Enable Registry Access
Implementation Effort: Medium – Requires configuration of registry connectors and credentials for external container registries.
User Impact: Low – Registry access setup is handled by security and DevOps teams; end users are not directly affected.
Overview
Enabling registry access in Microsoft Defender for Containers allows Defender to scan container images stored in external registries such as Docker Hub, Google Artifact Registry, and Google Container Registry. This enables vulnerability assessment and compliance monitoring of container images before they are deployed into Kubernetes environments.
For Docker Hub
- Create a dedicated Docker Hub user with access to all organizational repositories.
- Assign the user an Editor role and verify the email invitation.
- Generate a read-only access token for this user.
- Use the Docker Hub connector in Microsoft Defender for Cloud to provide the username and token 1.