Does the Owner Role Let Admin1 Assign Scaling1 to Pool1?

Plan and implement security Implement host pools and session hosts
Answer Correct answer: A — Assigning Admin1 the Owner role for Sub1 grants the Microsoft.Authorization/roleAssignments/write permission needed to assign Scaling1 to Pool1.

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have an Azure subscription named Sub1 that contains the resources shown in the following table. You have a user named Admin1 that is assigned the Desktop Virtualization Contributor role for Sub1. You need to ensure that Admin1 can assign Scaling1 to Pool1. Solution: You assign Admin1 the Owner role for Sub1. Does this meet the goal? - image

  1. Yes Correct Answer
  2. No

Community Votes

B
56%
A
44%

56% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests whether you know the scaling-plan assignment flow needs role-assignment rights (Owner or User Access Administrator) on top of Desktop Virtualization Contributor, rather than assuming the contributor role alone is sufficient.

Assigning Scaling1 to Pool1 in Azure Virtual Desktop requires Microsoft.Authorization/roleAssignments/write so the Azure Virtual Desktop service principal can be granted permission to manage session host VMs, and the Desktop Virtualization Contributor role does not include it. Because the Owner role carries that permission, assigning Admin1 Owner for Sub1 does meet the goal.

Answering No because Admin1 already holds Desktop Virtualization Contributor and can manage scaling plans and host pools — that role still lacks Microsoft.Authorization/roleAssignments/write, which is exactly the permission the autoscale assignment flow requires.

Community Discussion (6 comments)

d7b83e2 👍 1 Selected: A
Is something going on here? Many people saying no and their explanation is exactly what the question suggests.
zuzmo483 👍 1 Selected: B
I am risking to say B. Pool1 and Scaling1 are already exist. Admin1 would need Owner or User Access Admin role on the sub if the Service Principal needs to be given with the proper RBAC role to be able to create scaling plan. Admin1 already owns the Desktop Virtualization Contributor role which has the required permission to manage scaling plans: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/compute#desktop-virtualization-contributor https://learn.microsoft.com/en-us/azure/virtual-desktop/rbac Microsoft.DesktopVirtualization/ Microsoft.Resources/subscriptions/resourceGroups/read Microsoft.Resources/deployments/ Microsoft.Authorization//read Microsoft.Insights/alertRules/ Microsoft.Support/*
brucespr 👍 1 Selected: A
Yes You must have the Microsoft.Authorization/roleAssignments/write permission on your subscriptions in order to assign the role-based access control (RBAC) role for the Azure Virtual Desktop service principal on those subscriptions. This is part of User Access Administrator and Owner built in roles. https://learn.microsoft.com/en-us/azure/virtual-desktop/autoscale-create-assign-scaling-plan?tabs=portal%2Cintune&pivots=power-management
ClintC03 👍 1 Selected: B
Answer is B. https://learn.microsoft.com/en-us/azure/virtual-desktop/autoscale-create-assign-scaling-plan?tabs=portal%2Cintune&pivots=power-management
sKostas 👍 3 Selected: B
No, the Azure Virtual Desktop service principal needs to have the Owner role in the subscription.
jeff1988 👍 2 Selected: A
A. Yes Yes, assigning Admin1 the Owner role for Sub1 would meet the goal. The Owner role provides full access to all resources, including the ability to assign scaling plans to host pools.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Assigning Scaling1 to Pool1 is not a pure Desktop Virtualization operation: autoscale requires the Azure Virtual Desktop service principal to be granted rights to start, stop, and deallocate the session host VMs, and creating that role assignment requires Microsoft.Authorization/roleAssignments/write on the subscription. Microsoft's autoscale documentation states this permission "is part of User Access Administrator and Owner built in roles," and Desktop Virtualization Contributor does not contain it. Granting Admin1 the Owner role for Sub1 therefore supplies precisely the missing permission, and Owner's full management access also covers the scalingPlans and hostPools operations the same flow performs. Since Admin1 can now complete every step of assigning Scaling1 to Pool1, the solution meets the stated goal — the answer is Yes.

Why the Other Options Are Wrong

Option B (No) is chosen by learners who reason that Admin1 already manages scaling plans with Desktop Virtualization Contributor, which is true but ignores the separate role-assignment step the feature mandates. Others, such as sKostas, argue that "the Azure Virtual Desktop service principal needs to have the Owner role in the subscription," but that reasoning is inverted: the service principal needs a VM-management role, not Owner, and Owner on Admin1 is exactly what lets Admin1 create those assignments. No scope problem exists in the scenario either, because Pool1 and Scaling1 both live in Sub1, so Owner at subscription scope covers every resource involved. There is no permission gap that assigning Owner leaves open, making the negative verdict unsupported.

Community Comment Notes

The topic is genuinely contested: recorded votes split roughly 56% No to 44% Yes, and the source key also says No, so the majority cannot be treated as decisive here. brucespr points straight at the autoscale documentation and the roleAssignments/write requirement, noting it "is part of User Access Administrator and Owner built in roles" — a direct argument for Yes. d7b83e2 captures the confusion, remarking that "Many people saying no and their explanation is exactly what the question suggests," i.e. the No explanations actually describe why Owner succeeds. zuzmo483's No vote rests on Admin1 already being able to manage scaling plans, which overlooks the distinct role-assignment permission that Owner adds.

Official Reference

Exam Strategy

In "does this solution meet the goal?" items, identify the exact permission the action requires instead of judging the feature knowledge; here the deciding permission is Microsoft.Authorization/roleAssignments/write. Owner and User Access Administrator both carry it at subscription scope, so any solution that grants one of those roles over Sub1 meets the goal.

Frequently Asked Questions

Why isn't Desktop Virtualization Contributor enough to assign Scaling1 to Pool1?

That role manages host pools and scaling plans, but lacks Microsoft.Authorization/roleAssignments/write, which the autoscale flow needs to grant the AVD service principal rights over the session host VMs.

Would User Access Administrator on Sub1 also meet the goal?

Yes. User Access Administrator includes roleAssignments/write at subscription scope, so it can perform the role assignment that assigning Scaling1 to Pool1 requires, just like Owner.

Related Analysis

Practice All AZ-140 Questions

Access 64 questions with complete answers and detailed explanations.

View Full AZ-140 Practice Test →

← Back to AZ-140 Study Guide