Azure DevOps built-in role

DevOps Infrastructure Contributor

Creates, updates, reads, deletes, and performs service operations on Managed DevOps Pools. The published definition contains Azure control-plane Actions only and no DataActions; Azure DevOps organization, project, agent-pool, pipeline, and repository permissions remain separate.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 76153a9e-0edb-49bc-8e01-93c47e6b5180

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the dedicated resource group containing Managed DevOps Pools when the resource providers are already registered, or at a broader subscription scope only when the principal must manage pools across that subscription or perform provider registration. Parent assignments are inherited.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign DevOps Infrastructure Contributor to the human or service-connection identity at the dedicated pool resource group. Add the documented Azure DevOps organization, project, and agent-pool permissions separately, and grant Key Vault or other workload access only to the pool identity that needs it.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →