Skip to content

Commit 47eacba

Browse files
committed
Updating each role paragraph to provide clarity
1 parent 1fc7e35 commit 47eacba

File tree

1 file changed

+10
-12
lines changed

1 file changed

+10
-12
lines changed

articles/virtual-desktop/rbac.md

Lines changed: 10 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ The built-in roles for Azure Virtual Desktop and the permissions for each one ar
2121

2222
## Desktop Virtualization Contributor
2323

24-
The Desktop Virtualization Contributor role allows you to manage all aspects of the deployment. However, it doesn't grant you access to compute resources. You'll also need the User Access Administrator role to publish application groups to users or user groups.
24+
The Desktop Virtualization Contributor role allows users to manage all aspects of the deployment. However, it doesn't grant users access to compute resources. You'll also need the *User Access Administrator* role to publish application groups to users or user groups.
2525

2626
| Action type | Permissions |
2727
|--|--|
@@ -32,7 +32,7 @@ The Desktop Virtualization Contributor role allows you to manage all aspects of
3232

3333
## Desktop Virtualization Reader
3434

35-
The Desktop Virtualization Reader role allows you to view everything in the deployment but doesn't let you make any changes.
35+
The Desktop Virtualization Reader role allows users to view everything in the deployment, but doesn't let them make any changes.
3636

3737
| Action type | Permissions |
3838
|--|--|
@@ -54,7 +54,7 @@ The Desktop Virtualization User role allows users to use the applications in an
5454

5555
## Desktop Virtualization Host Pool Contributor
5656

57-
The Host Pool Contributor role allows you to manage all aspects of host pools, including access to resources. You'll need an extra contributor role, Virtual Machine Contributor, to create virtual machines. You will need AppGroup and Workspace contributor roles to create host pool using the portal or you can use Desktop Virtualization Contributor role.
57+
The Desktop Virtualization Host Pool Contributor role allows users to manage all aspects of host pools, including access to resources. You'll also need the *Virtual Machine Contributor* role to create virtual machines. You will need *Desktop Virtualization Application Group Contributor* and *Desktop Virtualization Workspace Contributor* roles to create host pools using the portal, or you can use the *Desktop Virtualization Contributor* role.
5858

5959
| Action type | Permissions |
6060
|--|--|
@@ -65,7 +65,7 @@ The Host Pool Contributor role allows you to manage all aspects of host pools, i
6565

6666
## Desktop Virtualization Host Pool Reader
6767

68-
The Host Pool Reader role allows you to view everything in the host pool, but won't allow you to make any changes.
68+
The Desktop Virtualization Host Pool Reader role allows users to view everything in the host pool, but won't allow them to make any changes.
6969

7070
| Action type | Permissions |
7171
|--|--|
@@ -76,9 +76,7 @@ The Host Pool Reader role allows you to view everything in the host pool, but wo
7676

7777
## Desktop Virtualization Application Group Contributor
7878

79-
The Application Group Contributor role allows you to manage all aspects of application groups. If you want to publish application groups to users or user groups, you'll need the User Access Administrator role.
80-
81-
The following table describes which permissions this role can access:
79+
The Desktop Virtualization Application Group Contributor role allows users to manage all aspects of application groups. If you want users to publish application groups to users or user groups, they'll also need the *User Access Administrator* role.
8280

8381
| Action type | Permissions |
8482
|--|--|
@@ -89,7 +87,7 @@ The following table describes which permissions this role can access:
8987

9088
## Desktop Virtualization Application Group Reader
9189

92-
The Application Group Reader role allows you to view everything in the app group and will not allow you to make any changes.
90+
The Desktop Virtualization Application Group Reader role allows users to view everything in the application group and will not allow them to make any changes.
9391

9492
| Action type | Permissions |
9593
|--|--|
@@ -100,7 +98,7 @@ The Application Group Reader role allows you to view everything in the app group
10098

10199
## Desktop Virtualization Workspace Contributor
102100

103-
The Workspace Contributor role allows you to manage all aspects of workspaces. To get information on applications added to the application groups, you'll also need to be assigned the Application Group Reader role.
101+
The Desktop Virtualization Workspace Contributor role allows users to manage all aspects of workspaces. To get information on applications added to the application groups, they'll also need the *Application Group Reader* role.
104102

105103
| Action type | Permissions |
106104
|--|--|
@@ -111,7 +109,7 @@ The Workspace Contributor role allows you to manage all aspects of workspaces. T
111109

112110
## Desktop Virtualization Workspace Reader
113111

114-
The Workspace Reader role allows you to view everything in the workspace, but won't allow you to make any changes.
112+
The Desktop Virtualization Workspace Reader role allows users to view everything in the workspace, but won't allow them to make any changes.
115113

116114
| Action type | Permissions |
117115
|--|--|
@@ -122,7 +120,7 @@ The Workspace Reader role allows you to view everything in the workspace, but wo
122120

123121
## Desktop Virtualization User Session Operator
124122

125-
The User Session Operator role allows you to send messages, disconnect sessions, and use the "logoff" function to sign sessions out of the session host. However, this role doesn't let you perform session host management like removing session host, changing drain mode, and so on. This role can see assignments, but can't modify admins. We recommend you assign this role to specific host pools. If you give this permission at a resource group level, the admin will have read permission on all host pools under a resource group.
123+
The Desktop Virtualization User Session Operator role allows users to send messages, disconnect sessions, and use the "logoff" function to sign sessions out of the session host. However, this role doesn't let users perform session host management like removing session host, changing drain mode, and so on. This role can see assignments, but can't modify admins. We recommend you assign this role to specific host pools. If you give this permission at a resource group level, the admin will have read permission on all host pools under a resource group.
126124

127125
| Action type | Permissions |
128126
|--|--|
@@ -133,7 +131,7 @@ The User Session Operator role allows you to send messages, disconnect sessions,
133131

134132
## Desktop Virtualization Session Host Operator
135133

136-
The Session Host Operator role allows you to view and remove session hosts, as well as change drain mode. They can't add session hosts using the Azure portal because they don't have write permission for host pool objects. If the registration token is valid (generated and not expired), you can use this role to add session hosts to the host pool outside of the Azure portal if the admin has compute permissions through the Virtual Machine Contributor role.
134+
The Desktop Virtualization Session Host Operator role allows users to view and remove session hosts, as well as change drain mode. Users can't add session hosts using the Azure portal because they don't have write permission for host pool objects. If the registration token is valid (generated and not expired), users assigned this role can add session hosts to the host pool outside of the Azure portal if they also have the *Virtual Machine Contributor* role.
137135

138136
| Action type | Permissions |
139137
|--|--|

0 commit comments

Comments
 (0)