Azure AI + machine learning built-in role

Healthcare Agent Reader

Provides read-only Healthcare Agent portal access to bot resources, scenarios, and configuration while excluding instance keys and secrets, end-user inputs, and portal user management. The imported role has read-oriented Healthcare Agent DataActions and no control-plane Actions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: eb5a76d5-50e7-4c33-a449-070e7c9c4cf2

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (17)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Healthcare Agent service resource the reviewer must inspect. A parent-scope assignment is inherited by every instance below that scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Healthcare Agent Reader on the individual instance to support, audit, or stakeholder users who only inspect portal content. Use Editor for approved bot changes and Admin only for secrets and access management.

Related roles (2)

Common questions

When should I assign the Healthcare Agent Reader Azure role?

Assign Healthcare Agent Reader when you need to: Review Healthcare Agent scenarios, resources, metadata, configuration, localization, and analytics without editing the bot.; and Give support, audit, or stakeholder users portal visibility while keeping secrets, end-user inputs, and user management unavailable.. Practical scope: Assign on the individual Healthcare Agent service resource the reviewer must inspect. A parent-scope assignment is inherited by every instance below that scope.

What permissions does the Healthcare Agent Reader Azure role grant?

The role definition grants 17 combined control-plane and data-plane actions. Representative operations include: Microsoft.HealthBot/healthBots/ResourceData/Read; Microsoft.HealthBot/healthBots/Metadata/Read; Microsoft.HealthBot/healthBots/CopilotStudioSolution/RestoreBuiltinTemplate/Read; Microsoft.HealthBot/healthBots/Feedback/Read; Microsoft.HealthBot/healthBots/Users/Read; and Microsoft.HealthBot/healthBots/AuditTrails/Read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Healthcare Agent Reader Azure role?

Key considerations when assigning Healthcare Agent Reader: Read access can expose bot scenarios, configuration, resource metadata, analytics, and operational context.; Microsoft documents instance keys, secrets, end-user inputs, and portal user management as excluded from Reader access.; and A parent-scope assignment exposes portal content from every inherited Healthcare Agent instance.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →