Azure Management and governance built-in role
Quota Request Operator
Reads quota usage, creates quota increase requests, tracks request status, registers quota providers, and creates support tickets. It is control-plane capacity administration with no DataActions and does not deploy resources that consume the approved quota.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 0e5f05e5-9ab9-446b-b98d-1e2157c94125
Control-plane actions (14)
Microsoft.Capacity/resourceProviders/locations/serviceLimits/readMicrosoft.Capacity/resourceProviders/locations/serviceLimits/writeMicrosoft.Capacity/resourceProviders/locations/serviceLimitsRequests/readMicrosoft.Capacity/register/actionMicrosoft.Quota/usages/readMicrosoft.Quota/quotas/readMicrosoft.Quota/quotas/writeMicrosoft.Quota/quotaRequests/readMicrosoft.Quota/register/actionMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the subscription whose service quotas the operator manages. Quotas are commonly provider, region, and subscription specific; a management-group assignment would inherit request authority to multiple subscriptions and should not be treated as one shared quota pool.
Common use cases (2)
- Request a supported subscription-level quota increase for a resource provider and region.
- Track quota usage and request status or open the associated Azure support request when required.
Prerequisites (2)
- Identify the subscription, provider, region, current usage, target limit, and business justification.
- Confirm the resource supports self-service quota requests; some limits require a support workflow or cannot be increased.
Best practices (2)
- Assign at the subscription to a capacity-management group and require workload forecasts and cost review before requesting large increases.
- Monitor approved capacity and remove stale increases or assignments when the workload plan changes.
Security considerations (2)
- Increasing quota enables larger deployments and potential spend but does not itself create resources.
- The role can create support tickets and manage classic alerts and deployments exposed by its definition, so it is broader than a quota form alone.
Assignment guidance
Assign to subscription capacity operators after documenting provider, region, target, and cost ownership. Keep resource deployment authority separate and avoid management-group scope unless the operator governs every inherited subscription.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Quickstart: Request a quota increase in the Azure portal →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.