Azure Containers built-in role
Container Registry Configuration Reader and Data Access Configuration Reader
Views Azure Container Registry and data-access configuration, lists registry login credentials, tokens, and scope maps, and can create or update diagnostic settings and manage classic alert rules. It has no direct repository artifact DataActions, but exposed admin or token credentials can carry repository read, write, or delete access.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 69b07be0-09bf-439a-b9a6-e73de851bd59
Control-plane actions (33)
Microsoft.ContainerRegistry/registries/operationStatuses/readMicrosoft.ContainerRegistry/registries/readMicrosoft.ContainerRegistry/registries/privateEndpointConnections/readMicrosoft.ContainerRegistry/registries/privateEndpointConnections/operationStatuses/readMicrosoft.ContainerRegistry/registries/listCredentials/actionMicrosoft.ContainerRegistry/registries/tokens/readMicrosoft.ContainerRegistry/registries/tokens/operationStatuses/readMicrosoft.ContainerRegistry/registries/scopeMaps/readMicrosoft.ContainerRegistry/registries/scopeMaps/operationStatuses/readMicrosoft.ContainerRegistry/registries/webhooks/readMicrosoft.ContainerRegistry/registries/webhooks/getCallbackConfig/actionMicrosoft.ContainerRegistry/registries/webhooks/listEvents/actionMicrosoft.ContainerRegistry/registries/webhooks/operationStatuses/readMicrosoft.ContainerRegistry/registries/replications/readMicrosoft.ContainerRegistry/registries/replications/operationStatuses/readMicrosoft.ContainerRegistry/registries/connectedRegistries/readMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/diagnosticSettings/readMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/diagnosticSettings/writeMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/logDefinitions/readMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/metricDefinitions/readMicrosoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.Resources/deployments/readMicrosoft.Resources/deployments/*/readMicrosoft.Resources/subscriptions/resourceGroups/readMicrosoft.Network/privateEndpoints/privateLinkServiceProxies/readMicrosoft.Network/virtualNetworks/readMicrosoft.Network/virtualNetworks/subnets/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual registry whose configuration the principal reviews. A parent assignment is inherited by every registry below it and exposes both registry and data-access configuration across those registries.
Common use cases (1)
- Support a tightly controlled registry audit or monitoring workflow that requires configuration visibility, registry credential listing, and diagnostic or classic-alert configuration without direct repository DataActions.
Prerequisites (1)
- Confirm that the assignee must see registry login credentials and data-access configuration and is authorized to change diagnostic settings or classic alert rules; otherwise use a narrower custom role.
Best practices (2)
- Treat this role as credential-bearing and monitoring-write access rather than a conventional read-only role, and assign it only to trusted auditors or monitoring automation.
- Grant repository Reader or Catalog Lister separately only when the audit explicitly requires artifact or catalog visibility.
Security considerations (2)
- Listing registry login credentials can expose admin credentials whose effective repository authority can include reading, writing, or deleting artifacts.
- Diagnostic-setting and classic-alert writes can redirect telemetry or change alert behavior even though the role cannot directly push or pull repository content.
Assignment guidance
Assign directly on one registry only when the identity needs the documented credential-listing and monitoring-write capabilities as well as configuration reads. Use a narrower custom role for read-only audits and do not treat the absence of DataActions as proof that the role cannot yield repository access through credentials.
Related roles (1)
- Container Registry Contributor and Data Access Configuration Administrator: Adds registry management and data-access configuration administration.
Common questions
When should I assign the Container Registry Configuration Reader and Data Access Configuration Reader Azure role?
Assign Container Registry Configuration Reader and Data Access Configuration Reader when you need to: Support a tightly controlled registry audit or monitoring workflow that requires configuration visibility, registry credential listing, and diagnostic or classic-alert configuration without direct repository DataActions.. Practical scope: Assign on the individual registry whose configuration the principal reviews. A parent assignment is inherited by every registry below it and exposes both registry and data-access configuration across those registries.
What permissions does the Container Registry Configuration Reader and Data Access Configuration Reader Azure role grant?
The role definition grants 33 combined control-plane and data-plane actions. Representative operations include: Microsoft.ContainerRegistry/registries/operationStatuses/read; Microsoft.ContainerRegistry/registries/read; Microsoft.ContainerRegistry/registries/privateEndpointConnections/read; Microsoft.ContainerRegistry/registries/privateEndpointConnections/operationStatuses/read; Microsoft.ContainerRegistry/registries/listCredentials/action; and Microsoft.ContainerRegistry/registries/tokens/read. Review the permission sections above for the complete definition and exclusions.
What are the security risks of the Container Registry Configuration Reader and Data Access Configuration Reader Azure role?
Key considerations when assigning Container Registry Configuration Reader and Data Access Configuration Reader: Listing registry login credentials can expose admin credentials whose effective repository authority can include reading, writing, or deleting artifacts.; and Diagnostic-setting and classic-alert writes can redirect telemetry or change alert behavior even though the role cannot directly push or pull repository content.. Follow the assignment guidance above and use the narrowest practical scope.
Editorial sources (8)
- Azure built-in roles for Containers - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure Container Registry Microsoft Entra permissions and role assignments overview →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure Container Registry roles directory reference →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure ABAC repository permissions in Azure Container Registry →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.