Azure Compute built-in role

Desktop Virtualization Contributor

Manages all Azure Virtual Desktop service resources through Microsoft.DesktopVirtualization, apart from assigning users or groups. It does not grant management of the compute resources that host sessions and is a broad service administrator role, not a least-privilege default.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 082f0a83-3be5-4ba1-904c-961cca79b387

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the Azure Virtual Desktop resource group when the administrator owns all contained host pools, application groups, workspaces, and service objects. Parent assignments are inherited by child resources. Its permissions are control-plane Actions only, with no DataActions or general VM management.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Use Desktop Virtualization Contributor only for administrators responsible for the complete Azure Virtual Desktop service deployment. Keep the scope to its resource group, grant compute and access-administration roles separately, and use object-specific roles for narrower teams.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →