Azure Container Registry: unauthorized: authentication required, visit https://aka.ms/acr/authorization (AKS ErrImagePull 401)
Pulling/pushing to ACR wasn’t authenticated — Docker not logged in, or AKS/App Service lacks AcrPull on the registry.
Seen on:
Azure Kubernetes Docker
Meaning
AKS needs the cluster’s kubelet identity to have AcrPull (az aks update --attach-acr). App Service/Container Apps need a managed identity with AcrPull or admin credentials. Locally, az acr login refreshes Docker credentials (tokens last 3 hours).
Common causes
- AKS kubelet identity without AcrPull
- az acr login token expired
- Admin user disabled and no other auth configured
- Pulling from the wrong registry/subscription
⚡ Quick fix
- az aks update -n aks -g rg --attach-acr myacr
- az acr login --name myacr
- Grant AcrPull to the app’s managed identity
Detailed fix by platform
Azure CLI
- bash
az aks update -n aks1 -g rg --attach-acr myacr az aks check-acr -n aks1 -g rg --acr myacr.azurecr.io az acr login --name myacr
How to diagnose
- Identity — Which identity pulls?
- Role — AcrPull on the registry
- Registry — Correct login server
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- CannotPullContainerError ECS task stopped: CannotPullContainerError: pull image manifest has been retried ... / ref pull has been retried
- Conflict container name Conflict. The container name "/x" is already in use by container …
- Container failed to start Cloud Run: The user-provided container failed to start and listen on the port defined provided by the PORT=8080 environment variable
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026