Azure AI + machine learning built-in role

Search Service Contributor

Provides full Azure AI Search service administration and search-object management, including indexes, indexers, data sources, skillsets, aliases, synonym maps, debug sessions, knowledge bases, authentication, networking, and admin keys. The imported role definition records its wildcard as control-plane Actions and no DataActions, while Search documentation describes the resulting endpoint object-management capability separately from document content access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 7ca78c08-252a-4471-8644-bb5ff32d4ba0

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual Azure AI Search service. A resource-group or subscription assignment is inherited by every search service below the scope and extends service, object, key, authentication, and network administration to all of them.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Search Service Contributor on the individual search service to administrators or development automation that manage service configuration and search objects. Add the two Search Index Data roles only when document loading and querying are also required, and protect admin-key access.

Related roles (3)

Editorial sources (5)

Official Microsoft Learn documentation →