Azure Containers built-in role

AcrPush

AcrPush performs artifact pull, push, tag management, untagging, and OCI referrer creation and deletion for a registry configured in RBAC Registry Permissions mode. The published definition expresses the registry operation as an Azure Action and has no DataActions, while the ACR product documentation describes its functional effect as repository data-plane access. The role is not honored when the registry uses RBAC Registry + ABAC Repository Permissions mode.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 8311e382-0749-4cb8-b61a-304f252e45ec

Control-plane actions (2)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual registry. A resource-group, subscription, or management-group assignment is inherited by every registry below it and cannot narrow access to selected repositories. This legacy role applies only while the target registry remains in RBAC Registry Permissions mode.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Assign AcrPush on the specific RBAC-only registry to the identity that requires artifact pull, push, tag management, untagging, and OCI referrer creation and deletion. For an ABAC-enabled registry, use the documented Repository role, add a repository condition when narrower access is required, and add Repository Catalog Lister separately only when catalog listing is needed.

Related roles (2)

Common questions

When should I assign the AcrPush Azure role?

Assign AcrPush when you need to: Allow a CI/CD identity or approved developer to build and publish images and OCI referrers to one RBAC-only registry.. Practical scope: Assign on the individual registry. A resource-group, subscription, or management-group assignment is inherited by every registry below it and cannot narrow access to selected repositories. This legacy role applies only while the target registry remains in RBAC Registry Permissions mode.

What permissions does the AcrPush Azure role grant?

The role definition grants 2 combined control-plane and data-plane actions. Representative operations include: Microsoft.ContainerRegistry/registries/pull/read; and Microsoft.ContainerRegistry/registries/push/write. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the AcrPush Azure role?

Key considerations when assigning AcrPush: Push authority can replace mutable tags, publish untrusted artifacts or signatures, destructively untag content, and delete OCI referrer artifacts even though it lacks general image or artifact delete permission.; A parent-scope assignment grants the same repository access across every inherited registry, and the role cannot be constrained to selected repositories.; and Switching permissions mode invalidates credentials issued under the prior mode, even when equivalent replacement assignments already exist.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →