Azure Compute built-in role
Windows 365 Network User
Allows the Windows 365 first-party service to read a designated virtual network and its subnets and to join Cloud PC network interfaces to those subnets. It is a narrowly scoped service role with control-plane Actions only.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 7eabc9a4-85f7-4f71-b8ab-75daaccc1033
Control-plane actions (4)
Microsoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/subnets/readMicrosoft.Network/virtualNetworks/usages/readMicrosoft.Network/virtualNetworks/subnets/join/action
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign to the Windows First Party App on the virtual network associated with the Azure network connection. The assignment covers that VNet and its subnets; assigning at a resource group or subscription would inherit join authority across additional networks.
Common use cases (2)
- Allow Windows 365 to join Cloud PC network interfaces to the designated customer-provided virtual network.
- Replace the older Network Contributor assignment on the ANC virtual network with the Windows 365-specific service role.
Prerequisites (2)
- Use a customer-provided Azure network connection and select the virtual network and subnets approved for Cloud PC provisioning.
- Grant Reader on the subscription and Windows 365 Network Interface Contributor on the associated resource group to the Windows 365 first-party service.
Best practices (3)
- Assign directly on the designated virtual network to the Windows First Party App.
- Keep Cloud PC subnets and routing intentionally designed and validate DNS, address capacity, and network reachability through ANC health checks.
- Remove legacy Network Contributor only after the updated service-role assignments are present and healthy.
Security considerations (3)
- The service can join network interfaces to any subnet in the assigned virtual network, affecting network reachability for provisioned Cloud PCs.
- The role cannot change VNet or subnet configuration and has no DataActions.
- A parent-scope assignment could unintentionally permit subnet joins across multiple networks and should be avoided.
Assignment guidance
Assign Windows 365 Network User to the Windows First Party App on the exact ANC virtual network. Pair it with Network Interface Contributor on the ANC resource group and Reader on the subscription, then validate the ANC before removing older broad network roles.
Related roles (1)
- Windows 365 Network Interface Contributor: Microsoft documents this companion service assignment on the ANC resource group for network-interface and deployment management.
Editorial sources (6)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Role-based access control for Windows 365 →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Windows 365 requirements →
Supports: Prerequisites, Best practices, Related roles. Retrieved 2026-07-16.