You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- Fix filename and update TOC link to manage-reservations-rbac-powershell.md
- Apply sentence-style capitalization to headings while preserving technical role names
- Fix tip formatting to use proper Azure docs [!TIP] extension
- Correct User Access Administrator link anchor from #general to #user-access-administrator
- Add missing punctuation and improve link consistency
Copy file name to clipboardExpand all lines: articles/cost-management-billing/reservations/manage-reservations-rbac-powershell.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,7 +16,7 @@ ms.author: liuyizhu
16
16
17
17
# Grant RBAC access to Azure reservations using PowerShell
18
18
19
-
This article shows you how to grant Role-Based Access Control (RBAC) access to Azure reservations using PowerShell. To view and manage RBAC access in Azure Portal, see [Permissions to view and manage Azure reservations](view-reservations.md).
19
+
This article shows you how to grant Role-Based Access Control (RBAC) access to Azure reservations using PowerShell. To view and manage RBAC access in Azure portal, see [Permissions to view and manage Azure reservations](view-reservations.md).
Copy file name to clipboardExpand all lines: articles/cost-management-billing/reservations/view-reservations.md
+22-21Lines changed: 22 additions & 21 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -35,10 +35,10 @@ Two different authorization methods control a user's ability to view, manage, an
35
35
- Billing admin roles
36
36
- Reservation role-based access control (RBAC) roles
37
37
38
-
## Billing Admin Roles
38
+
## Billing Admin roles
39
39
You can view, manage, and delegate permissions to reservations by using built-in billing admin roles. To learn more about Microsoft Customer Agreement and Enterprise Agreement billing roles, see [Understand Microsoft Customer Agreement administrative roles in Azure](../manage/understand-mca-roles.md) and [Managing Azure Enterprise Agreement roles](../manage/understand-ea-roles.md), respectively.
40
40
41
-
### Billing Admin Roles Required for Reservation Actions
41
+
### Billing Admin roles required for reservation actions
42
42
43
43
**View reservations:**
44
44
- Microsoft Customer Agreement: Users with billing profile reader or above
@@ -57,7 +57,7 @@ You can view, manage, and delegate permissions to reservations by using built-in
57
57
58
58
EA admins or Billing Profile Owners must have owner or reservation purchaser access on at least one EA or MCA subscription to purchase a reservation. This option is useful for enterprises that want a centralized team to purchase reservations. For more information, see [Buy an Azure reservation](prepare-buy-reservation.md).
59
59
60
-
### View and Manage Reservations as a Billing Admin
60
+
### View and manage reservations as a Billing Admin
61
61
62
62
If you're a billing role user, follow these steps to view and manage all reservations and reservation transactions in the Azure portal.
63
63
@@ -68,18 +68,18 @@ If you're a billing role user, follow these steps to view and manage all reserva
68
68
69
69
Billing role users can take ownership of a reservation by selecting one or multiple reservations, selecting **Grant access** in the window that appears. For a Microsoft Customer Agreement, the user should be in the same Microsoft Entra tenant (directory) as the reservation.
70
70
71
-
### Add billing administrators
71
+
### Add Billing Admins
72
72
73
73
Add a user as billing administrator to an Enterprise Agreement or a Microsoft Customer Agreement in the Azure portal.
74
74
75
75
-**Enterprise Agreement**: Add users with the _Enterprise administrator_ role to view and manage all reservation orders that apply to the Enterprise Agreement. Enterprise administrators can view and manage reservations in **Cost Management + Billing**.
76
76
- Users with the _Enterprise administrator (read-only)_ role can only view the reservation from **Cost Management + Billing**.
77
-
- Department admins and account owners can't view reservations _unless_ they're explicitly added to them by using Access control (IAM). For more information, see [Manage Azure Enterprise roles](../manage/understand-ea-roles.md)
77
+
- Department admins and account owners can't view reservations _unless_ they're explicitly added to them by using Access control (IAM). For more information, see [Manage Azure Enterprise roles](../manage/understand-ea-roles.md).
78
78
79
-
-**Microsoft Customer Agreement**: Users with the billing profile owner role or the billing profile contributor role can manage all reservation purchases made using the billing profile
80
-
- Billing profile readers and invoice managers can view all reservations that are paid for with the billing profile. However, they can't make changes to reservations. For more information, see [Billing profile roles and tasks](../manage/understand-mca-roles.md#billing-profile-roles-and-tasks)
79
+
-**Microsoft Customer Agreement**: Users with the billing profile owner role or the billing profile contributor role can manage all reservation purchases made using the billing profile.
80
+
- Billing profile readers and invoice managers can view all reservations that are paid for with the billing profile. However, they can't make changes to reservations. For more information, see [Billing profile roles and tasks](../manage/understand-mca-roles.md#billing-profile-roles-and-tasks).
81
81
82
-
## Reservation RBAC Roles
82
+
## Reservation RBAC roles
83
83
84
84
### Overview
85
85
@@ -93,7 +93,7 @@ Azure provides four reservation-specific RBAC roles with different permission le
93
93
These roles can be scoped to either a specific resource entity (for example, subscription or reservation) or the Microsoft Entra tenant. To learn more about Azure RBAC, see [What is Azure role-based access control (Azure RBAC)?](../../role-based-access-control/overview.md).
94
94
95
95
96
-
### Reservation RBAC Roles Required for Reservation Actions
96
+
### Reservation RBAC roles required for reservation actions
97
97
98
98
**View reservations:**
99
99
- Tenant scope: Users with reservation reader or above
@@ -104,21 +104,22 @@ These roles can be scoped to either a specific resource entity (for example, sub
104
104
- Reservation scope: Built-in contributor or owner roles, or reservation contributor or above
105
105
106
106
**Delegate reservation permissions:**
107
-
- Tenant scope: [User Access administrator](../../role-based-access-control/built-in-roles.md#general) rights are required to grant RBAC roles to all reservations in the tenant. To gain these rights, follow [Elevate access steps](../../role-based-access-control/elevate-access-global-admin.md)
107
+
- Tenant scope: [User Access administrator](../../role-based-access-control/built-in-roles.md#user-access-administrator) rights are required to grant RBAC roles to all reservations in the tenant. To gain these rights, follow [Elevate access steps](../../role-based-access-control/elevate-access-global-admin.md)
108
108
- Reservation scope: Reservation administrator or user access administrator
109
109
110
110
In addition, users who held the subscription owner role when the subscription was used to purchase a reservation can also view, manage, and delegate permissions for the purchased reservation.
111
111
112
-
### View and Manage Reservations with RBAC Access
112
+
### View and manage reservations with RBAC access
113
113
114
114
If you have reservation-specific RBAC roles (reservation administrator, purchaser, contributor, or reader), purchased reservations, or were added as an owner to reservations, follow these steps to view and manage reservations in the Azure portal:
115
115
116
116
1. Sign in to the Azure portal
117
117
2. Select **Home** > **Reservations** to list reservations to which you have access
118
118
119
-
> **Tip**: If you can't see your reservations, ensure you're signed in with the account that has the appropriate permissions. For cross-tenant scenarios, make sure you're in the correct tenant context.
119
+
> [!TIP]
120
+
> If you can't see your reservations, ensure you're signed in with the account that has the appropriate permissions. For cross-tenant scenarios, make sure you're in the correct tenant context.
120
121
121
-
### Delegate Reservation RBAC Roles
122
+
### Delegate reservation RBAC roles
122
123
123
124
Under this section, you will find how to:
124
125
- Delegate the Reservation Purchaser Role to a Specific Subscription
@@ -129,14 +130,14 @@ Users and groups who gain the ability to purchase, manage, or view reservations
129
130
130
131
_Enterprise administrators can take ownership of a reservation order. They can add other users to a reservation by using **Access control (IAM)**._
131
132
132
-
#### Delegate the Reservation Purchaser Role to a Specific Subscription
133
+
#### Delegate the Reservation Purchaser role to a specific subscription
133
134
134
135
To delegate the purchaser role to a specific subscription, and after you have elevated access:
135
136
136
137
1. Go to **Home** > **Reservations** to see all reservations that are in the tenant.
137
138
2. To make modifications to the reservation, add yourself as an owner of the reservation order by using **Access control (IAM)**.
138
139
139
-
#### Delegate Reservation Administrator, Contributor, or Reader Roles to a Specific Reservation
140
+
#### Delegate Reservation Administrator, Contributor, or Reader roles to a specific reservation
140
141
141
142
To delegate the administrator, contributor, or reader roles to a specific reservation:
142
143
@@ -145,15 +146,15 @@ To delegate the administrator, contributor, or reader roles to a specific reserv
145
146
3. Select **Access control (IAM)** on the leftmost pane.
146
147
4. Select **Add**, and then select **Add role assignment** from the top navigation bar.
147
148
148
-
#### Delegate Reservation Administrator, Contributor, or Reader Roles to All Reservations
149
+
#### Delegate Reservation Administrator, Contributor, or Reader roles to all reservations
149
150
150
151
[User Access administrator rights](../../role-based-access-control/built-in-roles.md#user-access-administrator) are required to grant RBAC roles at the tenant level. To get User Access administrator rights, follow the steps for elevated access: [Elevate access steps](../../role-based-access-control/elevate-access-global-admin.md?toc=/azure/cost-management-billing/reservations/toc.json).
151
152
152
153
Then, to delegate the administrator, contributor, or reader role to all reservations in a tenant:
153
154
1. Go to **Home** > **Reservations**
154
155
2. Select **Role assignment** from the top navigation bar
155
156
156
-
## Grant Access to Individual Reservations
157
+
## Grant access to individual reservations
157
158
158
159
Users who have owner access on the reservations and billing administrators can delegate access management for an individual reservation order in the Azure portal.
159
160
@@ -167,20 +168,20 @@ To allow other people to manage reservations, you have two options:
167
168
168
169
_Enterprise Administrators can take ownership of a reservation order and they can add other users to a reservation using Access control (IAM)._
169
170
170
-
- For a Microsoft Customer Agreement, users with the billing profile owner role or the billing profile contributor role can manage all reservation purchases made using the billing profile. Billing profile readers and invoice managers can view all reservations that are paid for with the billing profile. However, they can't make changes to reservations. For more information, see [Billing profile roles and tasks](../manage/understand-mca-roles.md).
171
+
- For a Microsoft Customer Agreement, users with the billing profile owner role or the billing profile contributor role can manage all reservation purchases made using the billing profile. Billing profile readers and invoice managers can view all reservations that are paid for with the billing profile. However, they can't make changes to reservations. For more information, see [Billing profile roles and tasks](../manage/understand-mca-roles.md#billing-profile-roles-and-tasks).
171
172
172
173
173
-
## Grant Access with PowerShell
174
+
## Grant access with PowerShell
174
175
Users that have owner access for reservations orders, users with elevated access, and User Access Administrators can delegate access management for all reservation orders they have access to.
175
176
176
177
Access granted using PowerShell isn't shown in the Azure portal. Instead, you use the `get-AzRoleAssignment` command in the following section to view assigned roles.
177
178
178
-
For details on granting access with PowerShell, see [Grant RBAC access to Azure Reservations using PowerShell](manage-reservation-rbac-powershell.md).
179
+
For details on granting access with PowerShell, see [Grant RBAC access to Azure Reservations using PowerShell](manage-reservations-rbac-powershell.md).
0 commit comments