Azure Containers built-in role
Container Registry Contributor and Data Access Configuration Administrator
Manages Azure Container Registry resources and data-access configuration, including listing and regenerating admin login credentials, generating token credentials, and creating, updating, or deleting tokens and scope maps. It has no direct repository artifact DataActions, but the credentials and token scopes it controls can create repository read, write, or delete access.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 3bc748fc-213d-45c1-8d91-9da5725539b9
Control-plane actions (58)
Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.ContainerRegistry/registries/operationStatuses/readMicrosoft.ContainerRegistry/registries/readMicrosoft.ContainerRegistry/registries/writeMicrosoft.ContainerRegistry/registries/deleteMicrosoft.ContainerRegistry/registries/listCredentials/actionMicrosoft.ContainerRegistry/registries/regenerateCredential/actionMicrosoft.ContainerRegistry/registries/generateCredentials/actionMicrosoft.ContainerRegistry/registries/replications/readMicrosoft.ContainerRegistry/registries/replications/writeMicrosoft.ContainerRegistry/registries/replications/deleteMicrosoft.ContainerRegistry/registries/replications/operationStatuses/readMicrosoft.ContainerRegistry/registries/privateEndpointConnectionsApproval/actionMicrosoft.ContainerRegistry/registries/privateEndpointConnections/readMicrosoft.ContainerRegistry/registries/privateEndpointConnections/writeMicrosoft.ContainerRegistry/registries/privateEndpointConnections/deleteMicrosoft.ContainerRegistry/registries/privateEndpointConnections/operationStatuses/readMicrosoft.ContainerRegistry/registries/tokens/readMicrosoft.ContainerRegistry/registries/tokens/writeMicrosoft.ContainerRegistry/registries/tokens/deleteMicrosoft.ContainerRegistry/registries/tokens/operationStatuses/readMicrosoft.ContainerRegistry/registries/scopeMaps/readMicrosoft.ContainerRegistry/registries/scopeMaps/writeMicrosoft.ContainerRegistry/registries/scopeMaps/deleteMicrosoft.ContainerRegistry/registries/scopeMaps/operationStatuses/readMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/diagnosticSettings/readMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/diagnosticSettings/writeMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/logDefinitions/readMicrosoft.ContainerRegistry/registries/providers/Microsoft.Insights/metricDefinitions/readMicrosoft.Resources/deployments/*Microsoft.Authorization/*/readMicrosoft.ContainerRegistry/registries/connectedRegistries/readMicrosoft.ContainerRegistry/registries/connectedRegistries/writeMicrosoft.ContainerRegistry/registries/connectedRegistries/deleteMicrosoft.ContainerRegistry/registries/connectedRegistries/deactivate/actionMicrosoft.ContainerRegistry/registries/webhooks/readMicrosoft.ContainerRegistry/registries/webhooks/writeMicrosoft.ContainerRegistry/registries/webhooks/deleteMicrosoft.ContainerRegistry/registries/webhooks/getCallbackConfig/actionMicrosoft.ContainerRegistry/registries/webhooks/ping/actionMicrosoft.ContainerRegistry/registries/webhooks/listEvents/actionMicrosoft.ContainerRegistry/registries/webhooks/operationStatuses/readMicrosoft.Insights/AlertRules/WriteMicrosoft.Insights/AlertRules/DeleteMicrosoft.Insights/AlertRules/ReadMicrosoft.Insights/AlertRules/Activated/ActionMicrosoft.Insights/AlertRules/Resolved/ActionMicrosoft.Insights/AlertRules/Throttled/ActionMicrosoft.Insights/AlertRules/Incidents/ReadMicrosoft.ContainerRegistry/locations/operationResults/readMicrosoft.Network/virtualNetworks/subnets/joinViaServiceEndpoint/actionMicrosoft.Network/virtualNetworks/subnets/readMicrosoft.Network/virtualNetworks/subnets/writeMicrosoft.Network/virtualNetworks/readMicrosoft.Network/privateEndpoints/privateLinkServiceProxies/writeMicrosoft.Network/privateEndpoints/privateLinkServiceProxies/readMicrosoft.Network/privateEndpoints/privateLinkServiceProxies/deleteMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual registry. A resource-group or broader assignment is inherited by every registry below it and permits management of registry security and data-access configuration across all of them.
Common use cases (1)
- Administer one registry, its network and monitoring configuration, and its admin-credential, token, and scope-map access mechanisms while ordinary publishers and consumers receive separate repository roles.
Prerequisites (1)
- Define the registry permissions mode, repository access model, network boundary, identities, and separation between registry administration and artifact workflows.
Best practices (2)
- Disable the registry admin account when it is not required, prefer Microsoft Entra workload identities, and tightly scope every token and scope map.
- Use eligible or time-bound access for people where available and audit credential listing or regeneration, token generation, scope-map changes, permissions-mode changes, and monitoring configuration.
Security considerations (2)
- Listing or regenerating admin credentials and generating token credentials can produce credential-derived repository access even though the role has no repository DataActions.
- Creating or changing tokens and scope maps can grant read, write, or delete authority to holders of generated credentials; registry, network, diagnostic, and alert changes can also disrupt clients or reduce visibility.
Assignment guidance
Assign directly on one registry to a small platform-administration group only when it owns registry configuration and credential-based access mechanisms. Prefer repository roles for ordinary artifact workflows, disable unused admin credentials, and review every generated token and scope map.
Related roles (2)
- Container Registry Configuration Reader and Data Access Configuration Reader: Narrower registry-management role that views configuration and credentials but still writes diagnostic settings and manages classic alert rules.
- Container Registry Repository Contributor: Separate ABAC-capable artifact read, write, and delete DataActions.
Editorial sources (8)
- Azure built-in roles for Containers - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure Container Registry Microsoft Entra permissions and role assignments overview →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure Container Registry roles directory reference →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Azure ABAC repository permissions in Azure Container Registry →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.