AI-102 Plan and manage an Azure AI solution Practice Question
You are planning to deploy an Azure AI Language resource that will be used by multiple applications. The applications must authenticate using Microsoft Entra ID (Azure AD) tokens. You need to assign the appropriate role to the applications' managed identities so they can call the Azure AI Language service. Which role should you assign?
⚠ Common exam trap
Many exam-takers confuse the Contributor role, which manages the resource, with the User role, which allows calling the service API.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cognitive Services User
For applications to call Azure AI Language using Microsoft Entra ID authentication, they need a role that grants data-plane access. The Cognitive Services User role provides read and write access to the service's data plane without granting management permissions. This aligns with least privilege and is the correct choice for managed identities that only need to invoke the API.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reader
Why it's wrong here
The Reader role allows viewing of the Azure AI Language resource but does not permit calling the service APIs. It is a management-plane role that provides read-only access to resource metadata. Applications need data-plane access to submit text for analysis, so this role would result in authorization failures when the application attempts to call the service. It is insufficient for the requirement.
- ✗
Azure AI Developer
Why it's wrong here
The Azure AI Developer role is designed for developers who need to build and manage AI applications, but it includes permissions to manage Azure AI resources, such as creating and deploying models. It is not the minimal role for simply calling the Azure AI Language service. Using this role would grant unnecessary management capabilities, which is not appropriate for application identities that only need to invoke the API.
- ✓
Cognitive Services User
Why this is correct
The Cognitive Services User role grants access to read and write data for Azure AI services, including calling the Azure AI Language APIs. It allows the managed identity to authenticate and perform operations such as text analytics and language understanding. This role provides the necessary permissions without granting full control over the resource, following the principle of least privilege for application access.
- ✗
Cognitive Services Contributor
Why it's wrong here
The Cognitive Services Contributor role grants full management permissions over the Azure AI services resource, including the ability to manage keys, configure settings, and delete the resource. Applications that only need to call the API do not require such broad permissions. Assigning this role would violate the principle of least privilege and increase security risk, making it unsuitable for the scenario.
Go deeper
Related to this question
About these practice questions
This AI-102 question is part of Courseiva's 761-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.