Azure Containers built-in role

Container Registry Configuration Reader and Data Access Configuration Reader

Views Azure Container Registry and data-access configuration, lists registry login credentials, tokens, and scope maps, and can create or update diagnostic settings and manage classic alert rules. It has no direct repository artifact DataActions, but exposed admin or token credentials can carry repository read, write, or delete access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 69b07be0-09bf-439a-b9a6-e73de851bd59

Control-plane actions (33)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual registry whose configuration the principal reviews. A parent assignment is inherited by every registry below it and exposes both registry and data-access configuration across those registries.

Common use cases (1)

Prerequisites (1)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign directly on one registry only when the identity needs the documented credential-listing and monitoring-write capabilities as well as configuration reads. Use a narrower custom role for read-only audits and do not treat the absence of DataActions as proof that the role cannot yield repository access through credentials.

Related roles (1)

Editorial sources (8)

Official Microsoft Learn documentation →