Azure DevOps built-in role

Lab Services Reader

Views existing Azure Lab Services resources without changing those service resources. The role has no DataActions, but its control-plane definition also includes a supporting resource-deployment wildcard. Azure Lab Services retires on June 28, 2027, so reader access should support inventory and migration rather than a new long-term deployment.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 2a5c394f-5eb7-4d4f-9c8e-e8eae39faebc

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on one lab for lab-specific visibility or on a resource group to view every contained lab. Labs and lab plans are sibling resources, so an assignment on a lab plan is not inherited by its associated labs; resource-group assignments are inherited by both.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (4)

Assignment guidance

Do not create a permanent reader model for a retiring service. Retain or assign Lab Services Reader only for a time-bounded migration inventory at one lab or a dedicated resource group, then remove it when the resources are migrated or deleted.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →