Azure Compute built-in role

Desktop Virtualization Application Group Reader

Views Azure Virtual Desktop application groups and their related host-pool and session-host context without changing them. It does not assign users or grant the Desktop Virtualization User DataAction.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: aebf23d0-b568-4e86-b8f9-fe83a2c6ab55

Control-plane actions (9)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the application group for a single publication boundary. A resource-group or parent assignment is inherited by every application group below it. The role contains read-oriented control-plane Actions and no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Application Group Reader on the application group for view-only support or audit work. Add Desktop Virtualization User only for approved end-user launch access, and use the contributor role only for application-group changes.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →