Your organization wants to delegate Azure Virtual Desktop object management (create and manage host pools, application groups, and workspaces) to the EUC engineering team without granting permissions to create, modify, or delete virtual machines, networks, or storage. You will scope the role at the resource group that contains only Azure Virtual Desktop resources. Which built-in Azure role should you assign?
Choose an answer
Tap an option to check your answer.
Correct answer: Desktop Virtualization Contributor.
Why this is the answer
The Desktop Virtualization Contributor role is the correct choice because it grants permissions specifically for managing Azure Virtual Desktop objects (host pools, application groups, workspaces) without allowing control over underlying infrastructure like virtual machines, networks, or storage. This aligns perfectly with the requirement to delegate AVD management without broader infrastructure privileges. Virtual Machine Contributor would grant too much access to VMs. Contributor and Owner roles provide extensive permissions across all resource types, exceeding the delegated scope. Desktop Virtualization Reader only allows viewing, not managing, AVD objects.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed