Azure Compute built-in role
Desktop Virtualization Host Pool Contributor
Manages all aspects of an Azure Virtual Desktop host pool. It does not create the underlying virtual machines by itself and does not manage the related application groups or workspaces.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: e307426c-f9b6-4e81-87de-d99efb3c32bc
Control-plane actions (6)
Microsoft.DesktopVirtualization/hostpools/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at an individual host pool for one delegated pool, or at the containing resource group only when every inherited host pool is in scope. The role is control-plane only and has no DataActions; underlying VM, application-group, and workspace administration are separate permissions.
Common use cases (2)
- Configure and operate a host pool, including its service-side properties and registration workflow.
- Delegate host-pool administration while keeping application publishing, workspace administration, and VM lifecycle with other teams.
Prerequisites (2)
- The administrator needs Virtual Machine Contributor to create virtual machines for the host pool.
- Portal deployment also requires Desktop Virtualization Application Group Contributor and Desktop Virtualization Workspace Contributor, or the broader Desktop Virtualization Contributor role.
Best practices (3)
- Assign on the host pool when the team owns only that pool.
- Separate host-pool service configuration from VM lifecycle and application publishing.
- Protect registration tokens and rotate or regenerate them only through approved provisioning workflows.
Security considerations (3)
- Host-pool changes can affect routing, registration, availability, and user access for every session host in the pool.
- The role does not grant guest login or underlying VM management, but registration and service configuration remain sensitive.
- A resource-group assignment provides inherited authority over every host pool in that group.
Assignment guidance
Assign Desktop Virtualization Host Pool Contributor on the host pool to its service administrator. Add Virtual Machine Contributor and the application-group or workspace roles only to principals that perform those separate deployment tasks.
Related roles (4)
- Desktop Virtualization Host Pool Reader: Read-only counterpart for host-pool inspection.
- Virtual Machine Contributor: Microsoft documents this separate role as required to create the host-pool virtual machines.
- Desktop Virtualization Application Group Contributor: Separate role Microsoft documents for portal deployment of the related application group.
- Desktop Virtualization Workspace Contributor: Separate role Microsoft documents for portal deployment of the related workspace.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.