Azure DevOps built-in role

Lab Creator

Creates Azure Lab Services labs and gives the creator full control over labs the creator makes. The definition contains legacy lab-account control-plane Actions and the current lab-plan create-lab DataAction. Azure Lab Services retires on June 28, 2027, so the role should support only an approved interim migration path.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b97fb8bc-a8b2-4522-a38b-dd33c7e65ead

Control-plane actions (18)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Existing guidance supports assignment on one lab plan or on a resource group containing lab plans. Lab plans and labs are sibling resources, so a role on a lab plan is not inherited by a created lab; the service separately grants the creator control of that lab. Resource-group assignments are inherited by both plans and labs.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not create a new permanent Lab Creator grant. Where an approved interim lab is unavoidable, retain or assign it on the one existing lab plan, record the migration and removal dates, and remove the assignment after the replacement workflow and lab cleanup are complete.

Related roles (2)

Common questions

When should I assign the Lab Creator Azure role?

Assign Lab Creator when you need to: Maintain an existing educator's ability to create a final interim lab while courses transition to a replacement platform before retirement.; and Inventory Lab Creator assignments and map each creator and lab plan to the retirement and resource-cleanup plan.. Practical scope: Existing guidance supports assignment on one lab plan or on a resource group containing lab plans. Lab plans and labs are sibling resources, so a role on a lab plan is not inherited by a created lab; the service separately grants the creator control of that lab. Resource-group assignments are inherited by both plans and labs.

What permissions does the Lab Creator Azure role grant?

The role definition grants 19 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.LabServices/labAccounts/*/read; Microsoft.LabServices/labAccounts/createLab/action; Microsoft.LabServices/labAccounts/getPricingAndAvailability/action; Microsoft.LabServices/labAccounts/getRestrictionsAndUsage/action; and Microsoft.Insights/alertRules/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Lab Creator Azure role?

Key considerations when assigning Lab Creator: A creator receives control over each lab the creator makes, including lab settings, deletion, and role assignment on that created lab.; A resource-group assignment exposes other labs in the group, whereas a lab-plan assignment does not grant visibility into labs created by other users because plans and labs are siblings.; and Continuing to create labs increases the migration and cleanup surface before the fixed retirement date.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →