Azure Compute built-in role

Desktop Virtualization Application Group Contributor

Manages all aspects of Azure Virtual Desktop application groups except assigning users or groups to them. It can also read the associated host pool and session hosts, but it does not manage those resources or grant users permission to launch applications.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 86240b0e-9422-4c43-887b-b61143f32ba8

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the application group for one published desktop or RemoteApp boundary, or at a resource group only when administration of every inherited application group is intended. The role uses control-plane Actions and has no DataActions; user or group assignment requires separate Azure RBAC access administration.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Application Group Contributor on the application group to the publishing administrator. Grant Azure RBAC assignment authority separately and only when that principal must also add or remove users or groups.

Related roles (2)

Common questions

When should I assign the Desktop Virtualization Application Group Contributor Azure role?

Assign Desktop Virtualization Application Group Contributor when you need to: Create, update, or delete an application group and configure its published desktop or RemoteApp resources.; and Delegate application publishing to an Azure Virtual Desktop application team without host-pool or workspace administration.. Practical scope: Assign at the application group for one published desktop or RemoteApp boundary, or at a resource group only when administration of every inherited application group is intended. The role uses control-plane Actions and has no DataActions; user or group assignment requires separate Azure RBAC access administration.

What permissions does the Desktop Virtualization Application Group Contributor Azure role grant?

The role definition grants 8 combined control-plane and data-plane actions. Representative operations include: Microsoft.DesktopVirtualization/applicationgroups/*; Microsoft.DesktopVirtualization/hostpools/read; Microsoft.DesktopVirtualization/hostpools/sessionhosts/read; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/deployments/*; and Microsoft.Authorization/*/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Desktop Virtualization Application Group Contributor Azure role?

Key considerations when assigning Desktop Virtualization Application Group Contributor: Changing an application group can expose or remove desktops and applications for its assigned users.; The role cannot assign members, but it can change what already assigned users can launch.; and It has no DataActions and does not grant end-user application access or guest-session access.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →