Azure Compute built-in role

Desktop Virtualization Workspace Reader

Views Azure Virtual Desktop workspaces and their application-group relationships without changing them. It is a control-plane reader and does not grant permission to launch applications.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 0fa44ee9-7a7d-466b-9bb2-2bf446b1204d

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the workspace for one view boundary. A resource-group or parent assignment is inherited by all workspaces below it. The role contains read-only control-plane Actions and no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Workspace Reader on the workspace for view-only support or audit access. Add Desktop Virtualization User on an application group only for approved launch access, and Contributor only for workspace changes.

Related roles (1)

Common questions

When should I assign the Desktop Virtualization Workspace Reader Azure role?

Assign Desktop Virtualization Workspace Reader when you need to: Inspect workspace configuration and associated application groups for support or audit work.; and Give a workspace owner visibility without allowing association or configuration changes.. Practical scope: Assign at the workspace for one view boundary. A resource-group or parent assignment is inherited by all workspaces below it. The role contains read-only control-plane Actions and no DataActions.

What permissions does the Desktop Virtualization Workspace Reader Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.DesktopVirtualization/workspaces/read; Microsoft.DesktopVirtualization/applicationgroups/read; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.Resources/deployments/read; Microsoft.Authorization/*/read; and Microsoft.Insights/alertRules/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Desktop Virtualization Workspace Reader Azure role?

Key considerations when assigning Desktop Virtualization Workspace Reader: Read access exposes workspace organization, application-group relationships, deployment information, alerts, and role assignments.; The role cannot change the workspace and has no DataActions.; and It does not grant end-user application access or host-pool administration.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →