Azure Containers built-in role
AcrDelete
AcrDelete performs repository, tag, and manifest deletion for a registry configured in RBAC Registry Permissions mode. The published definition expresses the registry operation as an Azure Action and has no DataActions, while the ACR product documentation describes its functional effect as repository data-plane access. The role is not honored when the registry uses RBAC Registry + ABAC Repository Permissions mode.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: c2f4ef07-c644-48eb-af81-4b1b4947fb11
Control-plane actions (1)
Microsoft.ContainerRegistry/registries/artifacts/delete
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual registry. A resource-group, subscription, or management-group assignment is inherited by every registry below it and cannot narrow access to selected repositories. This legacy role applies only while the target registry remains in RBAC Registry Permissions mode.
Common use cases (1)
- Allow a registry-cleanup identity to delete obsolete repositories, tags, or manifests in one RBAC-only registry without granting push permission.
Prerequisites (2)
- Confirm that the registry role assignment permissions mode is RBAC Registry Permissions; ABAC-enabled registries require the corresponding Container Registry Repository role instead.
- Identify the user, workload identity, or orchestrator that performs the registry operation and the exact registry it must access.
Best practices (2)
- Assign directly on one registry and use a managed identity or service principal for automation rather than sharing registry credentials.
- Before changing the registry to ABAC-enabled mode, add equivalent ABAC-enabled assignments, validate access, switch modes, refresh client credentials, and then remove the legacy assignments.
Security considerations (3)
- Deletion can make images unavailable to deployments and can remove tags or manifests needed for rollback, investigation, or retention requirements.
- A parent-scope assignment grants the same repository access across every inherited registry, and the role cannot be constrained to selected repositories.
- Switching permissions mode invalidates credentials issued under the prior mode, even when equivalent replacement assignments already exist.
Assignment guidance
Assign AcrDelete on the specific RBAC-only registry to the identity that requires repository, tag, and manifest deletion. For an ABAC-enabled registry, use the documented Repository role, add a repository condition when narrower access is required, and add Repository Catalog Lister separately only when catalog listing is needed.
Related roles (2)
- Container Registry Repository Contributor: ABAC-enabled replacement for repository read, write, and delete access; optional conditions can limit repositories.
- AcrPush: Adds pull and push access in RBAC-only mode; it can also untag content and delete OCI referrer artifacts, but not perform general artifact deletion.
Editorial sources (8)
- Azure built-in roles for Containers - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure Container Registry Microsoft Entra permissions and role assignments overview →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure Container Registry roles directory reference →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure ABAC repository permissions in Azure Container Registry →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.