Azure Containers built-in role
Container Registry Configuration Reader and Data Access Configuration Reader
Views Azure Container Registry and data-access configuration, lists registry login credentials, tokens, and scope maps, and can create or update diagnostic settings and manage classic alert rules. It has no direct repository artifact DataActions, but exposed admin or token credentials can carry repository read, write, or delete access.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 69b07be0-09bf-439a-b9a6-e73de851bd59
Control-plane actions (33)
Microsoft.ContainerRegistry/registries/operationStatuses/readMicrosoft.ContainerRegistry/registries/readMicrosoft.ContainerRegistry/registries/privateEndpointConnections/readMicrosoft.ContainerRegistry/registries/privateEndpointConnections/operationStatuses/readMicrosoft.ContainerRegistry/registries/listCredentials/actionMicrosoft.ContainerRegistry/registries/tokens/readMicrosoft.ContainerRegistry/registries/tokens/operationStatuses/readMicrosoft.ContainerRegistry/registries/scopeMaps/readMicrosoft.ContainerRegistry/registries/scopeMaps/operationStatuses/readMicrosoft.ContainerRegistry/registries/webhooks/readMicrosoft.ContainerRegistry/registries/webhooks/getCallbackConfig/actionMicrosoft.ContainerRegistry/registries/webhooks/listEvents/actionMicrosoft.ContainerRegistry/registries/webhooks/operationStatuses/readMicrosoft.ContainerRegistry/registries/replications/readMicrosoft.ContainerRegistry/registries/replications/operationStatuses/readMicrosoft.ContainerRegistry/registries/connectedRegistries/readMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/diagnosticSettings/readMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/diagnosticSettings/writeMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/logDefinitions/readMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/metricDefinitions/readMicrosoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Network/privateEndpoints/privateLinkServiceProxies/readMicrosoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/subnets/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual registry whose configuration the principal reviews. A parent assignment is inherited by every registry below it and exposes both registry and data-access configuration across those registries.
Common use cases (1)
- Support a tightly controlled registry audit or monitoring workflow that requires configuration visibility, registry credential listing, and diagnostic or classic-alert configuration without direct repository DataActions.
Prerequisites (1)
- Confirm that the assignee must see registry login credentials and data-access configuration and is authorized to change diagnostic settings or classic alert rules; otherwise use a narrower custom role.
Best practices (2)
- Treat this role as credential-bearing and monitoring-write access rather than a conventional read-only role, and assign it only to trusted auditors or monitoring automation.
- Grant repository Reader or Catalog Lister separately only when the audit explicitly requires artifact or catalog visibility.
Security considerations (2)
- Listing registry login credentials can expose admin credentials whose effective repository authority can include reading, writing, or deleting artifacts.
- Diagnostic-setting and classic-alert writes can redirect telemetry or change alert behavior even though the role cannot directly push or pull repository content.
Assignment guidance
Assign directly on one registry only when the identity needs the documented credential-listing and monitoring-write capabilities as well as configuration reads. Use a narrower custom role for read-only audits and do not treat the absence of DataActions as proof that the role cannot yield repository access through credentials.
Related roles (1)
- Container Registry Contributor and Data Access Configuration Administrator: Adds registry management and data-access configuration administration.
Editorial sources (8)
- Azure built-in roles for Containers - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure Container Registry Microsoft Entra permissions and role assignments overview →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure Container Registry roles directory reference →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure ABAC repository permissions in Azure Container Registry →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.