Azure DevOps built-in role
Deployment Environments Reader
Provides read-only visibility into Azure Deployment Environments project and environment resources. Its project reads are control-plane Actions, while environment administration and output reads are DataActions; pool and pool-schedule reads are excluded. Azure Deployment Environments is in maintenance mode: existing capabilities remain available and supported for current usage, but no new features are planned.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: eb960402-bf75-4cc3-8d68-35b34f960f72
Control-plane actions (4)
Microsoft.DevCenter/projects/readMicrosoft.DevCenter/projects/*/readMicrosoft.Authorization/*/readMicrosoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (3)
Microsoft.DevCenter/projects/users/environments/adminRead/actionMicrosoft.DevCenter/projects/users/environments/adminActionRead/actionMicrosoft.DevCenter/projects/users/environments/adminOutputsRead/action
Excluded actions (2)
Microsoft.DevCenter/projects/pools/readMicrosoft.DevCenter/projects/pools/schedules/read
Assignable scopes (1)
/
Practical scope
Assign at a project to view all of its environment types and environments, or at one project environment type to limit visibility to that type. Permissions assigned on the dev center itself are not inherited by projects or deployment environments.
Common use cases (2)
- For an existing Deployment Environments project, let a developer, service principal, or dev manager view environments created by any user without creating, redeploying, or deleting them.
- Give an auditor current supported visibility into one project or one environment type while keeping environment management separate.
Prerequisites (2)
- A dev center, project, and the environment types or environments to review must already exist.
- Choose whether the principal needs all project environment types or only one environment-type boundary before assigning the role.
Best practices (4)
- Use an environment-type assignment when the reviewer should not see every environment type in the project.
- Assign groups rather than individual users when the same review responsibility belongs to a team.
- Grant access to the Azure resources deployed inside an environment separately and only when the reviewer needs it.
- Treat the assignment as access for current supported usage and do not plan around future Deployment Environments features, because no new features are planned.
Security considerations (3)
- The DataActions expose environment records and deployment outputs throughout the assigned project or environment type.
- The role does not grant permission to modify environment resources or automatically authorize access to the Azure resources deployed inside an environment.
- A project-level assignment is broader than an environment-type assignment and covers environments created by other users.
Assignment guidance
For an existing deployment, assign Deployment Environments Reader on the project for project-wide visibility or on a specific project environment type for a smaller boundary. Use Deployment Environments User only for developers who create and manage their own environments, and plan with the service's maintenance-mode status in mind.
Related roles (2)
- Deployment Environments User: Adds creation, update, action, output, and deletion permissions for the user's own environments.
- DevCenter Project Admin: Provides administrative management across all environments and environment types in a project.
Editorial sources (7)
- Azure built-in roles for DevOps - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Plan Azure Role-Based Access Control - Azure Deployment Environments | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure Deployment Environments - maintenance mode - Azure Deployment Environments | Microsoft Learn →
Supports: Description, Common use cases, Best practices, Assignment guidance. Retrieved 2026-07-17.