Identity roles and privileges for a Windows 365 Cloud PC
Now, we will see the various identity roles and privileges for a Windows 365 Cloud PC. A Windows 365 Cloud PC is supported by two different identity types, hybrid identity or cloud-only identity. External identities are not supported by Cloud PCs.
Devices can either be Entra hybrid joined or Entra joined.
Azure Subscription Owner
Users with this role have global access to all resources in the Azure subscription. These rights are needed for the initial setup of Windows 365.
This role grants users full access to manage all resources, including the ability to assign roles in Entra RBAC.
Domain Administrator
Users with this role will be able to create computer accounts in your on-premises domain. This is needed to create the computer accounts for cloud PCs in your domain. You can also delegate access via delegation of control directly to the right organizational unit in your domain.