Azure DevOps built-in role

Lab Contributor

Manages an existing Azure Lab Services lab, including its settings, schedules, users, publishing, and VM operations, but Microsoft documents that it cannot create a new lab. The role has control-plane Actions and one lab-plan create-lab DataAction; its supported lab-scoped assignment does not flow to the sibling lab plan. Azure Lab Services retires on June 28, 2027.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 5daaa2af-1fe8-407c-9122-bba179798270

Control-plane actions (27)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The supported assignment is on the individual lab. Labs and lab plans are sibling resources, so the lab-scoped role does not grant the create-lab DataAction on the associated lab plan and does not authorize other labs.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not make a new permanent assignment. For an existing lab that still needs a co-manager during migration, keep Lab Contributor directly on that lab, document the cutover dependency, and remove it at the lab scope when the replacement workflow is accepted.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →