Azure Compute built-in role
Desktop Virtualization User
Allows a non-administrative user to use an application on a session host from an assigned Azure Virtual Desktop application group. It is an end-user data-plane role and grants no service-resource management.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 1d18fff3-a72a-46b5-b4a9-0b38a3cd7e63
Control-plane actions (0)
None — this role grants no control-plane management actions.
Data-plane actions (2)
Microsoft.DesktopVirtualization/applicationGroups/useApplications/actionMicrosoft.DesktopVirtualization/appAttachPackages/useApplications/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign directly on the application group that publishes the approved desktop or applications. The role contains DataActions only; assigning it at a resource group or broader scope would inherit application-use access across every application group below that scope.
Common use cases (1)
- Give a user or group access to the desktop or applications published through a specific Azure Virtual Desktop application group.
Prerequisites (2)
- The application group must be associated with a functioning host pool and workspace, and the intended desktop or applications must be published.
- The user must meet the Azure Virtual Desktop identity, licensing, client, and network requirements for the deployment.
Best practices (3)
- Assign groups rather than individual users where practical and scope the assignment directly to the application group.
- Separate different access populations into application groups instead of granting at a parent resource group.
- Review membership and remove access promptly when a user no longer needs the published resources.
Security considerations (3)
- The DataActions grant real application and desktop use even though the role has no control-plane Actions.
- The security impact depends on the applications, data, network paths, and identity privileges available inside the session.
- The role does not make the user a session host or service administrator and should not be combined with administrative roles by default.
Assignment guidance
Assign Desktop Virtualization User to an approved user group on the specific application group. Do not assign it at the resource group unless every contained application group is intended for the same population, and keep administrative roles separate.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.