Least Privilege Role for Azure OpenAI Studio Usage

Manage, monitor, and secure a Microsoft Foundry Service
Answer Correct answer: A — Assign the Cognitive Services OpenAI User role to allow viewing endpoints and generating content without deployment rights.

You have an Azure subscription that contains an Azure OpenAI resource named AI1 and a user named User1. You need to ensure that User1 can perform the following actions in Azure OpenAI Studio: • Identify resource endpoints. • View models that are available for deployment. • Generate text and images by using the deployed models. The solution must follow the principle of least privilege. Which role should you assign to User1?

  1. Cognitive Services OpenAI User Correct Answer
  2. Cognitive Services Contributor
  3. Contributor
  4. Cognitive Services OpenAI Contributor

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests RBAC least privilege for Azure OpenAI Studio; the common trap is choosing a Contributor role when the user only needs to consume, not deploy, models.

Assigning the correct Azure RBAC role for Azure OpenAI Studio ensures users can view endpoints and generate content without excessive permissions. This page establishes that the Cognitive Services OpenAI User role is the least privileged role for these specific tasks.

Choosing Cognitive Services OpenAI Contributor (D) because it sounds similar, but it grants model deployment creation rights which are not required.

Community Discussion (3 comments)

syupwsh 👍 1 Selected: A
Cognitive Services OpenAI User is CORRECT because this role grants users the minimum permissions needed to view and interact with Azure OpenAI resources. Specifically, it allows users to access resource endpoints, view available models for deployment, and use deployed models to generate text and images in Azure AI Studio. This aligns with the principle of least privilege by providing only the necessary permissions without allowing modification or management of the resource itself. Answer is A
a8da4af 👍 4 Selected: A
A. Cognitive Services OpenAI User Reasoning: The Cognitive Services OpenAI User role provides read-only access to the Azure OpenAI resource, allowing User1 to: Identify resource endpoints View available models for deployment Generate text and images using deployed models This role follows the principle of least privilege by granting only the permissions needed to view and interact with deployed models, without allowing management or configuration changes. The other roles, such as Cognitive Services OpenAI Contributor and Cognitive Services Contributor, grant additional permissions that are unnecessary for User1’s requirements.
Rubby 👍 1
A is correct. Cognitive Services OpenAI User permission: 1.View the resource endpoint under “Keys and Endpoint”. 2.View what models are available for deployment in Azure OpenAI Studio. 3. Use playground experiences with any models that have already been deployed to this Azure OpenAI resource Ref:https://learn.microsoft.com/en-us/azure/ai-services/openai/how-to/role-based-access-control#cognitive-services-openai-contributor

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Cognitive Services OpenAI User role is explicitly designed to allow users to identify resource endpoints, view models available for deployment, and use deployed models to generate text and images in the playground. It strictly follows the principle of least privilege by omitting the ability to create, update, or delete model deployments, which User1 does not need.

Why the Other Options Are Wrong

The Cognitive Services OpenAI Contributor role (D) allows users to create and manage model deployments, exceeding the required permissions. The Cognitive Services Contributor role (B) grants broad management access over all Cognitive Services resources, while the built-in Contributor role (C) provides full management access at the resource level. Both B and C severely violate the principle of least privilege for this scenario.

Community Comment Notes

Community members correctly point out that the User role provides the minimum permissions needed to view and interact with Azure OpenAI resources. As one commenter noted, it allows users to "Use playground experiences with any models that have already been deployed" without granting deployment creation rights.

Official Reference

Exam Strategy

When asked for an RBAC role following least privilege, carefully distinguish between 'User' and 'Contributor' roles. 'User' typically implies read and consume access for existing resources, while 'Contributor' implies create and manage access.

Related Analysis

← Back to AI-102 Study Guide