Skip to main content

September 2, 2026

Apply Permissions to Allow Horizon Cloud to Manage Microsoft Entra ID Joined Machines for an Azure Subscription

You can provide the permissions by going to the Microsoft Entra ID tenant that the Azure subscription used for Horizon Cloud is linked to and performing the following steps.

Review the following permission descriptions before proceeding:

  • Device.ReadWrite.All - This permission is required if the Entra ID joined pool is to be created or edited without selecting an administrative unit. It is required for machine lifecycle management, allowing Horizon Cloud to register new VMs and cleanly delete device entries from Entra ID when a pool or VM is torn down. This permission can also be assigned as an alternative to the microsoft.directory/devices/delete permission if the pool is to be created or edited by selecting an Administrative Unit.

  • AdministrativeUnit.ReadWrite.All - This permission is required if the Entra ID joined pool is to be created or edited by selecting an administrative unit. It is required if you organize or restrict your Entra ID-joined machine accounts within specific Administrative Units (AUs).

  • RoleManagement.Read.Directory - This permission is required to validate service principal role assignments. It allows Horizon Cloud to read directory role assignments to check necessary configuration compliance.

  • Device.Read.All - This permission is used by the Horizon control plane to query and validate existing machine objects in the tenant.

  • microsoft.directory/devices/delete - If the pool is to be created or edited by selecting an Administrative Unit, this permission can be assigned as an alternative to the Device.ReadWrite.All permission to restrict the scope of the device deletion ability to a particular Administrative Unit. This permission should be assigned to the service principal with the scope at either the directory level or the administrative unit level. It allows the devices to be deleted from Microsoft Entra ID.

    Note: If you do not want to grant Horizon Cloud full Device.ReadWrite.All permissions across the entire directory, you can alternatively grant the specific Azure Active Directory directory-level permission by using microsoft.directory/devices/delete to restrict access only to the specific Administrative Unit scope where your Horizon Cloud desktops reside.

Related information is available in the Machine Identity Requirements section of Requirements Checklist for Deploying a Microsoft Azure Edge. Additional information is available in Microsoft Graph permissions reference in Microsoft product documentation.

Procedure

  1. In the Microsoft Azure portal, navigate to Microsoft Entra ID.

  2. Select Manage > App Registrations in the left-hand navigation pane.

  3. Select the service principle where you want to modify the permissions.

  4. Select Manage > API permissions.

  5. Click Add a permission.

  6. Click Microsoft GRAPH.

  7. Click Application permissions.

  8. Search using the exact permission, such as Device.ReadWrite.All or AdministrativeUnit.ReadWrite.All or RoleManagement.Read.Directory or Device.Read.All.

  9. Select the required permission from the search results shown.

  10. Click Add permissions.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…