Forum Discussion

SeeInsideSpace's avatar
SeeInsideSpace
Copper Contributor
Feb 26, 2024

AVD Insights - Read access for support techs

Hi there. I'm trying to give our Support Techs reader access to AVD Insights to assist with troubleshooting and to do a bit of upskilling. They currently have Desktop Virtualization User Session Operator rights to enable them to view sessions and log users off, but see nothing when going to the host pool Insights or Legacy tab. I've tried giving them Reader access to the whole host pool, and Monitoring Reader also, but still no joy. Any ideas what I may be missing? Our admins see the Insights just fine. Thanks

6 Replies

    • SeeInsideSpace's avatar
      SeeInsideSpace
      Copper Contributor

      EugeneH 

       

      No unfortunately not. None of the reader roles when applied to both the host pool and to the log analytics workspace allow them to view Insights. It seems that contributor rights are required which is goes against rule of least privilege for our support desk technicians. Frustrating, as there is much useful data available in the Insights that would help them...  Not sure why Microsoft would make this a non read only function. 

      • EugeneH's avatar
        EugeneH
        Copper Contributor

        SeeInsideSpace I found a way to provide access to my users.

         

        Assign them Reader access to the Log Analytics Workspace and respective Resource Groups containing the AVD resources they need to see Insights dashboards for.....  You can find more info here: 

         

        https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/virtual-desktop/troubleshoot-insights.md

        See the section "My data isn't displaying properly".... 

         

         

  • NKC25's avatar
    NKC25
    Brass Contributor
    https://learn.microsoft.com/en-us/azure/virtual-desktop/rbac#desktop-virtualization-host-pool-reader

    probably hostpool reader access to view the sessionhosts and it's configuration, for monitoring below role should suffice.
    https://learn.microsoft.com/en-us/azure/virtual-desktop/rbac#desktop-virtualization-reader
    • SeeInsideSpace's avatar
      SeeInsideSpace
      Copper Contributor

      NKC25 

       

      No joy unfortunately, they just get a message that Azure Monitor is not configured for the host pool, even though it is. I am wondering if some permissions are needed to the Log Analytics Workspace.

Resources