Azure Compute built-in role

Desktop Virtualization Reader

Views all Azure Virtual Desktop service resources without changing them. It is broad across Microsoft.DesktopVirtualization but remains read-only in the control plane and grants neither end-user application use nor VM guest access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 49a72310-ab8d-41df-bbb0-79b649203868

Control-plane actions (6)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at a dedicated Azure Virtual Desktop resource group for service-wide visibility, or at a narrower resource when supported. Parent assignments are inherited. The role has read-oriented control-plane Actions and no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Reader at the deployment resource group for complete view-only service support. Choose an object-specific reader for narrower duties and add end-user or operator roles only for their documented actions.

Related roles (1)

Common questions

When should I assign the Desktop Virtualization Reader Azure role?

Assign Desktop Virtualization Reader when you need to: Provide service-wide configuration visibility to audit, support, monitoring, or architecture teams.; and Troubleshoot relationships among host pools, application groups, workspaces, and other service resources without making changes.. Practical scope: Assign at a dedicated Azure Virtual Desktop resource group for service-wide visibility, or at a narrower resource when supported. Parent assignments are inherited. The role has read-oriented control-plane Actions and no DataActions.

What permissions does the Desktop Virtualization Reader Azure role grant?

The role definition grants 6 combined control-plane and data-plane actions. Representative operations include: Microsoft.DesktopVirtualization/*/read; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/deployments/read; Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/read; and Microsoft.Support/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Desktop Virtualization Reader Azure role?

Key considerations when assigning Desktop Virtualization Reader: Broad read access exposes service topology, published-resource metadata, host pools, workspaces, alerts, deployments, and role assignments.; The role cannot change service resources and has no DataActions.; and It does not grant compute management, guest sign-in, or permission to launch published applications.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →