Azure Containers built-in role

AcrDelete

AcrDelete performs repository, tag, and manifest deletion for a registry configured in RBAC Registry Permissions mode. The published definition expresses the registry operation as an Azure Action and has no DataActions, while the ACR product documentation describes its functional effect as repository data-plane access. The role is not honored when the registry uses RBAC Registry + ABAC Repository Permissions mode.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: c2f4ef07-c644-48eb-af81-4b1b4947fb11

Control-plane actions (1)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual registry. A resource-group, subscription, or management-group assignment is inherited by every registry below it and cannot narrow access to selected repositories. This legacy role applies only while the target registry remains in RBAC Registry Permissions mode.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Assign AcrDelete on the specific RBAC-only registry to the identity that requires repository, tag, and manifest deletion. For an ABAC-enabled registry, use the documented Repository role, add a repository condition when narrower access is required, and add Repository Catalog Lister separately only when catalog listing is needed.

Related roles (2)

Common questions

When should I assign the AcrDelete Azure role?

Assign AcrDelete when you need to: Allow a registry-cleanup identity to delete obsolete repositories, tags, or manifests in one RBAC-only registry without granting push permission.. Practical scope: Assign on the individual registry. A resource-group, subscription, or management-group assignment is inherited by every registry below it and cannot narrow access to selected repositories. This legacy role applies only while the target registry remains in RBAC Registry Permissions mode.

What permissions does the AcrDelete Azure role grant?

The role definition grants 1 combined control-plane and data-plane actions. Representative operations include: Microsoft.ContainerRegistry/registries/artifacts/delete. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the AcrDelete Azure role?

Key considerations when assigning AcrDelete: Deletion can make images unavailable to deployments and can remove tags or manifests needed for rollback, investigation, or retention requirements.; A parent-scope assignment grants the same repository access across every inherited registry, and the role cannot be constrained to selected repositories.; and Switching permissions mode invalidates credentials issued under the prior mode, even when equivalent replacement assignments already exist.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →