Azure Containers built-in role

Container Registry Repository Reader

Container Registry Repository Reader reads and pulls artifacts and repository metadata in an ACR registry configured for RBAC Registry + ABAC Repository Permissions. Its repository operations are registry DataActions, distinct from Azure control-plane management of the registry resource. An optional ABAC condition on the role assignment can restrict access to repositories whose attributes match the approved expression; without a condition, the assignment applies registry-wide.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b93aa761-3e63-49ed-ac28-beffa264f7ac

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (2)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual registry. Azure assignment scope is inherited from parent resource scopes, while any supported ABAC condition filters the repository data-plane operations inside that registry; a condition does not change which Azure registry resources inherit the assignment.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Assign Container Registry Repository Reader on the target ABAC-enabled registry for reads and pulls artifacts and repository metadata. Add a tested repository condition unless registry-wide access is required, and grant Repository Catalog Lister separately only if the principal must enumerate repository names.

Related roles (2)

Editorial sources (8)

Official Microsoft Learn documentation →