Azure Privileged built-in role

Reservations Administrator

Reads and manages Azure reservations in a Microsoft Entra tenant and can delegate reservation RBAC roles. It is a reservation-specific privileged administrator role, not general subscription ownership.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: a8889054-8d42-49c9-bc1c-52486c10e7cd

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Reservations are tenant-level resources with RBAC that is separate from subscription inheritance. A reservation does not inherit subscription permissions after purchase. Assign this role for all reservations in the tenant or at an individual reservation scope as documented; its permissions are control-plane only and include no DataActions.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Reservations Administrator only when the principal must both manage reservations and delegate reservation RBAC. Select Reservations Contributor for management without delegation or Reservations Reader for visibility, and prefer an individual reservation scope over tenant-wide access when possible.

Related roles (3)

Common questions

When should I assign the Reservations Administrator Azure role?

Assign Reservations Administrator when you need to: Centrally manage reservation orders across a Microsoft Entra tenant.; and Delegate Reservations Contributor, Reservations Reader, or other supported reservation access at an individual reservation scope.. Practical scope: Reservations are tenant-level resources with RBAC that is separate from subscription inheritance. A reservation does not inherit subscription permissions after purchase. Assign this role for all reservations in the tenant or at an individual reservation scope as documented; its permissions are control-plane only and include no DataActions.

What permissions does the Reservations Administrator Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.Capacity/*/read; Microsoft.Capacity/*/action; Microsoft.Capacity/*/write; Microsoft.Authorization/roleAssignments/read; Microsoft.Authorization/roleDefinitions/read; and Microsoft.Authorization/roleAssignments/write. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Reservations Administrator Azure role?

Key considerations when assigning Reservations Administrator: This role can manage reservations and delegate reservation access across its assigned reservation scope.; Tenant-wide assignment affects reservations throughout the directory and should not be treated as a subscription-local permission.; and The role has no DataActions and does not grant workload data access, but its reservation and delegation authority is still privileged.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (3)

Official Microsoft Learn documentation →