Azure Compute built-in role

Desktop Virtualization Contributor

Manages all Azure Virtual Desktop service resources through Microsoft.DesktopVirtualization, apart from assigning users or groups. It does not grant management of the compute resources that host sessions and is a broad service administrator role, not a least-privilege default.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 082f0a83-3be5-4ba1-904c-961cca79b387

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the Azure Virtual Desktop resource group when the administrator owns all contained host pools, application groups, workspaces, and service objects. Parent assignments are inherited by child resources. Its permissions are control-plane Actions only, with no DataActions or general VM management.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Use Desktop Virtualization Contributor only for administrators responsible for the complete Azure Virtual Desktop service deployment. Keep the scope to its resource group, grant compute and access-administration roles separately, and use object-specific roles for narrower teams.

Related roles (2)

Common questions

When should I assign the Desktop Virtualization Contributor Azure role?

Assign Desktop Virtualization Contributor when you need to: Administer host pools, application groups, workspaces, and other Azure Virtual Desktop service objects across a deliberately bounded deployment.; and Run trusted service-management automation that requires the full Microsoft.DesktopVirtualization control plane.. Practical scope: Assign at the Azure Virtual Desktop resource group when the administrator owns all contained host pools, application groups, workspaces, and service objects. Parent assignments are inherited by child resources. Its permissions are control-plane Actions only, with no DataActions or general VM management.

What permissions does the Desktop Virtualization Contributor Azure role grant?

The role definition grants 6 combined control-plane and data-plane actions. Representative operations include: Microsoft.DesktopVirtualization/*; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/deployments/*; Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; and Microsoft.Support/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Desktop Virtualization Contributor Azure role?

Key considerations when assigning Desktop Virtualization Contributor: The wildcard service grant can change or delete all Azure Virtual Desktop service resources in scope.; The role cannot assign users and groups and does not manage the underlying virtual machines, networks, or storage by itself.; and The absence of DataActions does not reduce the operational impact of changing host pools, published resources, workspaces, or session configuration.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →