Back to Operation

Savings plan Administrator

Azure Built-in Role

Role Information

Details and metadata

Role ID
182a574c-b3c6-4acc-b019-48ae44cd4677
Type
BuiltInRole
Last Updated (Azure)
2024-04-24 15:11:06

Change History

Track all modifications to this role since 2025-12-15 01:08:16+00:00

2024-04-24 15:11:06 Initial Scan
View details
{
  "properties": {
    "roleName": "Savings plan Administrator",
    "type": "BuiltInRole",
    "description": "Lets you read, manage savings plans and delegate savings plan-related roles",
    "assignableScopes": [
      "/providers/Microsoft.BillingBenefits"
    ],
    "permissions": [
      {
        "actions": [
          "Microsoft.BillingBenefits/savingsPlanOrders/read",
          "Microsoft.BillingBenefits/savingsPlanOrders/action",
          "Microsoft.BillingBenefits/savingsPlanOrders/write",
          "Microsoft.BillingBenefits/savingsPlanOrders/savingsPlans/read",
          "Microsoft.BillingBenefits/savingsPlanOrders/savingsPlans/write",
          "Microsoft.BillingBenefits/savingsPlanOrders/*/action",
          "Microsoft.Authorization/roleAssignments/read",
          "Microsoft.Authorization/roleDefinitions/read",
          "Microsoft.Authorization/roleAssignments/write",
          "Microsoft.Authorization/roleAssignments/delete"
        ],
        "notActions": [],
        "dataActions": [],
        "notDataActions": [],
        "Condition": "((!(ActionMatches{'Microsoft.Authorization/roleAssignments/write'})) OR (@Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{182a574c-b3c6-4acc-b019-48ae44cd4677, d534ad90-4ac5-4815-a178-b2e47397baab, 28c0d4cd-558d-4de9-91a0-faa18e7b3266})) AND ((!(ActionMatches{'Microsoft.Authorization/roleAssignments/delete'})) OR (@Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{182a574c-b3c6-4acc-b019-48ae44cd4677, d534ad90-4ac5-4815-a178-b2e47397baab, 28c0d4cd-558d-4de9-91a0-faa18e7b3266}))",
        "ConditionVersion": "2.0"
      }
    ],
    "createdOn": "2024-03-19T15:23:18.125Z",
    "updatedOn": "2024-04-24T15:11:06.154Z",
    "createdBy": null,
    "updatedBy": null
  },
  "id": "/providers/Microsoft.Authorization/roleDefinitions/182a574c-b3c6-4acc-b019-48ae44cd4677",
  "type": "Microsoft.Authorization/roleDefinitions",
  "name": "182a574c-b3c6-4acc-b019-48ae44cd4677"
}

Latest Role JSON

Raw definition from Azure

{
  "properties": {
    "roleName": "Savings plan Administrator",
    "type": "BuiltInRole",
    "description": "Lets you read, manage savings plans and delegate savings plan-related roles",
    "assignableScopes": [
      "/providers/Microsoft.BillingBenefits"
    ],
    "permissions": [
      {
        "actions": [
          "Microsoft.BillingBenefits/savingsPlanOrders/read",
          "Microsoft.BillingBenefits/savingsPlanOrders/action",
          "Microsoft.BillingBenefits/savingsPlanOrders/write",
          "Microsoft.BillingBenefits/savingsPlanOrders/savingsPlans/read",
          "Microsoft.BillingBenefits/savingsPlanOrders/savingsPlans/write",
          "Microsoft.BillingBenefits/savingsPlanOrders/*/action",
          "Microsoft.Authorization/roleAssignments/read",
          "Microsoft.Authorization/roleDefinitions/read",
          "Microsoft.Authorization/roleAssignments/write",
          "Microsoft.Authorization/roleAssignments/delete"
        ],
        "notActions": [],
        "dataActions": [],
        "notDataActions": [],
        "Condition": "((!(ActionMatches{'Microsoft.Authorization/roleAssignments/write'})) OR (@Request[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{182a574c-b3c6-4acc-b019-48ae44cd4677, d534ad90-4ac5-4815-a178-b2e47397baab, 28c0d4cd-558d-4de9-91a0-faa18e7b3266})) AND ((!(ActionMatches{'Microsoft.Authorization/roleAssignments/delete'})) OR (@Resource[Microsoft.Authorization/roleAssignments:RoleDefinitionId] ForAnyOfAnyValues:GuidEquals{182a574c-b3c6-4acc-b019-48ae44cd4677, d534ad90-4ac5-4815-a178-b2e47397baab, 28c0d4cd-558d-4de9-91a0-faa18e7b3266}))",
        "ConditionVersion": "2.0"
      }
    ],
    "createdOn": "2024-03-19T15:23:18.125Z",
    "updatedOn": "2024-04-24T15:11:06.154Z",
    "createdBy": null,
    "updatedBy": null
  },
  "id": "/providers/Microsoft.Authorization/roleDefinitions/182a574c-b3c6-4acc-b019-48ae44cd4677",
  "type": "Microsoft.Authorization/roleDefinitions",
  "name": "182a574c-b3c6-4acc-b019-48ae44cd4677"
}

Effective Permissions

Operations granted by this role (9 total)

Conditional Permissions

This role has conditions that may restrict effective permissions based on context (e.g., resource attributes, request properties).

Permission Patterns (from role definition)

Actions 10 patterns
Microsoft.BillingBenefits/savingsPlanOrders/read Microsoft.BillingBenefits/savingsPlanOrders/action Microsoft.BillingBenefits/savingsPlanOrders/write Microsoft.BillingBenefits/savingsPlanOrders/savingsPlans/read Microsoft.BillingBenefits/savingsPlanOrders/savingsPlans/write Microsoft.BillingBenefits/savingsPlanOrders/*/action Microsoft.Authorization/roleAssignments/read Microsoft.Authorization/roleDefinitions/read Microsoft.Authorization/roleAssignments/write Microsoft.Authorization/roleAssignments/delete

Control Plane Operations (9)

Data Plane Operations (0)

No data plane operations granted