Azure DevOps built-in role

Lab Assistant

Views an existing Azure Lab Services lab, sends lab-registration invitations to users already listed in the lab, and can start, stop, reimage, or redeploy its lab virtual machines. The role has control-plane Actions only and no DataActions. Azure Lab Services retires on June 28, 2027, so this is transition and cleanup access rather than a new long-term assignment.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ce40b423-cede-4313-a93f-9b28290b72e1

Control-plane actions (17)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Existing assignments are documented at an individual lab or at a resource group for every contained lab. Labs and lab plans are sibling resources, so a role on a lab plan is not inherited by its associated labs; a resource-group assignment is inherited by both.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (5)

Assignment guidance

Do not establish a new permanent assignment. If an existing lab still needs operational support during migration, retain or narrowly scope Lab Assistant on that lab, record its removal date, and remove the assignment at its originating scope after cutover.

Related roles (2)

Editorial sources (10)

Official Microsoft Learn documentation →