grants the same project-management authority across every inherited project.
Assignment guidance
Assign Foundry Project Manager on a specific project to a lead who manages that project, its development, and contributors. Assign it on the Foundry resource when the lead creates or manages projects across that resource or maintains a supported legacy Agent Application during migration. New agents use the stable endpoint and identity created with the agent. Give ordinary builders Foundry User; place model deployment and account administration with the documented owner or deployment roles.
Related roles (3)
- Foundry User: The narrower builder role that Project Manager can assign under its built-in condition.
- Foundry Account Owner: Adds account and project provisioning and the model-management capability that the current matrix withholds from Project Manager, but does not provide project development DataActions.
- Foundry Owner: Combines account and model management with project development and agent publishing when one highly privileged principal requires both planes.
Editorial sources (9)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Understand Azure role definitions - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Role-based access control for Microsoft Foundry - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Microsoft Foundry architecture - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Publish your agent as an Agent Application - Microsoft Foundry | Microsoft Learn →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Migrate from agent applications to the new agent endpoint and publishing experience - Microsoft Foundry | Microsoft Learn →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.