Azure Compute built-in role

Desktop Virtualization Host Pool Reader

Views all aspects of an Azure Virtual Desktop host pool without changing it. The role does not manage session hosts, virtual machines, or end-user sessions and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ceadfde2-b300-400a-ab7b-6143895aa822

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the host pool for one pool or at a resource group for inherited visibility across every host pool below it. Permissions are read-oriented control-plane Actions only.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Host Pool Reader on the specific host pool for view-only support and audit duties. Use Session Host Operator or User Session Operator only for the corresponding operational actions, and Contributor for approved host-pool changes.

Related roles (1)

Common questions

When should I assign the Desktop Virtualization Host Pool Reader Azure role?

Assign Desktop Virtualization Host Pool Reader when you need to: Inspect host-pool settings, status, deployments, alerts, and role assignments for support or audit work.; and Give an application or operations team host-pool context without service changes.. Practical scope: Assign at the host pool for one pool or at a resource group for inherited visibility across every host pool below it. Permissions are read-oriented control-plane Actions only.

What permissions does the Desktop Virtualization Host Pool Reader Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.DesktopVirtualization/hostpools/*/read; Microsoft.DesktopVirtualization/hostpools/read; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/deployments/read; Microsoft.Authorization/*/read; and Microsoft.Insights/alertRules/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Desktop Virtualization Host Pool Reader Azure role?

Key considerations when assigning Desktop Virtualization Host Pool Reader: Read access exposes host-pool configuration, deployment data, alert information, and Azure RBAC assignments.; The role cannot change the host pool and has no DataActions.; and It does not provide guest-session or virtual-machine access.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →