How to Authenticate Terraform with an Azure Managed Identity
Question details
The user needs to authenticate a Terraform deployment using an Azure system-assigned managed identity within a container application.
- Product
- Terraform / Azure
- Device & OS
- not provided
- Scenario
- Running Terraform deployments via an Azure Container App using system-assigned managed identity authentication after running the 'az login --identity' command.
- Observed behavior
- Terraform fails to authenticate, returning an error that Azure CLI authentication supports only a user or service principal, ignoring the managed identity.
Ensure you have the exact versions of the Terraform AzureRM provider and Azure CLI noted down, as you may need to update them or provide them when seeking support on Microsoft Learn.
Configure the Terraform AzureRM Provider for Managed Identity
Use this solution to bypass user-based Azure CLI authentication by explicitly instructing the Terraform provider to use Managed Service Identity (MSI).
When running Terraform in automated container environments, relying solely on an interactive 'az login' session can cause provider authentication failures. You must configure the provider block directly to support system-assigned managed identities.
Locate the main configuration file where your `azurerm` provider is defined.
Add the attribute `use_msi = true` to the `azurerm` provider block to explicitly enforce managed identity authentication.
If you prefer not to hardcode the configuration, set the environment variable `ARM_USE_MSI=true` in your container app environment settings.
Navigate to the Azure Portal, open the target subscription or resource group's IAM settings, and ensure the container app's system-assigned managed identity has the necessary Contributor or Owner roles.
Document Your Cloud Infrastructure with WPS Office
While resolving complex Azure and Terraform configurations, you will need a reliable tool to document your architecture and troubleshooting steps. WPS Office is a free, lightweight alternative to Microsoft Office that easily handles your technical documentation.
- 1. Download WPS Office: Visit the official WPS website and install the free suite on your workstation.
- 2. Create Infrastructure Documentation: Open WPS Writer to draft your Terraform deployment runbooks and troubleshooting notes.
- 3. Save and Share: Save your documents in .docx format to ensure full compatibility when sharing with colleagues using Microsoft Office.

Frequently Asked Questions
Why does Terraform say Azure CLI authentication only supports a user or service principal?
Terraform's AzureRM provider treats the 'az login' session as an interactive CLI context, which natively expects a user or a service principal. When using managed identities in automation, you must explicitly enable Managed Service Identity (MSI) in the provider settings to bypass this limitation.
How do I pass my managed identity client ID to Terraform?
If you are using a user-assigned managed identity instead of a system-assigned one, you can specify the `client_id` in the `azurerm` provider block or set the `ARM_CLIENT_ID` environment variable in your container app.
Where is the best place to ask advanced Terraform Azure questions?
For highly specific provider issues, the Azure Microsoft Q&A forum or Microsoft Learn community are the best platforms. Always include your exact provider version, CLI version, and authentication configuration for faster assistance.




