An ACR option, on by default, letting chosen Azure services, for instance ACR import, Container Instances and Defender for Cloud, get past a registry's firewall rules or private endpoint. App Service isn't covered.
Also called allow access by trusted services.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Trusted services in context, with comparison tables and the common traps.
Terms in this definition
- Azure Container Registry
Private Azure registry for container images. Images can be geo-replicated, cleaned up by retention policies and built by ACR Tasks, while webhooks let a push kick off continuous deployment.
- Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
- Private endpoint
A network interface in your subnet whose private IP leads, through Private Link, to a single instance of a service. Peered VNets and on-premises networks (via ExpressRoute or VPN) can use it, after which public access can be switched off.
- App Service
Managed PaaS hosting for web apps and Web App for Containers, run in a sandbox without OS access. Deployment slots and autoscale start at the Standard tier.
Related terms
- AD CS
Short for Active Directory Certificate Services, a Windows Server role that operates a private certificate authority. Because the certificates it issues are not publicly trusted, services needing a public CA, such as Front Door bring-your-own-certificate, refuse them.
- Azure Storage firewall
Network rules on a storage account, applied when public network access is limited to selected networks. Only the listed IP ranges, VNet subnets, resource instances and trusted services can reach the public endpoint; all other traffic is refused.
- Key Vault network settings
Firewall controls on a vault that restrict data-plane access to permitted public IP ranges and VNet subnets via service endpoints, optionally letting trusted services bypass. IP rules can't contain private addresses.