nerdexam
Microsoft

AZ-140 · Question #89

You have been assigned the Workspace Contributor role for managing an Azure Virtual Desktop workspace but you don't have access to information about various applications in the workspace. Which of the

The correct answer is A. Application Group Reader. To gain access to information about various applications within an Azure Virtual Desktop workspace, the Application Group Reader role provides the necessary permissions for viewing application group details and their associated applications.

Submitted by asante_acc· Apr 18, 2026Plan and implement identity and security

Question

You have been assigned the Workspace Contributor role for managing an Azure Virtual Desktop workspace but you don't have access to information about various applications in the workspace. Which of the following role is required to get access?

Options

  • AApplication Group Reader
  • BHost Pool Reader
  • CDesktop Virtualization Reader
  • DDesktop Virtualization contributor
  • EApplication Group Contributor

How the community answered

(48 responses)
  • A
    88% (42)
  • C
    4% (2)
  • D
    6% (3)
  • E
    2% (1)

Why each option

To gain access to information about various applications within an Azure Virtual Desktop workspace, the Application Group Reader role provides the necessary permissions for viewing application group details and their associated applications.

AApplication Group ReaderCorrect

The Application Group Reader role specifically grants read access to application groups and the applications published within them, directly addressing the need to view information about applications in the workspace.

BHost Pool Reader

The Host Pool Reader role provides read access to host pool properties but does not grant access to the applications defined within application groups.

CDesktop Virtualization Reader

While the Desktop Virtualization Reader role provides broad read access across AVD resources, the Application Group Reader role is more granular and directly targets the specific resource type (applications within application groups) the user needs to access.

DDesktop Virtualization contributor

The Desktop Virtualization Contributor role grants full management permissions across all AVD resources, which is excessive if only read access to application information is required.

EApplication Group Contributor

The Application Group Contributor role grants full management permissions for application groups, which is excessive if only read access to application information is required.

Concept tested: Azure Virtual Desktop RBAC for applications

Source: https://learn.microsoft.com/en-us/azure/virtual-desktop/rbac

Topics

#Azure Virtual Desktop#RBAC#Application Groups#Permissions

Community Discussion

No community discussion yet for this question.

Full AZ-140 Practice