Azure Privileged built-in role
Reservations Administrator
Reads and manages Azure reservations in a Microsoft Entra tenant and can delegate reservation RBAC roles. It is a reservation-specific privileged administrator role, not general subscription ownership.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: a8889054-8d42-49c9-bc1c-52486c10e7cd
Control-plane actions (7)
Microsoft.Capacity/*/readMicrosoft.Capacity/*/actionMicrosoft.Capacity/*/writeMicrosoft.Authorization/roleAssignments/readMicrosoft.Authorization/roleDefinitions/readMicrosoft.Authorization/roleAssignments/writeMicrosoft.Authorization/roleAssignments/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/providers/Microsoft.Capacity
Practical scope
Reservations are tenant-level resources with RBAC that is separate from subscription inheritance. A reservation does not inherit subscription permissions after purchase. Assign this role for all reservations in the tenant or at an individual reservation scope as documented; its permissions are control-plane only and include no DataActions.
Common use cases (2)
- Centrally manage reservation orders across a Microsoft Entra tenant.
- Delegate Reservations Contributor, Reservations Reader, or other supported reservation access at an individual reservation scope.
Prerequisites (2)
- Use the Microsoft Entra tenant that owns the reservation and choose either the tenant-wide or individual-reservation scope required by the task.
- The assigning administrator needs the documented reservation or User Access Administrator authority for the selected scope.
Best practices (3)
- Use Reservations Reader for view-only work or Reservations Contributor when management is required without access delegation.
- Grant tenant-wide reservation access only to the central team responsible for all reservations; otherwise scope to an individual reservation.
- Review reservation RBAC separately from subscription RBAC because the two permission models do not inherit from one another.
Security considerations (3)
- This role can manage reservations and delegate reservation access across its assigned reservation scope.
- Tenant-wide assignment affects reservations throughout the directory and should not be treated as a subscription-local permission.
- The role has no DataActions and does not grant workload data access, but its reservation and delegation authority is still privileged.
Assignment guidance
Assign Reservations Administrator only when the principal must both manage reservations and delegate reservation RBAC. Select Reservations Contributor for management without delegation or Reservations Reader for visibility, and prefer an individual reservation scope over tenant-wide access when possible.
Related roles (3)
- Reservations Contributor: Manages reservations without delegating reservation RBAC roles.
- Reservations Reader: Read-only reservation access.
- Reservation Purchaser: Purchases reservations using a specified subscription.
Editorial sources (3)
- Azure built-in roles for Privileged →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Description. Retrieved 2026-07-16.
- Permissions to view and manage Azure reservations →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.