Azure Compute built-in role
Desktop Virtualization Session Host Operator
Views and removes Azure Virtual Desktop session hosts and changes drain mode. It cannot add session hosts through the Azure portal because it cannot write the host-pool object; outside the portal, a valid registration token and separate VM permissions are required to add a host.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 2ad6aaab-ead9-4eaa-8ac5-da422f562408
Control-plane actions (7)
Microsoft.DesktopVirtualization/hostpools/readMicrosoft.DesktopVirtualization/hostpools/sessionhosts/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the specific host pool whose session hosts the operator manages. A resource-group assignment is inherited by all host pools and is broader than Microsoft recommends for separated operations. Permissions are control-plane Actions and there are no DataActions.
Common use cases (2)
- Place session hosts into or out of drain mode and remove hosts from an approved host pool.
- Operate session-host registration outside the portal when a valid token and separate VM management access are already provided.
Prerequisites (2)
- For adding session hosts outside the portal, a valid unexpired host-pool registration token and Virtual Machine Contributor are required.
- Use Desktop Virtualization User Session Operator instead when the task concerns user sessions rather than session-host membership or drain mode.
Best practices (3)
- Assign to the specific host pool, as recommended by Microsoft, rather than the resource group.
- Coordinate drain mode and host removal with session monitoring to avoid disrupting active users.
- Protect registration tokens and expire or regenerate them after provisioning.
Security considerations (3)
- Removing session hosts or changing drain mode changes capacity and can affect user availability.
- The role cannot manage the underlying VM by itself and cannot write the host-pool object needed for portal-based host addition.
- Registration tokens are sensitive because they authorize session-host registration during their validity window.
Assignment guidance
Assign Desktop Virtualization Session Host Operator on a specific host pool to operations staff responsible for host membership and drain mode. Add Virtual Machine Contributor only for approved VM provisioning and do not substitute this role for user-session operations.
Related roles (2)
- Virtual Machine Contributor: Microsoft documents this separate role as required when adding session hosts outside the portal with a valid registration token.
- Desktop Virtualization User Session Operator: Handles messages, disconnects, and sign-out for user sessions rather than host membership.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.