Azure Compute built-in role

Desktop Virtualization Session Host Operator

Views and removes Azure Virtual Desktop session hosts and changes drain mode. It cannot add session hosts through the Azure portal because it cannot write the host-pool object; outside the portal, a valid registration token and separate VM permissions are required to add a host.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 2ad6aaab-ead9-4eaa-8ac5-da422f562408

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the specific host pool whose session hosts the operator manages. A resource-group assignment is inherited by all host pools and is broader than Microsoft recommends for separated operations. Permissions are control-plane Actions and there are no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Session Host Operator on a specific host pool to operations staff responsible for host membership and drain mode. Add Virtual Machine Contributor only for approved VM provisioning and do not substitute this role for user-session operations.

Related roles (2)

Common questions

When should I assign the Desktop Virtualization Session Host Operator Azure role?

Assign Desktop Virtualization Session Host Operator when you need to: Place session hosts into or out of drain mode and remove hosts from an approved host pool.; and Operate session-host registration outside the portal when a valid token and separate VM management access are already provided.. Practical scope: Assign on the specific host pool whose session hosts the operator manages. A resource-group assignment is inherited by all host pools and is broader than Microsoft recommends for separated operations. Permissions are control-plane Actions and there are no DataActions.

What permissions does the Desktop Virtualization Session Host Operator Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.DesktopVirtualization/hostpools/read; Microsoft.DesktopVirtualization/hostpools/sessionhosts/*; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/deployments/*; Microsoft.Authorization/*/read; and Microsoft.Insights/alertRules/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Desktop Virtualization Session Host Operator Azure role?

Key considerations when assigning Desktop Virtualization Session Host Operator: Removing session hosts or changing drain mode changes capacity and can affect user availability.; The role cannot manage the underlying VM by itself and cannot write the host-pool object needed for portal-based host addition.; and Registration tokens are sensitive because they authorize session-host registration during their validity window.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →