Azure DevOps built-in role

Lab Services Reader

Views existing Azure Lab Services resources without changing those service resources. The role has no DataActions, but its control-plane definition also includes a supporting resource-deployment wildcard. Azure Lab Services retires on June 28, 2027, so reader access should support inventory and migration rather than a new long-term deployment.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 2a5c394f-5eb7-4d4f-9c8e-e8eae39faebc

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on one lab for lab-specific visibility or on a resource group to view every contained lab. Labs and lab plans are sibling resources, so an assignment on a lab plan is not inherited by its associated labs; resource-group assignments are inherited by both.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (4)

Assignment guidance

Do not create a permanent reader model for a retiring service. Retain or assign Lab Services Reader only for a time-bounded migration inventory at one lab or a dedicated resource group, then remove it when the resources are migrated or deleted.

Related roles (2)

Common questions

When should I assign the Lab Services Reader Azure role?

Assign Lab Services Reader when you need to: Inventory existing labs, plans, schedules, users, images, and migration dependencies without changing them.; and Give a migration reviewer visibility into one lab or a dedicated Lab Services resource group before cleanup.. Practical scope: Assign on one lab for lab-specific visibility or on a resource group to view every contained lab. Labs and lab plans are sibling resources, so an assignment on a lab plan is not inherited by its associated labs; resource-group assignments are inherited by both.

What permissions does the Lab Services Reader Azure role grant?

The role definition grants 4 combined control-plane and data-plane actions. Representative operations include: Microsoft.LabServices/*/read; Microsoft.Authorization/*/read; Microsoft.Resources/deployments/*; and Microsoft.Resources/subscriptions/resourceGroups/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Lab Services Reader Azure role?

Key considerations when assigning Lab Services Reader: The role exposes lab, plan, schedule, user, image, deployment, authorization, and resource metadata throughout its scope.; The published definition includes Microsoft.Resources/deployments/* in addition to Lab Services reads, so it is not a generic read-only Azure role outside the service boundary.; A resource-group assignment reveals every inherited lab, while a lab-plan assignment does not provide visibility into sibling labs.; and The role cannot operate VMs or change Lab Services resources, but stale visibility remains unnecessary after migration.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →