Azure AI + machine learning built-in role
Foundry User
Provides reader access to a Foundry account and project plus project DataActions for building and testing AI applications. It has no Foundry account or project management writes and no role-assignment authority. Plane reconciliation is required: the canonical definition also includes resource-key listing and Resource Manager deployment Actions, but the current Foundry matrix still marks model management unavailable.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 53ca6127-db72-4b80-b1b0-d745d6d5456d
Control-plane actions (14)
Microsoft.Authorization/*/readMicrosoft.CognitiveServices/*/readMicrosoft.CognitiveServices/accounts/listkeys/actionMicrosoft.Insights/alertRules/readMicrosoft.Insights/diagnosticSettings/readMicrosoft.Insights/logDefinitions/readMicrosoft.Insights/metricdefinitions/readMicrosoft.Insights/metrics/readMicrosoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/operationresults/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (1)
Microsoft.CognitiveServices/*
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
For one project, assign Foundry User on that project and Reader on the parent Foundry resource. Assign Foundry User on the Foundry resource only when the principal needs inherited builder access to its projects. For a published Agent Application, assign Foundry User on that application resource; direct agent endpoints instead use Foundry Agent Consumer at project or agent scope.
Common use cases (2)
- Build and test agents or applications against predeployed models in a Foundry project.
- Perform project development DataActions without creating Foundry accounts or projects, publishing agents, assigning roles, or managing models.
Prerequisites (3)
- The Foundry account, project, and required model or agent deployment must already exist.
- A project-scoped builder also needs Reader on the parent Foundry resource; a published Agent Application caller instead needs Foundry User on the Agent Application resource.
- Grant the principal separate access to connected resources, such as Storage Blob Data Reader on an external storage account or the required Azure AI Search role, when the project workflow uses them.
Best practices (3)
- Use this role for ordinary project builders instead of Foundry Owner or broad Cognitive Services roles.
- Pair project-scoped Foundry User with Reader on the parent resource, or use Foundry-resource scope only when inherited access to all projects is intended.
- Use Foundry Agent Consumer at project or individual-agent scope for a principal that only calls agent endpoints; do not assign Foundry User as the endpoint-only default.
Security considerations (3)
- The role has broad Foundry project DataActions and can process project data even though the current product matrix withholds Foundry account and project management and model management.
- Its canonical listKeys Action can expose API keys. Foundry security documentation states that keys provide full resource access, cannot express user identity or granular scope, are harder to audit, and are not recommended for production.
- Canonical Resource Manager deployment Actions remain effective control-plane permissions even though they do not make this a Foundry model-management role; review them when a custom role is needed.
Assignment guidance
Assign Foundry User on the specific project plus Reader on the parent Foundry resource for developers or testers that build applications. Use Foundry-resource scope only for intended inherited project access. For endpoint-only access, use Foundry Agent Consumer on a direct agent or Foundry User on a published Agent Application, as documented. Prefer Microsoft Entra authentication and elevate only for documented publishing or model-management duties.
Related roles (3)
- Foundry Agent Consumer: The current least-privilege role for direct agent endpoints at project or individual-agent scope; published Agent Applications instead require Foundry User on the application resource.
- Foundry Project Manager: Adds project management, agent publishing, and conditioned delegation of Foundry User, but the current matrix still withholds model management.
- Foundry Owner: Adds broad account and project control-plane administration to the project DataActions.
Editorial sources (9)
- Azure built-in roles for AI + machine learning - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role - Azure RBAC | Microsoft Learn →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC | Microsoft Learn →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC | Microsoft Learn →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Understand Azure role definitions - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Role-based access control for Microsoft Foundry - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Microsoft Foundry architecture - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Authentication and authorization in Microsoft Foundry - Microsoft Foundry | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Publish your agent as an Agent Application - Microsoft Foundry | Microsoft Learn →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Assignment guidance, Related roles. Retrieved 2026-07-17.