Azure DevOps built-in role
Lab Assistant
Views an existing Azure Lab Services lab, sends lab-registration invitations to users already listed in the lab, and can start, stop, reimage, or redeploy its lab virtual machines. The role has control-plane Actions only and no DataActions. Azure Lab Services retires on June 28, 2027, so this is transition and cleanup access rather than a new long-term assignment.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: ce40b423-cede-4313-a93f-9b28290b72e1
Control-plane actions (17)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.LabServices/labPlans/images/readMicrosoft.LabServices/labPlans/readMicrosoft.LabServices/labs/readMicrosoft.LabServices/labs/schedules/readMicrosoft.LabServices/labs/users/readMicrosoft.LabServices/labs/users/invite/actionMicrosoft.LabServices/labs/virtualMachines/readMicrosoft.LabServices/labs/virtualMachines/start/actionMicrosoft.LabServices/labs/virtualMachines/stop/actionMicrosoft.LabServices/labs/virtualMachines/reimage/actionMicrosoft.LabServices/labs/virtualMachines/redeploy/actionMicrosoft.LabServices/locations/usages/readMicrosoft.LabServices/skus/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Existing assignments are documented at an individual lab or at a resource group for every contained lab. Labs and lab plans are sibling resources, so a role on a lab plan is not inherited by its associated labs; a resource-group assignment is inherited by both.
Common use cases (2)
- Keep an existing teaching assistant able to operate lab VMs while courses are moved to a replacement service before June 28, 2027.
- Inventory and remove Lab Assistant assignments as labs are decommissioned during the retirement plan.
Prerequisites (2)
- The lab must be an existing Azure Lab Services resource still required during the approved transition window.
- A retirement owner must identify the replacement workflow, migration date, and the assignment scope that will be removed after cutover.
Best practices (3)
- Do not create a new long-lived Lab Assistant access model; transition workflows to a Microsoft or partner replacement before retirement.
- For a temporary existing need, retain access on one lab instead of a resource group containing unrelated labs.
- Delete idle Lab Services resources and remove their role assignments after migration validation.
Security considerations (5)
- Reimage deletes and recreates the lab VM from the original template; Microsoft documents that all data on the OS disk and temporary disk is lost.
- Redeploy moves the lab VM to a different compute node. OS-disk data remains available, while temporary-disk data is lost.
- The role can send registration invitations to users already listed in the lab as well as operate lab VMs, so invitation sends and destructive recovery actions both require review.
- A resource-group assignment permits VM operations across every inherited lab, while a lab-plan assignment does not flow to sibling labs.
- Retaining the role after a lab is migrated leaves unnecessary authorization on a service approaching retirement.
Assignment guidance
Do not establish a new permanent assignment. If an existing lab still needs operational support during migration, retain or narrowly scope Lab Assistant on that lab, record its removal date, and remove the assignment at its originating scope after cutover.
Related roles (2)
- Lab Services Reader: Provides visibility without the Assistant VM start, stop, reimage, or redeploy operations.
- Lab Contributor: Adds management of the existing lab rather than limiting the principal to viewing and VM operations.
Editorial sources (10)
- Azure built-in roles for DevOps - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations, Related roles. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Remove Azure role assignments →
Supports: Common use cases, Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure role-based access control - Azure Lab Services | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure Lab Services retirement guide - Azure Lab Services | Microsoft Learn →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Migrate lab account role assignments to lab plans in Azure Lab Services →
Supports: Practical scope, Best practices. Retrieved 2026-07-17.
- Troubleshoot a lab VM with redeploy or reimage - Azure Lab Services | Microsoft Learn →
Supports: Security considerations. Retrieved 2026-07-17.
- Manage lab users in Azure Lab Services - Azure Lab Services | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.