Least Privilege Role for Azure OpenAI Studio Usage
You have an Azure subscription that contains an Azure OpenAI resource named AI1 and a user named User1. You need to ensure that User1 can perform the following actions in Azure OpenAI Studio: • Identify resource endpoints. • View models that are available for deployment. • Generate text and images by using the deployed models. The solution must follow the principle of least privilege. Which role should you assign to User1?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests RBAC least privilege for Azure OpenAI Studio; the common trap is choosing a Contributor role when the user only needs to consume, not deploy, models.
Assigning the correct Azure RBAC role for Azure OpenAI Studio ensures users can view endpoints and generate content without excessive permissions. This page establishes that the Cognitive Services OpenAI User role is the least privileged role for these specific tasks.
Choosing Cognitive Services OpenAI Contributor (D) because it sounds similar, but it grants model deployment creation rights which are not required.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The Cognitive Services OpenAI User role is explicitly designed to allow users to identify resource endpoints, view models available for deployment, and use deployed models to generate text and images in the playground. It strictly follows the principle of least privilege by omitting the ability to create, update, or delete model deployments, which User1 does not need.Why the Other Options Are Wrong
The Cognitive Services OpenAI Contributor role (D) allows users to create and manage model deployments, exceeding the required permissions. The Cognitive Services Contributor role (B) grants broad management access over all Cognitive Services resources, while the built-in Contributor role (C) provides full management access at the resource level. Both B and C severely violate the principle of least privilege for this scenario.Community Comment Notes
Community members correctly point out that the User role provides the minimum permissions needed to view and interact with Azure OpenAI resources. As one commenter noted, it allows users to "Use playground experiences with any models that have already been deployed" without granting deployment creation rights.Official Reference
Exam Strategy
When asked for an RBAC role following least privilege, carefully distinguish between 'User' and 'Contributor' roles. 'User' typically implies read and consume access for existing resources, while 'Contributor' implies create and manage access.