Azure Compute built-in role
Desktop Virtualization Contributor
Manages all Azure Virtual Desktop service resources through Microsoft.DesktopVirtualization, apart from assigning users or groups. It does not grant management of the compute resources that host sessions and is a broad service administrator role, not a least-privilege default.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 082f0a83-3be5-4ba1-904c-961cca79b387
Control-plane actions (6)
Microsoft.DesktopVirtualization/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the Azure Virtual Desktop resource group when the administrator owns all contained host pools, application groups, workspaces, and service objects. Parent assignments are inherited by child resources. Its permissions are control-plane Actions only, with no DataActions or general VM management.
Common use cases (2)
- Administer host pools, application groups, workspaces, and other Azure Virtual Desktop service objects across a deliberately bounded deployment.
- Run trusted service-management automation that requires the full Microsoft.DesktopVirtualization control plane.
Prerequisites (2)
- Confirm that one principal genuinely needs all Azure Virtual Desktop service-resource administration rather than one of the object-specific roles.
- Grant compute-resource management and user or group assignment through separate roles where those tasks are required.
Best practices (3)
- Prefer host-pool, application-group, workspace, session, or reader roles for separated duties.
- Assign at a dedicated Azure Virtual Desktop resource group and avoid subscription scope unless multiple deployments are intentionally managed together.
- Use PIM for eligible human assignments where available and review broad assignments regularly.
Security considerations (3)
- The wildcard service grant can change or delete all Azure Virtual Desktop service resources in scope.
- The role cannot assign users and groups and does not manage the underlying virtual machines, networks, or storage by itself.
- The absence of DataActions does not reduce the operational impact of changing host pools, published resources, workspaces, or session configuration.
Assignment guidance
Use Desktop Virtualization Contributor only for administrators responsible for the complete Azure Virtual Desktop service deployment. Keep the scope to its resource group, grant compute and access-administration roles separately, and use object-specific roles for narrower teams.
Related roles (2)
- Desktop Virtualization Reader: Read-only service-wide counterpart.
- User Access Administrator: Microsoft documents separate access-administration authority as required for user or group assignment.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.