Introduction
Employers expect cloud engineers to build security in from the start, not add it later.
The scenario: At Fabrikam Inc., the DevOps team is moving from AKS to Azure Container Apps. Before deploying anything, the security team requires that the container registry use a managed identity instead of stored credentials, grant only pull permissions (least privilege), and be reachable only through a private endpoint.
In Part 2, I meet those requirements by creating a user-assigned managed identity, assigning it the AcrPull role, and configuring a private endpoint with private DNS on VNET1/PESubnet. I then verify the setup.
Here, I configure a container registry instance for a secure connection from a container app.
The following Azure resources must be available in your Resource group named RG1:
- A Container Registry instance that contains one image.
- A Virtual Network with subnets.
- Service Bus Namespace
Important
The previous unit (Prepare your app deployment tools and resources) includes a Setup section that describes how to configure the recourses for this guided project module. If necessary, go back and follow the Setup instructions.
You've been asked to configure your Azure resources to meet the following requirements:
- Your resource group must include a user-assigned managed identity.
- Your container registry must be able to use the managed identity to pull artifacts.
- Access for the managed identity must be limited using the principle of least privilege.
- Your container registry must be accessible from a private endpoint on VNET1/PESubnet.
You complete the following tasks during this exercise:
1.Configure a user-assigned managed identity.
2.Configure your container registry with AcrPull permissions for the managed identity.
3.Configure your container registry with a private endpoint connection.
4.Verify the configuration.
Note
Before continuing, ensure that you've completed the Setup section of the Prepare your app deployment tools and resources unit.
Configure a user-assigned managed identity
Complete the following steps to configure a user-assigned managed identity.
1.Open your Azure portal.
2.On the Search bar, enter managed identity
3.In the filtered list of resources, select User Assigned Managed Identity.
4.On the User Assigned Managed Identity page, select Create.
5.On the Create User Assigned Managed Identity page, specify the following information:
- Subscription: Specify the Azure subscription that you're using for this guided project.
- Resource group: RG1
- Region: Central US
- Name: uai-az2003
6.Select Review + create.
7.Select Create.
Configure Container Registry with AcrPull permissions for the managed identity
Complete the following steps to configure Container Registry with AcrPull permissions for the managed identity.
1.In the Azure portal, open your Container Registry resource.
2.On the left-side menu, select Access Control (IAM).
3.On the Access Control (IAM) page, select Add role assignment.
4.Search for the AcrPull role, and then select AcrPull.
5.Select Next.
6.On the Members tab, to the right of Assign access to, select Managed identity.
7.Select + Select members.
8.On the Select managed identities page, under Managed identity, select User-assigned managed identity, and then select the user-assigned managed identity created for this project.
For example: uai-az2003.
9.On the Select managed identities page, select Select.
10.On the Members tab of the Add role assignment page, select Review + assign.
11.On the Review + assign tab, select Review + assign.
12.Wait for the role assignment to be added.
Configure Container Registry with a private endpoint connection
1.Ensure that your Container Registry resource is open in the portal.
2.Under Settings, select Networking.
3.On the Private access tab, select + Create a private endpoint connection.
4.On the Basics tab, under Project details, specify the following information:
- Subscription: Specify the Azure subscription that you're using for this guided project.
- Resource group: RG1
- Name: pe-acr-az2003
- Region: Ensure that Central US is selected.
5.Select Next: Resource.
6.On the Resource tab, ensure the following information is displayed:
- Subscription: Ensure that the Azure subscription that you're using for this guided project is selected.
- Resource type: Ensure that Microsoft.ContainerRegistry/registries is selected.
- Resource: Ensure that the name of your registry is selected.
- Target sub-resource: Ensure that registry is selected.
7.Select Next: Virtual Network.
8.On the Virtual Network tab, under Networking, ensure the following information is displayed:
- Virtual network: Ensure that
VNET1is selected - Subnet: Ensure that
PESubnetis selected.
9.Select Next: DNS.
10.On the DNS tab, under Private DNS Integration, ensure the following information is displayed:
- Integrate with private DNS zone: Ensure that Yes is selected.
- Private DNS Zone: Notice that (new) privatelink.azurecr.io is specified.
11.Select Next: Tags.
12.Select Next: Review + create.
13.On the Review + create tab, when you see the Validation passed message, select Create.
14.Wait for the deployment to complete.
Check your work
In this task, you verify that your configuration meets the specified requirements.
1.In the Azure portal, open your Container Registry resource.
2.On the Access Control (IAM) page, select Role assignments.
3.Verify that the role assignments list shows the AcrPull role assigned to the User-assigned Managed Identity resource.
4.On the left-side menu, under Settings, select Networking.
5.On the Networking page, select the Private access tab.
6.Under Private endpoint, select the private endpoint that you created.
For example, select per-acr-az2003
7.On the Private endpoint page, under Settings, select DNS configuration.
8.Verify the following DNS setting:
- Private DNS zone: set to privatelink.azurecr.io.
9.On the left-side menu, select Overview.
10.Verify the following setting:
- Virtual network/subnet: set to VNET1/PESubnet.
Summary
Cloud and DevOps practitioner building hands-on Azure security skills through a five-part series on Azure Container Apps.
Part 2 focuses on securing Azure Container Registry for a container app, following the principle of least privilege:
Created a user-assigned managed identity to replace stored credentials
Assigned the AcrPull role so the identity can pull images and nothing more
Configured a private endpoint on VNET1/PESubnet with private DNS integration (privatelink.azurecr.io)
Verified the role assignment, DNS configuration, and network placement against the requirements


















Top comments (2)
Part 2 is about securing Azure Container Registry with a user-assigned managed identity (AcrPull) and a private endpoint. Next, I'll create the container app itself. Follow along if you'd like to catch the rest of the series!
I approach cloud work with security and cost in mind from day one. In this part, I replaced stored credentials with a managed identity limited to AcrPull, and locked the registry behind a private endpoint with private DNS. Each setting is verified against the requirements at the end. I document every step so teams can repeat the setup. I'm open to DevOps and cloud roles, so feel free to connect with me.