Azure Containers built-in role

Container Registry Contributor and Data Access Configuration Administrator

Manages Azure Container Registry resources and data-access configuration, including listing and regenerating admin login credentials, generating token credentials, and creating, updating, or deleting tokens and scope maps. It has no direct repository artifact DataActions, but the credentials and token scopes it controls can create repository read, write, or delete access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 3bc748fc-213d-45c1-8d91-9da5725539b9

Control-plane actions (58)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual registry. A resource-group or broader assignment is inherited by every registry below it and permits management of registry security and data-access configuration across all of them.

Common use cases (1)

Prerequisites (1)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign directly on one registry to a small platform-administration group only when it owns registry configuration and credential-based access mechanisms. Prefer repository roles for ordinary artifact workflows, disable unused admin credentials, and review every generated token and scope map.

Related roles (2)

Common questions

When should I assign the Container Registry Contributor and Data Access Configuration Administrator Azure role?

Assign Container Registry Contributor and Data Access Configuration Administrator when you need to: Administer one registry, its network and monitoring configuration, and its admin-credential, token, and scope-map access mechanisms while ordinary publishers and consumers receive separate repository roles.. Practical scope: Assign on the individual registry. A resource-group or broader assignment is inherited by every registry below it and permits management of registry security and data-access configuration across all of them.

What permissions does the Container Registry Contributor and Data Access Configuration Administrator Azure role grant?

The role definition grants 58 combined control-plane and data-plane actions. Representative operations include: Microsoft.Resources/subscriptions/resourceGroups/read; Microsoft.ContainerRegistry/registries/operationStatuses/read; Microsoft.ContainerRegistry/registries/read; Microsoft.ContainerRegistry/registries/write; Microsoft.ContainerRegistry/registries/delete; and Microsoft.ContainerRegistry/registries/listCredentials/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Container Registry Contributor and Data Access Configuration Administrator Azure role?

Key considerations when assigning Container Registry Contributor and Data Access Configuration Administrator: Listing or regenerating admin credentials and generating token credentials can produce credential-derived repository access even though the role has no repository DataActions.; and Creating or changing tokens and scope maps can grant read, write, or delete authority to holders of generated credentials; registry, network, diagnostic, and alert changes can also disrupt clients or reduce visibility.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →