Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500AI-901AI-300AI-103AZ-900AI-200AZ-400ALZ
Each book explains Azure RBAC in context, with comparison tables and the common traps.
Terms in this definition
- Custom roles
Azure RBAC roles containing actions you pick yourself, for when no built-in role fits; a tenant can hold as many as 5,000.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Foundry User
Least-privileged built-in role aimed at developers: it pairs read access with the data actions needed to create and try things out inside a Foundry project, and each project's managed identity is granted it too.
- Cognitive Services OpenAI User
The narrowest Azure OpenAI role for calling models through Entra ID; it can see the endpoint and deployments and use the playgrounds, but not deploy, view keys or upload fine-tuning data.
Related terms
- Access control mode
Whether people can read Log Analytics data through their rights on individual resources depends on this workspace setting. Since March 2019 new workspaces default to the option that honours resource-context Azure RBAC as well as workspace rights; the stricter choice demands explicit access to the workspace or its tables.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Agent identity blueprint
Template in Microsoft Entra Agent ID that holds credentials for one type of agent and obtains tokens for the agent identities created from it. Policies like Conditional Access set on it reach all those identities; Azure RBAC roles cannot be assigned to it.
- Azure ABAC
Attribute-based conditions added on top of Azure RBAC role assignments, such as granting access only to blobs carrying a certain index tag. Blobs (ADLS Gen2 included) and queues support them; Azure Files and Tables do not.
- Azure custom role
A role you author yourself for Azure RBAC, listing permitted and excluded control-plane and data-plane operations plus the scopes it may be assigned at. Excluded operations are simply taken out of the allowed set rather than blocked, and if the role includes data-plane operations it can't be used at management group level.
- Azure custom roles
Roles you author yourself in Azure RBAC, listing your own permitted actions, for cases no built-in role covers; a tenant can hold as many as 5,000.
- Classic subscription administrator roles
Azure's original way of granting access: Account Administrator, Service Administrator and Co-Administrator. By May 2026 Microsoft had fully retired the latter two, leaving Azure RBAC to control access, while Account Administrator remains only as owner of the billing account.
- Classic subscription administrators
Old roles with authority over a whole subscription, namely Account Administrator, Service Administrator and Co-Administrator; they were retired in August 2024 in favour of Azure RBAC.