Azure RBAC roles containing actions you pick yourself, for when no built-in role fits; a tenant can hold as many as 5,000.
Also called Azure custom roles.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Custom roles in context, with comparison tables and the common traps.
Terms in this definition
- Azure RBAC
Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
Related terms
- App consent policy
Set of include and exclude conditions deciding which permissions users, or holders of custom roles, are allowed to consent to; microsoft-user-default-low is one built-in policy.
- Intune Role Administrator
One of Intune's built-in roles. Holders look after custom roles and can hand out the built-in ones; it is the sole Intune role allowed to give other admins permissions.