Azure Compute built-in role
Desktop Virtualization Workspace Contributor
Manages all aspects of Azure Virtual Desktop workspaces. It can read application groups to associate them with a workspace, but Microsoft documents Application Group Reader as additionally required to obtain application information from a related group.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 21efdde3-836f-432b-bf3d-3e8e734d4b2b
Control-plane actions (7)
Microsoft.DesktopVirtualization/workspaces/*Microsoft.DesktopVirtualization/applicationgroups/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/*Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the individual workspace for one presentation boundary, or at a resource group only when every inherited workspace is in scope. Permissions are control-plane Actions and there are no DataActions or end-user application-use rights.
Common use cases (2)
- Create, update, or delete a workspace and manage its application-group associations.
- Delegate workspace presentation and organization without host-pool or application-group modification.
Prerequisites (2)
- The related application groups must already exist when they are associated with the workspace.
- Grant Desktop Virtualization Application Group Reader when the administrator needs the additional application information Microsoft documents for related groups.
Best practices (3)
- Assign on the workspace when the administrator owns only that workspace.
- Keep workspace administration separate from application publishing and end-user assignment.
- Use Workspace Reader for audit or support tasks that require no changes.
Security considerations (3)
- Workspace changes can alter which application groups are presented to users and can disrupt resource discovery.
- The role cannot modify application-group contents or grant users the ability to launch applications.
- A parent-scope assignment provides inherited management of every workspace below it.
Assignment guidance
Assign Desktop Virtualization Workspace Contributor on the workspace to the workspace administrator. Add Application Group Reader only for the documented related-application visibility and keep application publishing and user assignment with their separate roles.
Related roles (2)
- Desktop Virtualization Workspace Reader: Read-only counterpart for workspace inspection.
- Desktop Virtualization Application Group Reader: Microsoft documents this additional role for information about applications in a related application group.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.