Azure Containers built-in role
AcrPull
AcrPull performs artifact pull and repository metadata read access for a registry configured in RBAC Registry Permissions mode. The published definition expresses the registry operation as an Azure Action and has no DataActions, while the ACR product documentation describes its functional effect as repository data-plane access. The role is not honored when the registry uses RBAC Registry + ABAC Repository Permissions mode.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 7f951dda-4ed3-4680-a7ca-43fe172d538d
Control-plane actions (1)
Microsoft.ContainerRegistry/registries/pull/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual registry. A resource-group, subscription, or management-group assignment is inherited by every registry below it and cannot narrow access to selected repositories. This legacy role applies only while the target registry remains in RBAC Registry Permissions mode.
Common use cases (1)
- Allow an AKS kubelet identity, container host, scanner, developer, or deployment workload to pull images from one RBAC-only registry.
Prerequisites (2)
- Confirm that the registry role assignment permissions mode is RBAC Registry Permissions; ABAC-enabled registries require the corresponding Container Registry Repository role instead.
- Identify the user, workload identity, or orchestrator that performs the registry operation and the exact registry it must access.
Best practices (2)
- Assign directly on one registry and use a managed identity or service principal for automation rather than sharing registry credentials.
- Before changing the registry to ABAC-enabled mode, add equivalent ABAC-enabled assignments, validate access, switch modes, refresh client credentials, and then remove the legacy assignments.
Security considerations (3)
- Pulled artifacts and repository metadata can disclose proprietary software or deployment content even though the role cannot push or delete artifacts.
- A parent-scope assignment grants the same repository access across every inherited registry, and the role cannot be constrained to selected repositories.
- Switching permissions mode invalidates credentials issued under the prior mode, even when equivalent replacement assignments already exist.
Assignment guidance
Assign AcrPull on the specific RBAC-only registry to the identity that requires artifact pull and repository metadata read access. For an ABAC-enabled registry, use the documented Repository role, add a repository condition when narrower access is required, and add Repository Catalog Lister separately only when catalog listing is needed.
Related roles (2)
- Container Registry Repository Reader: ABAC-enabled replacement for artifact read access; Repository Catalog Lister is separate when repository enumeration is required.
- AcrPush: Adds artifact push and tag-management capability in RBAC-only mode.
Editorial sources (8)
- Azure built-in roles for Containers - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure Container Registry Microsoft Entra permissions and role assignments overview →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure Container Registry roles directory reference →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure ABAC repository permissions in Azure Container Registry →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.