Azure Compute built-in role

Desktop Virtualization Workspace Contributor

Manages all aspects of Azure Virtual Desktop workspaces. It can read application groups to associate them with a workspace, but Microsoft documents Application Group Reader as additionally required to obtain application information from a related group.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 21efdde3-836f-432b-bf3d-3e8e734d4b2b

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the individual workspace for one presentation boundary, or at a resource group only when every inherited workspace is in scope. Permissions are control-plane Actions and there are no DataActions or end-user application-use rights.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Workspace Contributor on the workspace to the workspace administrator. Add Application Group Reader only for the documented related-application visibility and keep application publishing and user assignment with their separate roles.

Related roles (2)

Common questions

When should I assign the Desktop Virtualization Workspace Contributor Azure role?

Assign Desktop Virtualization Workspace Contributor when you need to: Create, update, or delete a workspace and manage its application-group associations.; and Delegate workspace presentation and organization without host-pool or application-group modification.. Practical scope: Assign at the individual workspace for one presentation boundary, or at a resource group only when every inherited workspace is in scope. Permissions are control-plane Actions and there are no DataActions or end-user application-use rights.

What permissions does the Desktop Virtualization Workspace Contributor Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.DesktopVirtualization/workspaces/*; Microsoft.DesktopVirtualization/applicationgroups/read; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/deployments/*; Microsoft.Authorization/*/read; and Microsoft.Insights/alertRules/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Desktop Virtualization Workspace Contributor Azure role?

Key considerations when assigning Desktop Virtualization Workspace Contributor: Workspace changes can alter which application groups are presented to users and can disrupt resource discovery.; The role cannot modify application-group contents or grant users the ability to launch applications.; and A parent-scope assignment provides inherited management of every workspace below it.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →