Azure Compute built-in role
Compute Limit Operator
Manages and shares approved compute quota limits, such as VM-family core limits, from a host subscription to guest subscriptions. It does not provide a general virtual-machine management workflow.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 980cf6f7-edec-4fd1-8e9e-28f70b1d5258
Control-plane actions (10)
Microsoft.ComputeLimit/locations/guestSubscriptions/readMicrosoft.ComputeLimit/locations/guestSubscriptions/writeMicrosoft.ComputeLimit/locations/guestSubscriptions/deleteMicrosoft.ComputeLimit/locations/sharedLimits/readMicrosoft.ComputeLimit/locations/sharedLimits/writeMicrosoft.ComputeLimit/locations/sharedLimits/deleteMicrosoft.ComputeLimit/register/actionMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the host subscription whose approved limits are shared. The Compute Limit REST resources are addressed by host subscription and location; a parent assignment would inherit authority across additional subscriptions.
Common use cases (2)
- Configure which guest subscriptions may consume compute limits shared by a host subscription in a region.
- Enable, inspect, or disable shared compute-limit records and register the Compute Limit resource provider.
Prerequisites (2)
- Identify the host subscription, guest subscription IDs, Azure location, and approved compute limits to share.
- Use a supported Compute Limit REST API version and confirm that the workflow is sharing an already approved limit rather than requesting a quota increase.
Best practices (3)
- Assign at the host subscription and keep the operator population small because changes affect capacity available to multiple subscriptions.
- Document each host-to-guest relationship and review it when subscriptions or workload ownership changes.
- Monitor capacity consumption after enabling sharing and remove guest relationships that are no longer needed.
Security considerations (3)
- Adding a guest subscription lets it consume compute limits made available by the host subscription.
- Disabling a shared limit or removing a guest can block future capacity consumption and disrupt deployment plans.
- The role has no VM or data-plane permissions, but its cross-subscription capacity impact makes broad assignment inappropriate.
Assignment guidance
Assign Compute Limit Operator to the capacity-management identity on the host subscription after the host, guest, location, and approved limits are recorded. Do not use it for ordinary quota requests or VM administration, and remove the assignment when the sharing relationship ends.
Editorial sources (7)
- Azure built-in roles for Compute →
Supports: Description, Practical scope. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Azure Compute Limit REST API →
Supports: Description, Practical scope, Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Compute Limit shared limits operations →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.
- Compute Limit guest subscriptions operations →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.