Azure DevOps built-in role
DevCenter Owner
Manages Microsoft.DevCenter resources and has conditional Azure role-assignment authority limited to DevCenter Project Admin and DevCenter Dev Box User role definitions. The published role contains control-plane Actions only and no DataActions. For Microsoft Dev Box, this is existing-usage administration: no additional Dev Box features are planned, and Microsoft recommends Windows 365 as the path forward for virtualized developer environments.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 4c6569b6-f23e-4295-9b90-bd4cc4ff3292
Control-plane actions (6)
Microsoft.DevCenter/*Microsoft.Authorization/*/readMicrosoft.Authorization/roleAssignments/writeMicrosoft.Authorization/roleAssignments/deleteMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Conditions (1)
Condition version: 2.0
((!(ActionMatches{'Microsoft.Authorization/roleAssignments/write'})) OR (@Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{331c37c6-af14-46d9-b9f4-e1909e1b95a0, 45d50f46-0b78-4001-a660-4198cbe8cd05})) AND ((!(ActionMatches{'Microsoft.Authorization/roleAssignments/delete'})) OR (@Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{331c37c6-af14-46d9-b9f4-e1909e1b95a0, 45d50f46-0b78-4001-a660-4198cbe8cd05}))
Assignable scopes (1)
/
Practical scope
At resource-group scope, the role can create and manage DevCenter resources in that group. At dev-center scope, it manages that center and its projects, pools, definitions, catalogs, connections, and galleries but cannot create another dev center. Dev-center assignments are not inherited as generic permissions on separate project or dev-box resources.
Common use cases (2)
- Delegate administration of one dev center without granting Contributor or Owner over unrelated resource types in its resource group.
- Administer existing Dev Box or Deployment Environments projects and delegate approved project-admin and Dev Box user access.
Prerequisites (2)
- Identify whether the assignee must create dev centers at resource-group scope or only administer one existing dev center.
- Plan project boundaries and the DevCenter Project Admin and DevCenter Dev Box User assignments the owner is allowed to delegate.
Best practices (4)
- Use dev-center scope when the platform engineer does not need to create new dev centers in the resource group.
- Keep unrelated Azure resources out of the resource group and review the owner's conditional role assignments regularly.
- Assign project administrators and users explicitly at project or environment-type scope because dev-center permissions are not inherited by those resources.
- For Dev Box, use this role for current supported administration while planning the recommended transition path to Windows 365 rather than relying on future Dev Box features.
Security considerations (3)
- The role can create, update, and delete a broad set of Microsoft.DevCenter resources and alter catalogs, connections, galleries, projects, definitions, and pools.
- Its role-assignment write and delete Actions are constrained to the DevCenter Project Admin and DevCenter Dev Box User role-definition IDs rather than arbitrary Azure roles.
- A resource-group assignment reaches every Microsoft.DevCenter resource in the group and also permits creation of new dev centers there.
Assignment guidance
Assign DevCenter Owner at an existing dev center when the platform engineer manages only that center, or at a dedicated resource group only when the engineer must create or manage all DevCenter resources there. Keep project user and admin assignments explicit, rely on the built-in condition rather than describing this role as general access delegation, and include the Windows 365 path forward in Dev Box planning.
Related roles (3)
- DevCenter Project Admin: The DevCenter Owner condition permits delegation of this project-scoped administration role.
- DevCenter Dev Box User: The DevCenter Owner condition permits delegation of this project-scoped developer role.
- Contributor: Microsoft documents Contributor as broader resource-group control that includes non-DevCenter resources but cannot assign Azure roles.
Editorial sources (8)
- Azure built-in roles for DevOps - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Plan Azure role-based access control - Microsoft Dev Box | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Plan Azure Role-Based Access Control - Azure Deployment Environments | Microsoft Learn →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Microsoft Dev Box for Cloud-Based Development - Microsoft Dev Box | Microsoft Learn →
Supports: Description, Common use cases, Best practices, Assignment guidance. Retrieved 2026-07-17.