Azure DevOps built-in role

Lab Contributor

Manages an existing Azure Lab Services lab, including its settings, schedules, users, publishing, and VM operations, but Microsoft documents that it cannot create a new lab. The role has control-plane Actions and one lab-plan create-lab DataAction; its supported lab-scoped assignment does not flow to the sibling lab plan. Azure Lab Services retires on June 28, 2027.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5daaa2af-1fe8-407c-9122-bba179798270

Control-plane actions (27)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The supported assignment is on the individual lab. Labs and lab plans are sibling resources, so the lab-scoped role does not grant the create-lab DataAction on the associated lab plan and does not authorize other labs.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not make a new permanent assignment. For an existing lab that still needs a co-manager during migration, keep Lab Contributor directly on that lab, document the cutover dependency, and remove it at the lab scope when the replacement workflow is accepted.

Related roles (2)

Common questions

When should I assign the Lab Contributor Azure role?

Assign Lab Contributor when you need to: Keep an existing co-manager able to maintain one lab while its schedules, users, images, and course workflow are migrated.; and Inventory and remove Lab Contributor assignments as each lab is decommissioned before service retirement.. Practical scope: The supported assignment is on the individual lab. Labs and lab plans are sibling resources, so the lab-scoped role does not grant the create-lab DataAction on the associated lab plan and does not authorize other labs.

What permissions does the Lab Contributor Azure role grant?

The role definition grants 28 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; Microsoft.LabServices/labPlans/images/read; Microsoft.LabServices/labPlans/read; Microsoft.LabServices/labPlans/saveImage/action; and Microsoft.LabServices/labs/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Lab Contributor Azure role?

Key considerations when assigning Lab Contributor: The role can change or delete the assigned lab and can publish it, manage users and schedules, reset VM passwords, and reimage or redeploy VMs.; The create-lab DataAction does not make the documented lab-scoped role a lab creator because the associated lab plan is a sibling resource outside that scope.; and Retaining broad lab management during or after cutover can allow destructive changes to a service being decommissioned.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →