Azure Compute built-in role

Desktop Virtualization Workspace Contributor

Manages all aspects of Azure Virtual Desktop workspaces. It can read application groups to associate them with a workspace, but Microsoft documents Application Group Reader as additionally required to obtain application information from a related group.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 21efdde3-836f-432b-bf3d-3e8e734d4b2b

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the individual workspace for one presentation boundary, or at a resource group only when every inherited workspace is in scope. Permissions are control-plane Actions and there are no DataActions or end-user application-use rights.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Workspace Contributor on the workspace to the workspace administrator. Add Application Group Reader only for the documented related-application visibility and keep application publishing and user assignment with their separate roles.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →