The Azure Container Registry admin account is enabled

Use identity-specific registry access instead of shared administrator credentials.

Description

The Azure Container Registry admin account provides a username and passwords that users or systems can share. Its access spans the registry’s images, making it harder to separate permissions and accountability for individual operations.

Potential impact

Exposed or shared credentials can allow broad access to read or modify images and make it harder to identify the actor behind an operation.

Remediation

Grant suitable registry permissions to managed identities or service principals, migrate consumers, and then disable admin_user_enabled. Disabling the account does not configure replacement authentication.

Examples

The examples compare only the admin account setting. Configure alternative authentication and permissions for pulling and publishing images separately.

Before

yaml
- name: Container Registry 생성
  azure.azcollection.azure_rm_containerregistry:
    name: myRegistry
    location: eastus
    resource_group: myResourceGroup
    admin_user_enabled: true
    sku: Premium

After

yaml
- name: Container Registry 생성
  azure.azcollection.azure_rm_containerregistry:
    name: myRegistry
    location: eastus
    resource_group: myResourceGroup
    admin_user_enabled: false
    sku: Premium

References