Container Registry admin user is enabled

Prefer individual user and workload authentication with least privilege over shared administrator credentials.

Description

The ACR admin account has broad permissions across the registry. Sharing its password makes actions harder to attribute, and disclosure can affect the image supply chain. Prefer Microsoft Entra ID and role-based permissions unless an integration specifically requires the admin account.

Potential impact

  • Disclosed administrator credentials can be abused to read or change images.
  • Sharing the account makes individual attribution and permission revocation harder.

Remediation

  • Configure alternative authentication and required roles first, then disable the admin account with admin_enabled = false. Use supported Microsoft Entra ID or managed-identity authentication for individual users or workloads.
  • For integrations that require the admin account, limit its use and protect and rotate the passwords. Regenerate exposed credentials separately and test dependent connections.

Examples

Resource-group references are aligned and current AzureRM georeplications blocks are used. Replace the registry name with an available name.

Before

hcl
resource "azurerm_resource_group" "example" {
  name     = "resourceGroup1"
  location = "West US"
}

resource "azurerm_container_registry" "example" {
  name                     = "containerRegistry1"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  sku                      = "Premium"
  admin_enabled            = true
  georeplications {
    location = "East US"
  }
  georeplications {
    location = "West Europe"
  }
}

After

hcl
resource "azurerm_resource_group" "example" {
  name     = "resourceGroup1"
  location = "West US"
}

resource "azurerm_container_registry" "example" {
  name                     = "containerRegistry1"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  sku                      = "Premium"
  admin_enabled            = false
  georeplications {
    location = "East US"
  }
  georeplications {
    location = "West Europe"
  }
}

Explanation:

  • Before: The registry administrator account is enabled.
  • After: The administrator account is disabled. This does not automatically create alternative identities or roles.

References