Azure Compute built-in role

Desktop Virtualization Application Group Reader

Views Azure Virtual Desktop application groups and their related host-pool and session-host context without changing them. It does not assign users or grant the Desktop Virtualization User DataAction.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: aebf23d0-b568-4e86-b8f9-fe83a2c6ab55

Control-plane actions (9)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the application group for a single publication boundary. A resource-group or parent assignment is inherited by every application group below it. The role contains read-oriented control-plane Actions and no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Application Group Reader on the application group for view-only support or audit work. Add Desktop Virtualization User only for approved end-user launch access, and use the contributor role only for application-group changes.

Related roles (2)

Common questions

When should I assign the Desktop Virtualization Application Group Reader Azure role?

Assign Desktop Virtualization Application Group Reader when you need to: Inspect application-group configuration and published resources for audit, support, or troubleshooting.; and Give an application owner visibility into the associated host pool and session hosts without change permissions.. Practical scope: Assign at the application group for a single publication boundary. A resource-group or parent assignment is inherited by every application group below it. The role contains read-oriented control-plane Actions and no DataActions.

What permissions does the Desktop Virtualization Application Group Reader Azure role grant?

The role definition grants 9 combined control-plane and data-plane actions. Representative operations include: Microsoft.DesktopVirtualization/applicationgroups/*/read; Microsoft.DesktopVirtualization/applicationgroups/read; Microsoft.DesktopVirtualization/hostpools/read; Microsoft.DesktopVirtualization/hostpools/sessionhosts/read; Microsoft.Resources/subscriptions/resourceGroups/read; and Microsoft.Resources/deployments/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Desktop Virtualization Application Group Reader Azure role?

Key considerations when assigning Desktop Virtualization Application Group Reader: Read access can reveal published application names, host-pool relationships, session-host metadata, role assignments, alerts, and deployment information.; The role cannot modify application groups and has no DataActions.; and It does not let the assignee launch applications; Desktop Virtualization User is the separate end-user role.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →