Azure Compute built-in role

Desktop Virtualization Virtual Machine Contributor

Allows the Azure Virtual Desktop resource provider to create, update, delete, start, and stop session-host virtual machines for dynamic autoscale. Microsoft marks the role as preview and subject to change.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a959dbd1-f747-45e3-8ba6-dd80f235f97c

Control-plane actions (59)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign to the Azure Virtual Desktop service principal at every subscription containing pooled host pools with session host configuration that use dynamic autoscale. Microsoft states that assignment below subscription scope prevents autoscale from working properly. The role uses control-plane Actions and has no DataActions.

Common use cases (1)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign this preview role and Desktop Virtualization Power On Off Contributor to the Azure Virtual Desktop service principal at each subscription used by dynamic autoscale. Do not assign either role below subscription scope or to ordinary administrators, and reassess the preview definition before expansion.

Related roles (1)

Common questions

When should I assign the Desktop Virtualization Virtual Machine Contributor Azure role?

Assign Desktop Virtualization Virtual Machine Contributor when you need to: Enable dynamic autoscale to create, delete, update, start, and stop session-host VMs in a pooled host pool with session host configuration.. Practical scope: Assign to the Azure Virtual Desktop service principal at every subscription containing pooled host pools with session host configuration that use dynamic autoscale. Microsoft states that assignment below subscription scope prevents autoscale from working properly. The role uses control-plane Actions and has no DataActions.

What permissions does the Desktop Virtualization Virtual Machine Contributor Azure role grant?

The role definition grants 59 combined control-plane and data-plane actions. Representative operations include: Microsoft.DesktopVirtualization/hostpools/read; Microsoft.DesktopVirtualization/hostpools/write; Microsoft.DesktopVirtualization/hostpools/retrieveRegistrationToken/action; Microsoft.DesktopVirtualization/hostpools/sessionhosts/read; Microsoft.DesktopVirtualization/hostpools/sessionhosts/write; and Microsoft.DesktopVirtualization/hostpools/sessionhosts/delete. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Desktop Virtualization Virtual Machine Contributor Azure role?

Key considerations when assigning Desktop Virtualization Virtual Machine Contributor: Dynamic autoscale can create, update, delete, start, and stop session-host VMs throughout the assigned subscription.; Deleting or stopping session hosts can interrupt users, while creating hosts can change cost and network exposure.; and No DataActions are present, but subscription-wide VM lifecycle authority makes this a broad privileged service role.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →