Azure Compute built-in role

Compute Limit Operator

Manages and shares approved compute quota limits, such as VM-family core limits, from a host subscription to guest subscriptions. It does not provide a general virtual-machine management workflow.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 980cf6f7-edec-4fd1-8e9e-28f70b1d5258

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the host subscription whose approved limits are shared. The Compute Limit REST resources are addressed by host subscription and location; a parent assignment would inherit authority across additional subscriptions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Compute Limit Operator to the capacity-management identity on the host subscription after the host, guest, location, and approved limits are recorded. Do not use it for ordinary quota requests or VM administration, and remove the assignment when the sharing relationship ends.

Editorial sources (7)

Official Microsoft Learn documentation →