Azure Compute built-in role

Desktop Virtualization User

Allows a non-administrative user to use an application on a session host from an assigned Azure Virtual Desktop application group. It is an end-user data-plane role and grants no service-resource management.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 1d18fff3-a72a-46b5-b4a9-0b38a3cd7e63

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (2)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the application group that publishes the approved desktop or applications. The role contains DataActions only; assigning it at a resource group or broader scope would inherit application-use access across every application group below that scope.

Common use cases (1)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization User to an approved user group on the specific application group. Do not assign it at the resource group unless every contained application group is intended for the same population, and keep administrative roles separate.

Common questions

When should I assign the Desktop Virtualization User Azure role?

Assign Desktop Virtualization User when you need to: Give a user or group access to the desktop or applications published through a specific Azure Virtual Desktop application group.. Practical scope: Assign directly on the application group that publishes the approved desktop or applications. The role contains DataActions only; assigning it at a resource group or broader scope would inherit application-use access across every application group below that scope.

What permissions does the Desktop Virtualization User Azure role grant?

The role definition grants 2 combined control-plane and data-plane actions. Representative operations include: Microsoft.DesktopVirtualization/applicationGroups/useApplications/action; and Microsoft.DesktopVirtualization/appAttachPackages/useApplications/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Desktop Virtualization User Azure role?

Key considerations when assigning Desktop Virtualization User: The DataActions grant real application and desktop use even though the role has no control-plane Actions.; The security impact depends on the applications, data, network paths, and identity privileges available inside the session.; and The role does not make the user a session host or service administrator and should not be combined with administrative roles by default.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →