Azure DevOps built-in role

Deployment Environments Reader

Provides read-only visibility into Azure Deployment Environments project and environment resources. Its project reads are control-plane Actions, while environment administration and output reads are DataActions; pool and pool-schedule reads are excluded. Azure Deployment Environments is in maintenance mode: existing capabilities remain available and supported for current usage, but no new features are planned.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: eb960402-bf75-4cc3-8d68-35b34f960f72

Control-plane actions (4)

Data-plane actions (3)

Excluded actions (2)

Assignable scopes (1)

Practical scope

Assign at a project to view all of its environment types and environments, or at one project environment type to limit visibility to that type. Permissions assigned on the dev center itself are not inherited by projects or deployment environments.

Common use cases (2)

Prerequisites (2)

Best practices (4)

Security considerations (3)

Assignment guidance

For an existing deployment, assign Deployment Environments Reader on the project for project-wide visibility or on a specific project environment type for a smaller boundary. Use Deployment Environments User only for developers who create and manage their own environments, and plan with the service's maintenance-mode status in mind.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →