Azure DevOps built-in role

Deployment Environments User

Creates, reads, redeploys, updates, and deletes the principal's own Azure Deployment Environments. Project discovery uses control-plane Actions, while the user environment lifecycle and output operations are DataActions; pool and schedule reads are excluded. Azure Deployment Environments is in maintenance mode: existing capabilities remain available and supported for current usage, but no new features are planned.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 18e40d4e-8d2e-438d-97e1-9528336e149c

Control-plane actions (4)

Data-plane actions (5)

Excluded actions (2)

Assignable scopes (1)

Practical scope

Assign at a project to let a developer use every available project environment type, or at a specific project environment type to limit creation and management to that type. A role on the dev center is not inherited by its projects or environments.

Common use cases (2)

Prerequisites (3)

Best practices (4)

Security considerations (3)

Assignment guidance

For an existing deployment, assign Deployment Environments User to a developer group at the project or specific environment-type scope. Configure the dev-center identity's documented subscription roles separately, attach a narrower deployment identity and resource roles to the project environment type, and use Reader when only visibility is required. No new Deployment Environments features are planned.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →