Azure DevOps built-in role
DevCenter Project Admin
Administers Microsoft Dev Box and Azure Deployment Environments resources within a project without creating or deleting the project itself. It combines project control-plane Actions with administrative DataActions over user dev boxes and deployment environments. For Microsoft Dev Box, this is existing-usage administration: no additional Dev Box features are planned, and Microsoft recommends Windows 365 as the path forward for virtualized developer environments.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 331c37c6-af14-46d9-b9f4-e1909e1b95a0
Control-plane actions (4)
Microsoft.DevCenter/projects/*Microsoft.Authorization/*/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (27)
Microsoft.DevCenter/projects/users/devboxes/adminStart/actionMicrosoft.DevCenter/projects/users/devboxes/adminStop/actionMicrosoft.DevCenter/projects/users/devboxes/adminRead/actionMicrosoft.DevCenter/projects/users/devboxes/adminWrite/actionMicrosoft.DevCenter/projects/users/devboxes/adminDelete/actionMicrosoft.DevCenter/projects/users/devboxes/adminAlign/actionMicrosoft.DevCenter/projects/users/devboxes/adminActionRead/actionMicrosoft.DevCenter/projects/users/devboxes/adminActionManage/actionMicrosoft.DevCenter/projects/users/devboxes/userStop/actionMicrosoft.DevCenter/projects/users/devboxes/userStart/actionMicrosoft.DevCenter/projects/users/devboxes/userGetRemoteConnection/actionMicrosoft.DevCenter/projects/users/devboxes/userRead/actionMicrosoft.DevCenter/projects/users/devboxes/userWrite/actionMicrosoft.DevCenter/projects/users/devboxes/userDelete/actionMicrosoft.DevCenter/projects/users/devboxes/userActionRead/actionMicrosoft.DevCenter/projects/users/devboxes/userActionManage/actionMicrosoft.DevCenter/projects/users/devboxes/userCustomize/actionMicrosoft.DevCenter/projects/users/environments/adminRead/actionMicrosoft.DevCenter/projects/users/environments/userWrite/actionMicrosoft.DevCenter/projects/users/environments/adminWrite/actionMicrosoft.DevCenter/projects/users/environments/userDelete/actionMicrosoft.DevCenter/projects/users/environments/adminDelete/actionMicrosoft.DevCenter/projects/users/environments/adminAction/actionMicrosoft.DevCenter/projects/users/environments/adminActionRead/actionMicrosoft.DevCenter/projects/users/environments/adminActionManage/actionMicrosoft.DevCenter/projects/users/environments/adminOutputsRead/actionMicrosoft.DevCenter/projects/pools/align/action
Excluded actions (2)
Microsoft.DevCenter/projects/writeMicrosoft.DevCenter/projects/delete
Assignable scopes (1)
/
Practical scope
Assign at a project for all project pools, dev boxes, environment types, and environments. Deployment Environments also supports assignment on a specific project environment type for a narrower admin boundary; permissions assigned at a dev center are not inherited by its projects.
Common use cases (2)
- For an existing Dev Box project, let a dev manager create and manage pools and start, stop, or delete dev boxes across users in that project.
- Let a dev manager manage all deployment environments and environment types, including project catalogs and environment expiry settings, for one project.
Prerequisites (2)
- A dev center and project must already exist, and project-level catalogs must be enabled before the admin can manage a project catalog.
- The platform owner must decide whether administration covers the whole project or only one Deployment Environments environment type.
Best practices (4)
- Assign at project scope only to a team lead responsible for every user dev box and environment in that project.
- Use environment-type scope when a Deployment Environments administrator should not manage other types in the same project.
- Keep platform-level dev center, network connection, gallery, and access-delegation duties with DevCenter Owner.
- For Dev Box, use this role for current supported project administration while planning the recommended path forward in Windows 365.
Security considerations (3)
- Administrative DataActions can start, stop, update, or delete other users' dev boxes and can update, redeploy, or delete environments across the assigned project.
- The role can manage project pools and catalogs but cannot create or delete the project itself.
- Repository permissions for GitHub or Azure Repos catalogs remain separate and can expand the administrator's effective ability to change environment or customization content.
Assignment guidance
For current supported usage, assign DevCenter Project Admin to the dev manager on the project, or on a specific Deployment Environments environment type when that narrower boundary is sufficient. Use Dev Box User and Deployment Environments User for self-service users, keep dev-center ownership separate, and include the Windows 365 path forward in Dev Box planning.
Related roles (3)
- DevCenter Owner: Manages the dev center and can delegate Project Admin, while Project Admin remains bounded to project resources.
- DevCenter Dev Box User: Self-service role for developers to manage only the dev boxes they create.
- Deployment Environments User: Self-service role for developers to manage only their own deployment environments.
Editorial sources (8)
- Azure built-in roles for DevOps - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Plan Azure role-based access control - Microsoft Dev Box | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Plan Azure Role-Based Access Control - Azure Deployment Environments | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Microsoft Dev Box for Cloud-Based Development - Microsoft Dev Box | Microsoft Learn →
Supports: Description, Common use cases, Best practices, Assignment guidance. Retrieved 2026-07-17.