Azure DevOps built-in role
Lab Operator
The lab operator role
Control-plane and data-plane permissions below are imported directly from Microsoft Learn. In-app editorial guidance (use cases, best practices, security notes) and least-privilege recommendations are still pending review.
Role definition ID: a36e6959-b6be-4b12-8e9f-ef4b474d304d
Control-plane actions (24)
Microsoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.LabServices/labPlans/images/readMicrosoft.LabServices/labPlans/readMicrosoft.LabServices/labPlans/saveImage/actionMicrosoft.LabServices/labs/publish/actionMicrosoft.LabServices/labs/readMicrosoft.LabServices/labs/schedules/readMicrosoft.LabServices/labs/schedules/writeMicrosoft.LabServices/labs/schedules/deleteMicrosoft.LabServices/labs/users/readMicrosoft.LabServices/labs/users/writeMicrosoft.LabServices/labs/users/deleteMicrosoft.LabServices/labs/users/invite/actionMicrosoft.LabServices/labs/virtualMachines/readMicrosoft.LabServices/labs/virtualMachines/start/actionMicrosoft.LabServices/labs/virtualMachines/stop/actionMicrosoft.LabServices/labs/virtualMachines/reimage/actionMicrosoft.LabServices/labs/virtualMachines/redeploy/actionMicrosoft.LabServices/labs/virtualMachines/resetPassword/actionMicrosoft.LabServices/locations/usages/readMicrosoft.LabServices/skus/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/