Azure Compute built-in role
Desktop Virtualization Application Group Reader
Views Azure Virtual Desktop application groups and their related host-pool and session-host context without changing them. It does not assign users or grant the Desktop Virtualization User DataAction.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: aebf23d0-b568-4e86-b8f9-fe83a2c6ab55
Control-plane actions (9)
Microsoft.DesktopVirtualization/applicationgroups/*/readMicrosoft.DesktopVirtualization/applicationgroups/readMicrosoft.DesktopVirtualization/hostpools/readMicrosoft.DesktopVirtualization/hostpools/sessionhosts/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the application group for a single publication boundary. A resource-group or parent assignment is inherited by every application group below it. The role contains read-oriented control-plane Actions and no DataActions.
Common use cases (2)
- Inspect application-group configuration and published resources for audit, support, or troubleshooting.
- Give an application owner visibility into the associated host pool and session hosts without change permissions.
Prerequisites (2)
- Identify the application group or resource boundary the principal must inspect.
- Grant end-user application access separately when the principal also needs to launch the published desktop or RemoteApps.
Best practices (3)
- Assign at the application group instead of the resource group when broader Azure Virtual Desktop visibility is unnecessary.
- Use this role for support and audit duties before considering a contributor role.
- Review inherited parent assignments because they can expose configuration for multiple application groups.
Security considerations (3)
- Read access can reveal published application names, host-pool relationships, session-host metadata, role assignments, alerts, and deployment information.
- The role cannot modify application groups and has no DataActions.
- It does not let the assignee launch applications; Desktop Virtualization User is the separate end-user role.
Assignment guidance
Assign Desktop Virtualization Application Group Reader on the application group for view-only support or audit work. Add Desktop Virtualization User only for approved end-user launch access, and use the contributor role only for application-group changes.
Related roles (2)
- Desktop Virtualization Application Group Contributor: Adds application-group creation, update, and deletion.
- Desktop Virtualization User: Separate DataAction that allows a user to launch applications from an application group.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.