Azure Compute built-in role
Desktop Virtualization Virtual Machine Contributor
Allows the Azure Virtual Desktop resource provider to create, update, delete, start, and stop session-host virtual machines for dynamic autoscale. Microsoft marks the role as preview and subject to change.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: a959dbd1-f747-45e3-8ba6-dd80f235f97c
Control-plane actions (59)
Microsoft.DesktopVirtualization/hostpools/readMicrosoft.DesktopVirtualization/hostpools/writeMicrosoft.DesktopVirtualization/hostpools/retrieveRegistrationToken/actionMicrosoft.DesktopVirtualization/hostpools/sessionhosts/readMicrosoft.DesktopVirtualization/hostpools/sessionhosts/writeMicrosoft.DesktopVirtualization/hostpools/sessionhosts/deleteMicrosoft.DesktopVirtualization/hostpools/sessionhosts/usersessions/readMicrosoft.DesktopVirtualization/hostpools/sessionhosts/usersessions/disconnect/actionMicrosoft.DesktopVirtualization/hostpools/sessionhosts/usersessions/sendMessage/actionMicrosoft.DesktopVirtualization/hostpools/sessionHostConfigurations/readMicrosoft.DesktopVirtualization/hostpools/doNotUseInternalAPI/actionMicrosoft.DesktopVirtualization/hostpools/sessionhosts/retryprovisioning/actionMicrosoft.Compute/availabilitySets/readMicrosoft.Compute/availabilitySets/writeMicrosoft.Compute/availabilitySets/vmSizes/readMicrosoft.Compute/disks/readMicrosoft.Compute/disks/writeMicrosoft.Compute/disks/deleteMicrosoft.Compute/galleries/readMicrosoft.Compute/galleries/images/readMicrosoft.Compute/galleries/images/versions/readMicrosoft.Compute/images/readMicrosoft.Compute/locations/usages/readMicrosoft.Compute/locations/vmSizes/readMicrosoft.Compute/operations/readMicrosoft.Compute/skus/readMicrosoft.Compute/virtualMachines/readMicrosoft.Compute/virtualMachines/writeMicrosoft.Compute/virtualMachines/deleteMicrosoft.Compute/virtualMachines/start/actionMicrosoft.Compute/virtualMachines/powerOff/actionMicrosoft.Compute/virtualMachines/restart/actionMicrosoft.Compute/virtualMachines/deallocate/actionMicrosoft.Compute/virtualMachines/runCommand/actionMicrosoft.Compute/virtualMachines/extensions/readMicrosoft.Compute/virtualMachines/extensions/writeMicrosoft.Compute/virtualMachines/extensions/deleteMicrosoft.Compute/virtualMachines/runCommands/readMicrosoft.Compute/virtualMachines/runCommands/writeMicrosoft.Compute/virtualMachines/vmSizes/readMicrosoft.Network/networkSecurityGroups/readMicrosoft.Network/networkInterfaces/writeMicrosoft.Network/networkInterfaces/readMicrosoft.Network/networkInterfaces/join/actionMicrosoft.Network/networkInterfaces/deleteMicrosoft.Network/virtualNetworks/subnets/readMicrosoft.Network/virtualNetworks/subnets/join/actionMicrosoft.Network/virtualNetworks/usages/readMicrosoft.Network/virtualNetworks/readMicrosoft.Network/networkSecurityGroups/readMicrosoft.Marketplace/offerTypes/publishers/offers/plans/agreements/readMicrosoft.KeyVault/vaults/deploy/actionMicrosoft.Storage/storageAccounts/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.DesktopVirtualization/scalingPlans/readMicrosoft.DesktopVirtualization/scalingPlans/write
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign to the Azure Virtual Desktop service principal at every subscription containing pooled host pools with session host configuration that use dynamic autoscale. Microsoft states that assignment below subscription scope prevents autoscale from working properly. The role uses control-plane Actions and has no DataActions.
Common use cases (1)
- Enable dynamic autoscale to create, delete, update, start, and stop session-host VMs in a pooled host pool with session host configuration.
Prerequisites (3)
- Use a dynamic scaling plan with a pooled host pool that has session host configuration, and identify the Azure Virtual Desktop service principal.
- Also assign Desktop Virtualization Power On Off Contributor to the service principal at the same subscription scope.
- The administrator assigning the service roles needs Microsoft.Authorization/roleAssignments/write on each affected subscription.
Best practices (3)
- Treat the role as preview, test the workflow before production use, and monitor Microsoft documentation for definition changes.
- Assign only to the Azure Virtual Desktop service principal and keep unrelated compute, network, and storage resources outside its inherited scope.
- Review service activity and scaling-plan changes regularly, and remove the assignment when dynamic autoscale is retired.
Security considerations (3)
- Dynamic autoscale can create, update, delete, start, and stop session-host VMs throughout the assigned subscription.
- Deleting or stopping session hosts can interrupt users, while creating hosts can change cost and network exposure.
- No DataActions are present, but subscription-wide VM lifecycle authority makes this a broad privileged service role.
Assignment guidance
Assign this preview role and Desktop Virtualization Power On Off Contributor to the Azure Virtual Desktop service principal at each subscription used by dynamic autoscale. Do not assign either role below subscription scope or to ordinary administrators, and reassess the preview definition before expansion.
Related roles (1)
- Desktop Virtualization Power On Off Contributor: Microsoft requires both service-principal roles at subscription scope for dynamic autoscale.
Editorial sources (6)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Create and assign an autoscale scaling plan for Azure Virtual Desktop →
Supports: Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.