Azure Containers built-in role

Container Registry Tasks Contributor

Creates, changes, runs, cancels, and inspects ACR Tasks, quick builds, quick runs, task logs, and agent pools, including customer-authored build directives and scripts; it can retrieve run-log SAS URLs. On RBAC-only registries, Microsoft warns that task management can be used for full registry data-plane operations, including reading, writing, or deleting images. On ABAC-enabled registries, tasks and quick operations have no default source-registry data access and require an explicitly authorized task identity or caller.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fb382eab-e894-4461-af04-94435c366c3f

Control-plane actions (24)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual registry that owns the tasks. Parent-scope assignments are inherited by every registry below them and permit task administration and execution across those registries.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (3)

Assignment guidance

Assign directly on one registry only to the build-platform identity that owns executable ACR Task configuration. In RBAC-only mode, treat the grant as capable of full registry content impact. In ABAC-enabled mode, explicitly assign the least repository role to each task identity or quick-task caller and review any ABAC condition.

Related roles (1)

Editorial sources (8)

Official Microsoft Learn documentation →