Article ID: kb10150Last Modified: 06-Oct-2026

The backup storage account does not have enough permissions (code 1068)

Situation

A backup or restore plan failed with the following error message: The backup storage account does not have enough permissions to create temporary credentials. The root cause of the issue is reported in the error message.

Cause

This error will be reported when the backup storage cannot be accessed. The following causes can result in this issue:

  • The access credentials become invalid. These credentials might have been changed, or the storage account might have been disabled after the backup was started.
  • The user access to the backup storage is not properly configured in the Management Console.
  • AWS S3, Wasabi: IAM policy is removed, invalid, or cannot be accessed.
  • AWS S3: There is no permission for creating temporary credentials/federation token.

Solutions

  1. Check if the user or provider accounts are enabled.
  2. Check the storage account credentials.
  3. AWS S3, Wasabi: Check whether the IAM policy is valid.
  4. AWS S3: Check if the GetFederationToken permission is granted (if an IAM role is not used and the storage account is accessed using access/secret keys).

Solution 1. How to check whether the user or provider accounts are enabled

User Account

  1. On the Organization > Users page, find the required user. Use search or filtering to simplify the search.
  2. Click the username to access the side panel.

  1. On the Personal Info tab, check if the user is enabled. Enable the user, if necessary.

Administrator/Provider Account

  1. On the Organization > Administrators page, find the required account. Use search or filtering to simplify the search.
  2. Click the account name to access the side panel.

  1. On the General tab, check if the account has a valid license.

Solution 2. How to check the storage account availability

Check if the storage account is available On the Backup > Storage account page, find the storage account.

If the storage account is not found, add it again using the Add Account button.

Provide the valid credentials for the storage account.

Expand actions and click Change Credentials.

Provide the required credentials. The required credentials depend on the selected storage provider.

Check if the storage account is associated with the user

  1. On the Organization > Users page, find the required user. Use search or filtering to simplify the search.
  2. Click the username to access the side panel.

  1. On the Backup Destinations tab, check if the storage account that is used for the backup is available for the user account. Add a storage account, if necessary. To add an account, click + Add New.

Solution 3. Check whether IAM user policy is valid

Refer to the AWS Documentation to validate the IAM user policy.

Solution 4. AWS S3 storage account

Refer to the AWS Documentation for instructions on how to grant the GetFederationToken permission properly.

https://git.cloudberrylab.com/egor.m/doc-help-kb.git
Production