SOLVED

WVD Start on Connect - Custom Role configuration

%3CLINGO-SUB%20id%3D%22lingo-sub-2411978%22%20slang%3D%22en-US%22%3EWVD%20Start%20on%20Connect%20-%20Custom%20Role%20configuration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2411978%22%20slang%3D%22en-US%22%3E%3CP%3EI%20followed%20the%20instructions%20to%20create%20a%20new%20custom%20role%20at%20the%20Subscription%20level%20for%20the%20Windows%20Virtual%20Desktop%20app%20to%20be%20able%20to%20start%2Fstop%20my%20WVD%20VM's%20and%20it%20works%20fine.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%2C%20I%20notice%20that%20this%20role%20assignment%20appears%20on%20all%20my%20resources%20now%20in%20this%20Azure%20Subscription%20(obviously)%20-%20even%20for%20a%20lot%20of%20resources%20that%20are%20not%20related%20to%20WVD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20a%20way%20of%20assigning%20this%20custom%20role%20at%20the%20Resource%20Group%20level%20instead%20of%20at%20the%20Subscription%20level%20so%20that%20I%20can%20only%20apply%20it%20to%20my%20WVD%20resources%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2412463%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20Start%20on%20Connect%20-%20Custom%20Role%20configuration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2412463%22%20slang%3D%22en-US%22%3EYes%20the%20custom%20role%20can%20be%20created%20under%20IAM%20of%20RG%20and%20be%20assigned%20with%20required%20permissions%20(startVM%20and%20readVM)%20which%20will%20limit%20the%20scope%20to%20RG%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2412490%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20Start%20on%20Connect%20-%20Custom%20Role%20configuration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2412490%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F667622%22%20target%3D%22_blank%22%3E%40AaaBokkaLe%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20getting%20back%20to%20me%20on%20this...%20But%20what%20if%20I%20have%20multiple%20RG's%20with%20WVD%20session%20hosts%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20I%20need%20to%20create%20the%20custom%20role%20multiple%20times%20(one%20in%20the%20IAM%20of%20each%20RG)%20and%20then%20add%20each%20of%20these%20roles%20to%20the%20enterprise%20level%20Windows%20Virtual%20Desktop%20Application%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2412506%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20Start%20on%20Connect%20-%20Custom%20Role%20configuration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2412506%22%20slang%3D%22en-US%22%3EStart%20creating%20the%20custom%20role%20at%20Subscription%20level.%20In%20%22Assignable%20Scopes%22%20remove%20the%20Subscription%20and%20chose%20multiple%20RG's%20to%20make%20this%20role%20available%20for%20these%20RG's.%20Hope%20this%20helps%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E
Contributor

I followed the instructions to create a new custom role at the Subscription level for the Windows Virtual Desktop app to be able to start/stop my WVD VM's and it works fine.

 

But, I notice that this role assignment appears on all my resources now in this Azure Subscription (obviously) - even for a lot of resources that are not related to WVD.

 

Is there a way of assigning this custom role at the Resource Group level instead of at the Subscription level so that I can only apply it to my WVD resources?

5 Replies
Yes the custom role can be created under IAM of RG and be assigned with required permissions (startVM and readVM) which will limit the scope to RG

@AaaBokkaLe 

 

Thanks for getting back to me on this... But what if I have multiple RG's with WVD session hosts?

 

Would I need to create the custom role multiple times (one in the IAM of each RG) and then add each of these roles to the enterprise level Windows Virtual Desktop Application?

Start creating the custom role at Subscription level. In "Assignable Scopes" remove the Subscription and chose multiple RG's to make this role available for these RG's. Hope this helps :)
Ah - gotcha, thanks. I see how to do it for a new custom role now

Is it possible to edit these assignable scopes in the Portal for the custom role I have already created to save starting again?
best response confirmed by garymansell (Contributor)
Solution
Yes. Search for your custom role in Roles from previously scoped resource. Select the "..." adjacent to your role to get edit option and proceed with required changes.