Azure Containers built-in role
Container Registry Transfer Pipeline Contributor
Configures ACR import and export transfer pipelines that move artifacts through intermediary storage accounts and Key Vault. Microsoft explicitly states that it does not grant ordinary image push or pull, storage-account or vault management, or role-assignment authority.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: bf94e731-3a51-4a7c-8c54-a1ab9971dfc1
Control-plane actions (10)
Microsoft.ContainerRegistry/registries/exportPipelines/readMicrosoft.ContainerRegistry/registries/exportPipelines/writeMicrosoft.ContainerRegistry/registries/exportPipelines/deleteMicrosoft.ContainerRegistry/registries/importPipelines/readMicrosoft.ContainerRegistry/registries/importPipelines/writeMicrosoft.ContainerRegistry/registries/importPipelines/deleteMicrosoft.ContainerRegistry/registries/pipelineRuns/readMicrosoft.ContainerRegistry/registries/pipelineRuns/writeMicrosoft.ContainerRegistry/registries/pipelineRuns/deleteMicrosoft.ContainerRegistry/registries/pipelineRuns/operationStatuses/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on each registry participating in the approved transfer workflow. Parent assignments inherit to all registries below them; storage container and Key Vault access are separate assignments on those resources.
Common use cases (1)
- Configure and run a documented artifact transfer between disconnected or restricted registries through approved intermediary storage.
Prerequisites (1)
- Provision the source and target pipeline resources, intermediary storage, Key Vault secrets, export policy, network path, and separate permissions required by the documented transfer design.
Best practices (2)
- Use dedicated identities and storage containers for each trust boundary and protect pipeline tokens and Key Vault secrets.
- Validate artifact digests and signatures on both sides and remove temporary pipeline or intermediary access after a one-time transfer.
Security considerations (2)
- Pipeline configuration can export sensitive artifacts or import untrusted content across disconnected trust boundaries.
- The role does not provide push, pull, Key Vault management, storage management, or role-assignment permissions; adding broad companion roles would materially expand its impact.
Assignment guidance
Assign on the exact source or target registry to the transfer automation identity. Grant only the separately documented storage and Key Vault access at those resources, validate the transfer, and remove temporary assignments when complete.
Related roles (1)
- Container Registry Data Importer and Data Reader: Supports server-side import and registry data reads without configuring a disconnected transfer pipeline.
Editorial sources (7)
- Azure built-in roles for Containers - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Azure Container Registry roles directory reference →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Transfer artifacts to another registry →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.