Azure Compute built-in role
Desktop Virtualization Application Group Contributor
Manages all aspects of Azure Virtual Desktop application groups except assigning users or groups to them. It can also read the associated host pool and session hosts, but it does not manage those resources or grant users permission to launch applications.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 86240b0e-9422-4c43-887b-b61143f32ba8
Control-plane actions (8)
Microsoft.DesktopVirtualization/applicationgroups/*Microsoft.DesktopVirtualization/hostpools/readMicrosoft.DesktopVirtualization/hostpools/sessionhosts/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the application group for one published desktop or RemoteApp boundary, or at a resource group only when administration of every inherited application group is intended. The role uses control-plane Actions and has no DataActions; user or group assignment requires separate Azure RBAC access administration.
Common use cases (2)
- Create, update, or delete an application group and configure its published desktop or RemoteApp resources.
- Delegate application publishing to an Azure Virtual Desktop application team without host-pool or workspace administration.
Prerequisites (2)
- The target host pool must exist, and the administrator must know which application group and published resources it owns.
- A separately authorized access administrator is required when users or groups must be assigned to the application group.
Best practices (3)
- Assign at the individual application group when the team owns only one publication boundary.
- Keep user assignment separate from application-group configuration unless the same trusted administrator requires both duties.
- Use the Reader counterpart for support or audit work that requires no changes.
Security considerations (3)
- Changing an application group can expose or remove desktops and applications for its assigned users.
- The role cannot assign members, but it can change what already assigned users can launch.
- It has no DataActions and does not grant end-user application access or guest-session access.
Assignment guidance
Assign Desktop Virtualization Application Group Contributor on the application group to the publishing administrator. Grant Azure RBAC assignment authority separately and only when that principal must also add or remove users or groups.
Related roles (2)
- Desktop Virtualization Application Group Reader: Read-only counterpart for application-group inspection.
- User Access Administrator: Microsoft documents separate access-administration authority as required to assign users or groups to application groups.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.