Azure Compute built-in role

Desktop Virtualization Host Pool Reader

Views all aspects of an Azure Virtual Desktop host pool without changing it. The role does not manage session hosts, virtual machines, or end-user sessions and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ceadfde2-b300-400a-ab7b-6143895aa822

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the host pool for one pool or at a resource group for inherited visibility across every host pool below it. Permissions are read-oriented control-plane Actions only.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Host Pool Reader on the specific host pool for view-only support and audit duties. Use Session Host Operator or User Session Operator only for the corresponding operational actions, and Contributor for approved host-pool changes.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →