|[Container registries should have anonymous authentication disabled.](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2F9f2dea28-e834-476c-99c5-3507b4728395) |Disable anonymous pull for your registry so that data is not accessible by unauthenticated user. Disabling local authentication methods like admin user, repository scoped access tokens and anonymous pull improves security by ensuring that container registries exclusively require Azure Active Directory identities for authentication. Learn more at: [https://aka.ms/acr/authentication](../../../../articles/container-registry/container-registry-authentication.md). |Audit, Deny, Disabled |[1.0.0](https://github.com/Azure/azure-policy/tree/master/built-in-policies/policyDefinitions/Container%20Registry/ACR_AnonymousPullDisabled_AuditDeny.json) |
0 commit comments