Azure Compute built-in role

Desktop Virtualization Host Pool Contributor

Manages all aspects of an Azure Virtual Desktop host pool. It does not create the underlying virtual machines by itself and does not manage the related application groups or workspaces.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: e307426c-f9b6-4e81-87de-d99efb3c32bc

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at an individual host pool for one delegated pool, or at the containing resource group only when every inherited host pool is in scope. The role is control-plane only and has no DataActions; underlying VM, application-group, and workspace administration are separate permissions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Host Pool Contributor on the host pool to its service administrator. Add Virtual Machine Contributor and the application-group or workspace roles only to principals that perform those separate deployment tasks.

Related roles (4)

Editorial sources (5)

Official Microsoft Learn documentation →