last sync: 2025-Oct-23 17:22:49 UTC

Azure AI Account Owner

Azure BuiltIn RBAC Role definition

NameAzure AI Account Owner
Ide47c6f54-e4a2-4754-9501-8e0985b135e1
DescriptionGrants full access to manage AI projects and accounts. Grants conditional assignment of the Azure AI User role to other user principles.
CategoryNone
CreatedOn2025-05-01 00:11:10 UTC
UpdatedOn2025-05-01 00:11:10 UTC
Permissions summary Effective control plane and data plane operations: 188 (unique operations)
•: 1
•action: 30
•delete: 27
•read: 100
•write: 30

Actions: 20
Resolved control plane operations from Actions: 188
Effective control plane operations: 188
•: 1
•action: 30
•delete: 27
•read: 100
•write: 30

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 17188

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 4081
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Authorization/roleAssignments/delete conditionedDelete a role assignment at the specified scope.
Microsoft.Authorization/roleAssignments/write conditionedCreate a role assignment at the specified scope.
Microsoft.CognitiveServices/*wildcarded / no description
Microsoft.Features/features/readGets the features of a subscription.
Microsoft.Features/providers/features/readGets the feature of a subscription in a given resource provider.
Microsoft.Features/providers/features/register/actionRegisters the feature for a subscription in a given resource provider.
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.Insights/diagnosticSettings/*wildcarded / no description
Microsoft.Insights/logDefinitions/readRead log definitions
Microsoft.Insights/metricdefinitions/readRead metric definitions
Microsoft.Insights/metrics/readRead metrics
Microsoft.ResourceHealth/availabilityStatuses/readGets the availability statuses for all resources in the specified scope
Microsoft.Resources/deployments/*wildcarded / no description
Microsoft.Resources/deployments/operations/readGets or lists deployment operations.
Microsoft.Resources/subscriptions/operationresults/readGet the subscription operation results.
Microsoft.Resources/subscriptions/readGets the list of subscriptions.
Microsoft.Resources/subscriptions/resourcegroups/deployments/*wildcarded / no description
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Support/*wildcarded / no description
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2025-05-01 19:36:20 add: Role e47c6f54-e4a2-4754-9501-8e0985b135e1
JSON
api-version=2023-07-01-preview
Condition

    (
        (
            !
            (
                ActionMatches {
                'Microsoft.Authorization/roleAssignments/write'
                }
            )
        )
        OR
        (
            @Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
            53ca6127-db72-4b80-b1b0-d745d6d5456d (Azure AI User)
            }
        )
    )
    AND
    (
        (
            !
            (
                ActionMatches {
                'Microsoft.Authorization/roleAssignments/delete'
                }
            )
        )
        OR
        (
            @Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals {
            53ca6127-db72-4b80-b1b0-d745d6d5456d (Azure AI User)
            }
        )
    )