Azure Compute built-in role
Desktop Virtualization Host Pool Reader
Views all aspects of an Azure Virtual Desktop host pool without changing it. The role does not manage session hosts, virtual machines, or end-user sessions and has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: ceadfde2-b300-400a-ab7b-6143895aa822
Control-plane actions (7)
Microsoft.DesktopVirtualization/hostpools/*/readMicrosoft.DesktopVirtualization/hostpools/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the host pool for one pool or at a resource group for inherited visibility across every host pool below it. Permissions are read-oriented control-plane Actions only.
Common use cases (2)
- Inspect host-pool settings, status, deployments, alerts, and role assignments for support or audit work.
- Give an application or operations team host-pool context without service changes.
Prerequisites (2)
- Identify the host pool or resource boundary that the principal needs to inspect.
- Use a session-host or user-session operator role separately if operational actions are required.
Best practices (3)
- Assign at the individual host pool unless the reader supports every pool in the resource group.
- Use this role instead of Host Pool Contributor for troubleshooting that requires no changes.
- Review inherited visibility where host-pool names and configuration are sensitive.
Security considerations (3)
- Read access exposes host-pool configuration, deployment data, alert information, and Azure RBAC assignments.
- The role cannot change the host pool and has no DataActions.
- It does not provide guest-session or virtual-machine access.
Assignment guidance
Assign Desktop Virtualization Host Pool Reader on the specific host pool for view-only support and audit duties. Use Session Host Operator or User Session Operator only for the corresponding operational actions, and Contributor for approved host-pool changes.
Related roles (1)
- Desktop Virtualization Host Pool Contributor: Adds full host-pool management when read-only access is insufficient.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.