Azure DevOps built-in role

DevCenter Dev Box User

Creates and manages the assignee's own Microsoft Dev Box resources. Project and pool discovery use control-plane Actions, while create, start, stop, connect, schedule-management, and delete operations on the user's dev boxes are DataActions. Microsoft Dev Box is in maintenance mode with no additional features planned; it remains supported for existing usage, while Microsoft recommends Windows 365 as the path forward for virtualized developer environments.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 45d50f46-0b78-4001-a660-4198cbe8cd05

Control-plane actions (4)

Data-plane actions (11)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the Microsoft Dev Box project. The assignment grants access to the project and its available pools; a role assigned on the dev center itself is not inherited by projects, pools, definitions, or dev boxes.

Common use cases (2)

Prerequisites (2)

Best practices (4)

Security considerations (3)

Assignment guidance

For current supported Dev Box usage, assign DevCenter Dev Box User to the developer group on the specific project. Use separate projects to isolate teams, reserve DevCenter Project Admin for managers who configure pools or administer dev boxes across users, and include the Windows 365 path forward in platform planning.

Related roles (2)

Common questions

When should I assign the DevCenter Dev Box User Azure role?

Assign DevCenter Dev Box User when you need to: For an existing Dev Box project, let developers create dev boxes from approved pools and manage the dev boxes they create through the developer portal.; and Allow a project member to connect, start, stop, restart, delay scheduled shutdown, or delete the member's own dev boxes.. Practical scope: Assign at the Microsoft Dev Box project. The assignment grants access to the project and its available pools; a role assigned on the dev center itself is not inherited by projects, pools, definitions, or dev boxes.

What permissions does the DevCenter Dev Box User Azure role grant?

The role definition grants 15 combined control-plane and data-plane actions. Representative operations include: Microsoft.DevCenter/projects/read; Microsoft.DevCenter/projects/*/read; Microsoft.Authorization/*/read; Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.DevCenter/projects/users/devboxes/userStop/action; and Microsoft.DevCenter/projects/users/devboxes/userStart/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the DevCenter Dev Box User Azure role?

Key considerations when assigning DevCenter Dev Box User: The role can obtain remote connection information and gives the user full lifecycle control over dev boxes the user creates.; A project assignment exposes every pool available in that project and allows creation from any pool the project presents.; and The role does not grant platform management of dev centers, definitions, network connections, or other users' dev boxes.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →