Azure Compute built-in role

Desktop Virtualization Workspace Reader

Views Azure Virtual Desktop workspaces and their application-group relationships without changing them. It is a control-plane reader and does not grant permission to launch applications.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 0fa44ee9-7a7d-466b-9bb2-2bf446b1204d

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the workspace for one view boundary. A resource-group or parent assignment is inherited by all workspaces below it. The role contains read-only control-plane Actions and no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Desktop Virtualization Workspace Reader on the workspace for view-only support or audit access. Add Desktop Virtualization User on an application group only for approved launch access, and Contributor only for workspace changes.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →