Azure Management and governance built-in role
Reservation Purchaser
Purchases Azure reservations and reads related reservation, billing, and consumption information. It does not provide general resource management or reservation-order administration beyond the published purchase and read surface.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: f7b75c60-3036-4b75-91c3-6b41c27c1689
Control-plane actions (11)
Microsoft.Authorization/roleAssignments/readMicrosoft.Capacity/catalogs/readMicrosoft.Capacity/register/actionMicrosoft.Compute/register/actionMicrosoft.Consumption/register/actionMicrosoft.Consumption/reservationRecommendationDetails/readMicrosoft.Consumption/reservationRecommendations/readMicrosoft.Resources/subscriptions/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.SQL/register/actionMicrosoft.Support/supporttickets/write
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign according to the documented billing and reservation scope for the agreement. Purchasing eligibility depends on billing-account permissions and subscription context; Azure resource hierarchy inheritance must not be confused with provider-specific billing ownership.
Common use cases (2)
- Purchase an approved reservation commitment after finance and workload validation.
- Read the reservation and billing context needed to complete the authorized purchase.
Prerequisites (2)
- Confirm the billing agreement, eligible subscription, reservation product, scope, term, quantity, payment, and purchase authorization.
- Validate usage forecasts and compare reservation economics with savings plans or on-demand consumption.
Best practices (2)
- Assign to a small procurement or FinOps purchasing group and use approval controls outside Azure RBAC for each commitment.
- Review utilization, exchange, refund, renewal, and scope settings after purchase.
Security considerations (2)
- A purchase creates a financial commitment and can be mis-scoped or underutilized even though the role has no workload DataActions.
- Billing and reservation information is financially sensitive; the role is purchase authority, not a least-privilege reader role.
Assignment guidance
Assign only to authorized reservation purchasers at the applicable billing context. Require documented approval per purchase and use Reservations Reader for users who only inspect commitments.
Related roles (2)
- Reservations Reader: Reads reservations across the tenant provider scope without purchase authority.
- Savings plan Purchaser: Separate purchase role for compute savings plans.
Editorial sources (5)
- Azure built-in roles for Management and governance →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Permissions to view and manage Azure reservations →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.