Azure Compute built-in role
Desktop Virtualization Workspace Reader
Views Azure Virtual Desktop workspaces and their application-group relationships without changing them. It is a control-plane reader and does not grant permission to launch applications.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 0fa44ee9-7a7d-466b-9bb2-2bf446b1204d
Control-plane actions (7)
Microsoft.DesktopVirtualization/workspaces/readMicrosoft.DesktopVirtualization/applicationgroups/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Resources/deployments/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the workspace for one view boundary. A resource-group or parent assignment is inherited by all workspaces below it. The role contains read-only control-plane Actions and no DataActions.
Common use cases (2)
- Inspect workspace configuration and associated application groups for support or audit work.
- Give a workspace owner visibility without allowing association or configuration changes.
Prerequisites (2)
- Identify the workspace or resource boundary the principal needs to inspect.
- Grant Desktop Virtualization User separately if the same person needs to launch a desktop or RemoteApp.
Best practices (3)
- Assign at the workspace rather than its resource group when broader visibility is unnecessary.
- Use this role instead of Workspace Contributor for view-only duties.
- Review inherited assignments that expose multiple workspaces and their application-group relationships.
Security considerations (3)
- Read access exposes workspace organization, application-group relationships, deployment information, alerts, and role assignments.
- The role cannot change the workspace and has no DataActions.
- It does not grant end-user application access or host-pool administration.
Assignment guidance
Assign Desktop Virtualization Workspace Reader on the workspace for view-only support or audit access. Add Desktop Virtualization User on an application group only for approved launch access, and Contributor only for workspace changes.
Related roles (1)
- Desktop Virtualization Workspace Contributor: Adds workspace and application-group association management.
Editorial sources (5)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Built-in Azure RBAC roles for Azure Virtual Desktop →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.