Azure DevOps built-in role

DevTest Labs User

Lets a DevTest Labs member view lab resources and policies and create or modify the member's own VMs and environments within lab policy limits. The role uses control-plane Actions only and has no DataActions; users automatically receive Owner permissions on VMs they create or claim.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 76283e04-6283-4c54-8f91-bcf1374a3c64

Control-plane actions (32)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (1)

Assignable scopes (1)

Practical scope

Assign on the individual DevTest Labs lab. Resource-group or subscription assignments are inherited more broadly and can make the role's VM, network, deployment, and storage-key Actions effective against additional resources in scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (4)

Assignment guidance

Assign DevTest Labs User directly on the approved lab to developer or tester groups. Configure restrictive lab policies first, keep secrets in Key Vault, and avoid resource-group or subscription scope unless every inherited resource is intentionally included.

Related roles (2)

Editorial sources (9)

Official Microsoft Learn documentation →