I'm trying to use an Azure Bicep template to assign read-only access for reservations and savings plans. I'm not trying to purchase either resource; I only want to assign the appropriate reader permissions for different billing account types, including CSP, MCA, and EA. For an MCA setup, if a billing account scope isn't available, I may need to assign access at the billing-profile level. Is this supported through Bicep, and what scope and resource types should be used?
3 Answers
The key detail is the scope. Reservation and savings-plan permissions may need to be assigned at the billing-account, billing-profile, or individual resource scope rather than at a normal subscription scope. For an MCA agreement, check whether the billing profile is the first available scope and whether your identity has permission to create role assignments there. If that billing resource type doesn’t expose a supported role-assignment API, Bicep won’t be able to assign it directly and you’ll need to use the billing API, CLI, or portal.
Before writing the template, verify the exact built-in role names and the scope exposed for each agreement type. CSP, MCA, and EA can have different billing hierarchies, so a template that works for a subscription or billing account may not work for a billing profile. The practical approach is to identify the scope ID and role definition ID first, then create a Microsoft.Authorization role assignment only if that billing scope supports ARM deployments.
Purchasing reservations or savings plans isn’t something Bicep handles directly; that would typically be done through the Azure CLI or another pipeline step. Role assignment is a separate issue, but it depends on whether the required billing-scope role and resource provider support ARM or Bicep deployments.

That makes sense. I’m specifically looking for read-only access and will check whether the MCA billing-profile scope supports role assignments before building the Bicep template.