Azure Compute built-in role
Desktop Virtualization Reader
Views all Azure Virtual Desktop service resources without changing them. It is broad across Microsoft.DesktopVirtualization but remains read-only in the control plane and grants neither end-user application use nor VM guest access.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 49a72310-ab8d-41df-bbb0-79b649203868
Control-plane actions (6)
Microsoft.DesktopVirtualization/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at a dedicated Azure Virtual Desktop resource group for service-wide visibility, or at a narrower resource when supported. Parent assignments are inherited. The role has read-oriented control-plane Actions and no DataActions.
Common use cases (2)
- Provide service-wide configuration visibility to audit, support, monitoring, or architecture teams.
- Troubleshoot relationships among host pools, application groups, workspaces, and other service resources without making changes.
Prerequisites (2)
- Define whether the principal needs visibility across the complete deployment or only one object type.
- Use a more specific application-group, host-pool, or workspace reader when service-wide visibility is unnecessary.
Best practices (3)
- Prefer object-specific reader roles for teams responsible for only one Azure Virtual Desktop resource type.
- Scope service-wide Reader to the dedicated deployment resource group rather than the subscription.
- Grant Desktop Virtualization User separately for approved end-user application access.
Security considerations (3)
- Broad read access exposes service topology, published-resource metadata, host pools, workspaces, alerts, deployments, and role assignments.
- The role cannot change service resources and has no DataActions.
- It does not grant compute management, guest sign-in, or permission to launch published applications.
Assignment guidance
Assign Desktop Virtualization Reader at the deployment resource group for complete view-only service support. Choose an object-specific reader for narrower duties and add end-user or operator roles only for their documented actions.
Related roles (1)
- Desktop Virtualization Contributor: Adds broad Azure Virtual Desktop service-resource management.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.