Azure DevOps built-in role
Lab Contributor
Manages an existing Azure Lab Services lab, including its settings, schedules, users, publishing, and VM operations, but Microsoft documents that it cannot create a new lab. The role has control-plane Actions and one lab-plan create-lab DataAction; its supported lab-scoped assignment does not flow to the sibling lab plan. Azure Lab Services retires on June 28, 2027.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 5daaa2af-1fe8-407c-9122-bba179798270
Control-plane actions (27)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.LabServices/labPlans/images/readMicrosoft.LabServices/labPlans/readMicrosoft.LabServices/labPlans/saveImage/actionMicrosoft.LabServices/labs/readMicrosoft.LabServices/labs/writeMicrosoft.LabServices/labs/deleteMicrosoft.LabServices/labs/publish/actionMicrosoft.LabServices/labs/syncGroup/actionMicrosoft.LabServices/labs/schedules/readMicrosoft.LabServices/labs/schedules/writeMicrosoft.LabServices/labs/schedules/deleteMicrosoft.LabServices/labs/users/readMicrosoft.LabServices/labs/users/writeMicrosoft.LabServices/labs/users/deleteMicrosoft.LabServices/labs/users/invite/actionMicrosoft.LabServices/labs/virtualMachines/readMicrosoft.LabServices/labs/virtualMachines/start/actionMicrosoft.LabServices/labs/virtualMachines/stop/actionMicrosoft.LabServices/labs/virtualMachines/reimage/actionMicrosoft.LabServices/labs/virtualMachines/redeploy/actionMicrosoft.LabServices/labs/virtualMachines/resetPassword/actionMicrosoft.LabServices/locations/usages/readMicrosoft.LabServices/skus/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (1)
Microsoft.LabServices/labPlans/createLab/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The supported assignment is on the individual lab. Labs and lab plans are sibling resources, so the lab-scoped role does not grant the create-lab DataAction on the associated lab plan and does not authorize other labs.
Common use cases (2)
- Keep an existing co-manager able to maintain one lab while its schedules, users, images, and course workflow are migrated.
- Inventory and remove Lab Contributor assignments as each lab is decommissioned before service retirement.
Prerequisites (2)
- An existing lab must still require co-management during a documented migration window.
- The retirement plan must identify the replacement lab workflow, data or image migration tasks, cutover owner, and role-removal date.
Best practices (3)
- Do not use Lab Contributor to build a new long-term lab platform; move to a recommended Microsoft or partner solution before June 28, 2027.
- Keep the temporary assignment on the individual lab because lab-plan and lab roles do not inherit across their sibling relationship.
- Remove the assignment and delete unused Lab Services resources after migration and retention requirements are satisfied.
Security considerations (3)
- The role can change or delete the assigned lab and can publish it, manage users and schedules, reset VM passwords, and reimage or redeploy VMs.
- The create-lab DataAction does not make the documented lab-scoped role a lab creator because the associated lab plan is a sibling resource outside that scope.
- Retaining broad lab management during or after cutover can allow destructive changes to a service being decommissioned.
Assignment guidance
Do not make a new permanent assignment. For an existing lab that still needs a co-manager during migration, keep Lab Contributor directly on that lab, document the cutover dependency, and remove it at the lab scope when the replacement workflow is accepted.
Related roles (2)
- Lab Assistant: Narrower transition role for viewing the lab and operating VMs without changing or deleting the lab.
- Lab Creator: The documented lab-plan or resource-group role for creating and controlling the assignee's own labs.
Editorial sources (8)
- Azure built-in roles for DevOps - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Remove Azure role assignments →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure role-based access control - Azure Lab Services | Microsoft Learn →
Supports: Description, Practical scope, Common use cases, Prerequisites, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure Lab Services retirement guide - Azure Lab Services | Microsoft Learn →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Migrate lab account role assignments to lab plans in Azure Lab Services →
Supports: Practical scope, Best practices. Retrieved 2026-07-17.