Azure DevOps built-in role

Lab Creator

Creates Azure Lab Services labs and gives the creator full control over labs the creator makes. The definition contains legacy lab-account control-plane Actions and the current lab-plan create-lab DataAction. Azure Lab Services retires on June 28, 2027, so the role should support only an approved interim migration path.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b97fb8bc-a8b2-4522-a38b-dd33c7e65ead

Control-plane actions (18)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Existing guidance supports assignment on one lab plan or on a resource group containing lab plans. Lab plans and labs are sibling resources, so a role on a lab plan is not inherited by a created lab; the service separately grants the creator control of that lab. Resource-group assignments are inherited by both plans and labs.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Do not create a new permanent Lab Creator grant. Where an approved interim lab is unavoidable, retain or assign it on the one existing lab plan, record the migration and removal dates, and remove the assignment after the replacement workflow and lab cleanup are complete.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →