Windows Virtual Desktop has a delegated access model that lets you define the amount of access a particular user is allowed to have by assigning them a role. A role assignment has three components: security principal, role definition, and scope. The Windows Virtual Desktop delegated access model is based on the Azure RBAC model. To learn more about specific role assignments and their components, see the Azure role-based access control overview.
Windows Virtual Desktop delegated access supports the following values for each element of the role assignment:
Security principal
Role definition
Scope
Please refer to this document to get more details on delegated access in Windows Virtual desktop: https://learn.microsoft.com/en-us/azure/virtual-desktop/delegated-access-virtual-desktop