Azure Containers built-in role

AcrDelete

AcrDelete performs repository, tag, and manifest deletion for a registry configured in RBAC Registry Permissions mode. The published definition expresses the registry operation as an Azure Action and has no DataActions, while the ACR product documentation describes its functional effect as repository data-plane access. The role is not honored when the registry uses RBAC Registry + ABAC Repository Permissions mode.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: c2f4ef07-c644-48eb-af81-4b1b4947fb11

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual registry. A resource-group, subscription, or management-group assignment is inherited by every registry below it and cannot narrow access to selected repositories. This legacy role applies only while the target registry remains in RBAC Registry Permissions mode.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Assign AcrDelete on the specific RBAC-only registry to the identity that requires repository, tag, and manifest deletion. For an ABAC-enabled registry, use the documented Repository role, add a repository condition when narrower access is required, and add Repository Catalog Lister separately only when catalog listing is needed.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →