Azure Containers built-in role

AcrQuarantineReader

AcrQuarantineReader reads registry quarantine state and quarantined artifacts. The published definition combines an Azure registry quarantine read Action with a quarantined-artifact read DataAction; it does not grant ordinary artifact push, delete, or registry management.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: cdda3590-29a3-44f6-95f2-9f980659eb04

Control-plane actions (1)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual registry whose quarantined content the reviewer must inspect. A parent-scope assignment is inherited by every registry below it and exposes quarantined content across those registries.

Common use cases (1)

Prerequisites (1)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign AcrQuarantineReader directly on the registry to the scanner or responder that only inspects quarantined content. Use QuarantineWriter only for a separate identity that must change quarantine state.

Related roles (1)

Editorial sources (7)

Official Microsoft Learn documentation →