Azure Compute built-in role
Desktop Virtualization User Session Operator
Manages active Azure Virtual Desktop user sessions by sending messages, disconnecting sessions, and signing users out. It can view assignments but cannot modify members, host pools, or session-host configuration.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: ea4bfff8-7fb4-485a-aadd-d4129a0ffaa6
Control-plane actions (8)
Microsoft.DesktopVirtualization/hostpools/readMicrosoft.DesktopVirtualization/hostpools/sessionhosts/readMicrosoft.DesktopVirtualization/hostpools/sessionhosts/usersessions/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Microsoft recommends assigning this role to specific host pools. At resource-group scope it inherits read visibility across all host pools in the group. Its user-session operations are control-plane Actions and it has no DataActions.
Common use cases (2)
- Let help-desk staff message or disconnect a user session while troubleshooting.
- Sign users out of an approved host pool during maintenance or incident response.
Prerequisites (2)
- Identify the host pools whose user sessions the operator is authorized to manage.
- Establish operational procedures for notification, disconnect, and forced sign-out, including handling unsaved user work.
Best practices (3)
- Assign on specific host pools rather than the resource group, as Microsoft recommends.
- Send a message before disconnecting or signing out a user when the incident permits.
- Log and review forced sign-outs and remove the role from staff who no longer perform session support.
Security considerations (3)
- Forced sign-out can terminate applications and cause loss of unsaved user data.
- The role exposes active-session information and can disrupt any user in the assigned host pool.
- It cannot change host-pool or session-host configuration and does not grant VM guest login.
Assignment guidance
Assign Desktop Virtualization User Session Operator to support personnel on each host pool they service. Avoid resource-group scope, require an approved session-intervention procedure, and use Session Host Operator only for host membership or drain-mode duties.
Related roles (1)
- Desktop Virtualization Session Host Operator: Manages session-host membership and drain mode rather than individual user sessions.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.