Skip to content

Commit 0fa5b37

Browse files
Merge pull request #286123 from bandersmsft/remove-classic-admins
MCM - Updates to remove classic admin roles for EA
2 parents 937a63c + 0d79193 commit 0fa5b37

File tree

3 files changed

+14
-25
lines changed

3 files changed

+14
-25
lines changed

articles/cost-management-billing/manage/cancel-azure-subscription.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ The following table describes the permission required to cancel a subscription.
5656
|Subscription type |Who can cancel |
5757
|---------|---------|
5858
|Subscriptions created when you sign up for Azure through the Azure website. For example, when you sign up for an [Azure Free Account](https://azure.microsoft.com/offers/ms-azr-0044p/), [account with pay-as-you-go rates](https://azure.microsoft.com/offers/ms-azr-0003p/) or as a [Visual studio subscriber](https://azure.microsoft.com/pricing/member-offers/credit-for-visual-studio-subscribers/). | Service administrator and subscription owner |
59-
|[Microsoft Enterprise Agreement](https://azure.microsoft.com/pricing/enterprise-agreement/) and [Enterprise Dev/Test](https://azure.microsoft.com/offers/ms-azr-0148p/) | Service administrator and subscription owner |
59+
|[Microsoft Enterprise Agreement](https://azure.microsoft.com/pricing/enterprise-agreement/) and [Enterprise Dev/Test](https://azure.microsoft.com/offers/ms-azr-0148p/) | Subscription owner |
6060
|[Azure plan](https://azure.microsoft.com/offers/ms-azr-0017g/) and [Azure plan for DevTest](https://azure.microsoft.com/offers/ms-azr-0148g/) | Subscription owners |
6161

6262
An account administrator without the service administrator or subscription owner role can’t cancel an Azure subscription. For more information, see [Azure classic subscription administrators](../../role-based-access-control/classic-administrators.md).

articles/cost-management-billing/manage/direct-ea-administration.md

Lines changed: 10 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: EA Billing administration on the Azure portal
33
description: This article explains the common tasks that an enterprise administrator accomplishes in the Azure portal.
44
author: bandersmsft
55
ms.author: banders
6-
ms.date: 06/07/2024
6+
ms.date: 09/04/2024
77
ms.topic: conceptual
88
ms.service: cost-management-billing
99
ms.subservice: enterprise
@@ -265,12 +265,9 @@ Transferring one or more subscriptions from one EA enrollment to another EA enro
265265

266266
Before starting the ownership transfer, get familiar with the following Azure role-based access control (RBAC) policies:
267267

268-
- When doing a subscription or account ownership transfers between two organizational IDs within the same tenant, the following items are preserved:
269-
- Azure RBAC policies
270-
- Existing service administrator
271-
- Coadministrator roles
268+
- When doing a subscription or account ownership transfers between two organizational IDs within the same tenant Azure RBAC policies and role assignments are preserved.
272269
- Cross-tenant subscription or account ownership transfers result in losing your Azure RBAC policies and role assignments.
273-
- Policies and administrator roles don't transfer across different directories. Service administrators are updated to the owner of destination account.
270+
- Policies and administrator roles don't transfer across different directories. The destination enrollment account owner is assigned as the Subscription Owner role on the subscription.
274271
- To avoid losing Azure RBAC policies and role assignments when transferring subscription between tenants, ensure that the **Move the subscriptions to the recipient's Microsoft Entra tenant** selection remains cleared. This selection keeps the services, Azure roles, and policies on the current Microsoft Entra tenant and only transfers the billing ownership for the account.
275272

276273
Before changing an account owner:
@@ -412,18 +409,14 @@ When a user is added as an account owner, any Azure subscriptions associated wit
412409

413410
## Create a subscription
414411

415-
You can use subscriptions to give teams in your organization access to development environments and projects. For example:
412+
You can use subscriptions to give teams in your organization access to development environments and projects. For example:
416413

417414
- Test
418415
- Production
419416
- Development
420417
- Staging
421418

422-
When you create different subscriptions for each application environment, you help secure each environment.
423-
424-
- You can also assign a different service administrator account for each subscription.
425-
- You can associate subscriptions with any number of services.
426-
- The account owner creates subscriptions and assigns a service administrator account to each subscription in their account.
419+
When you create different subscriptions for each application environment, you help secure each environment. As an account owner, you can create multiple subscriptions and assign different Subscription Owners for each subscription.
427420

428421
Check out the [EA admin manage subscriptions](https://www.youtube.com/watch?v=KFfcg2eqPo8) video. It's part of the [Enterprise Customer Billing Experience in the Azure portal](https://www.youtube.com/playlist?list=PLeZrVF6SXmsoHSnAgrDDzL0W5j8KevFIm) series of videos.
429422

@@ -602,7 +595,7 @@ For either option, you must submit a [support request](https://support.microsoft
602595
An organizational unit used to administer subscriptions and for reporting.
603596

604597
**Account owner**<br>
605-
The person who manages subscriptions and service administrators on Azure. They can view usage data on this account and its associated subscriptions.
598+
The person who manages subscriptions and developoment projects.
606599

607600
**Amendment subscription**<br>
608601
A one-year, or coterminous subscription under the enrollment amendment.
@@ -634,11 +627,12 @@ An amendment signed by an enterprise, which provides them with access to Azure a
634627
**Resource quantity consumed**<br>
635628
The quantity of an individual Azure service that was used in a month.
636629

637-
**Service administrator**<br>
630+
**Subscription**<br>
631+
Represents an Azure EA subscription and is a container of Azure services.
632+
633+
**Subscription owner**<br>
638634
The person who accesses and manages subscriptions and development projects.
639635

640-
**Subscription**<br>
641-
Represents an Azure EA subscription and is a container of Azure services managed by the same service administrator.
642636

643637
**Work or school account**<br>
644638
For organizations that set up Microsoft Entra ID with federation to the cloud and all accounts are on a single tenant.

articles/cost-management-billing/manage/understand-ea-roles.md

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.reviewer: sapnakeshari
66
ms.service: cost-management-billing
77
ms.subservice: enterprise
88
ms.topic: conceptual
9-
ms.date: 02/16/2024
9+
ms.date: 09/04/2024
1010
ms.author: banders
1111
---
1212

@@ -49,7 +49,7 @@ The Azure portal hierarchy for Cost Management consists of:
4949

5050
- **Accounts** are organizational units in the Azure portal for Cost Management. You can use accounts to manage subscriptions and access reports.
5151

52-
- **Subscriptions** are the smallest unit in the Azure portal for Cost Management. They're containers for Azure services managed by the Account Owner role, also known as the Subscription's service administrator.
52+
- **Subscriptions** are the smallest unit in the Azure portal for Cost Management. They're containers for Azure services.
5353

5454
The following diagram illustrates simple Azure EA hierarchies.
5555

@@ -63,7 +63,6 @@ The following administrative user roles are part of your enterprise enrollment:
6363
- EA purchaser
6464
- Department administrator
6565
- Account owner
66-
- Service administrator
6766
- Notification contact
6867

6968
Use Cost Management in the [Azure portal](https://portal.azure.com) so you can manage Azure Enterprise Agreement roles.
@@ -127,7 +126,7 @@ You can grant department administrators read-only access when you edit or create
127126
Users with this role can:
128127

129128
- Create and manage subscriptions.
130-
- Manage service administrators.
129+
- Manage subscription role assignments.
131130
- View usage for subscriptions.
132131

133132
Each account requires a unique work, school, or Microsoft account. For more information about Azure portal administrative roles, see [Understand Azure Enterprise Agreement administrative roles in Azure](understand-ea-roles.md).
@@ -136,10 +135,6 @@ There can be only one account owner per account. However, there can be multiple
136135

137136
For different Microsoft Entra accounts, it can take more than 30 minutes for permission settings to take effect.
138137

139-
### Service administrator
140-
141-
The service administrator role has permissions to manage services in the Azure portal and assign users to the coadministrator role.
142-
143138
### Notification contact
144139

145140
The notification contact receives usage notifications related to the enrollment.

0 commit comments

Comments
 (0)