Least-privileged built-in role aimed at developers: it pairs read access with the data actions needed to create and try things out inside a Foundry project, and each project's managed identity is granted it too.
Also called Azure AI User, Azure AI User.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Foundry User in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Foundry project
A container beneath a Foundry resource that keeps one team's agents, data, files, evaluations and project connections separate. Model deployments and resource-level connections are shared from the parent, and governance is not configured at this level.
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
Related terms
- Azure AI Developer
Built-in role scoped to an Azure Machine Learning workspace or hub: holders can do anything inside it except administer the workspace itself. For Foundry projects, the equivalent roles are Foundry Owner and Foundry User.
- Azure RBAC
Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.
- Foundry Account Owner
A built-in role able to manage Foundry resources and projects, including deployments, networking and connections, and to grant the Foundry User role. Lacking data actions, it cannot build anything inside a project.
- Foundry Project Manager
A built-in role that can both manage Foundry projects and build within them. When granting access to others, the only role it can assign is Foundry User.