Azure Containers built-in role

Container Registry Contributor and Data Access Configuration Administrator

Manages Azure Container Registry resources and data-access configuration, including listing and regenerating admin login credentials, generating token credentials, and creating, updating, or deleting tokens and scope maps. It has no direct repository artifact DataActions, but the credentials and token scopes it controls can create repository read, write, or delete access.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 3bc748fc-213d-45c1-8d91-9da5725539b9

Control-plane actions (58)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual registry. A resource-group or broader assignment is inherited by every registry below it and permits management of registry security and data-access configuration across all of them.

Common use cases (1)

Prerequisites (1)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign directly on one registry to a small platform-administration group only when it owns registry configuration and credential-based access mechanisms. Prefer repository roles for ordinary artifact workflows, disable unused admin credentials, and review every generated token and scope map.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →