StudyToCert

All certifications / SC-500 / Lessons

Microsoft Certified: Cloud and AI Security Engineer Associate (replaces Azure Security Engineer Associate / AZ-500) SC-500 · Domain 3: Secure compute

Container registry security: disable the admin user, RBAC pull/push roles, private endpoints, image vulnerability scanning

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Azure Container Registry (ACR) stores the container images that AKS, App Service, Container Apps and other services run. If an attacker can push to your registry, they can plant a malicious image that your clusters will happily deploy; if they can pull, they may find secrets or proprietary code inside images. So registry security is part of the software supply chain.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-500 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-500 study plan