{"record":{"id":"84d3913449799375","repo":"hashicorp/terraform","slug":"subscription-id-not-specified","errorCode":null,"errorMessage":"subscription id not specified","messagePattern":"subscription id not specified","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/azure/api_client.go","lineNumber":92,"sourceCode":"\t}\n\n\tif armAuthRequired {\n\t\tresourceManagerAuth, err := auth.NewAuthorizerFromCredentials(ctx, *config.AuthConfig, config.AuthConfig.Environment.ResourceManager)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"unable to build authorizer for Resource Manager API: %+v\", err)\n\t\t}\n\n\t\t// When using Azure CLI to auth, the user can leave the \"subscription_id\" unspecified. In this case the subscription id is inferred from\n\t\t// the Azure CLI default subscription.\n\t\tif config.SubscriptionID == \"\" {\n\t\t\tif cachedAuth, ok := resourceManagerAuth.(*auth.CachedAuthorizer); ok {\n\t\t\t\tif cliAuth, ok := cachedAuth.Source.(*auth.AzureCliAuthorizer); ok && cliAuth.DefaultSubscriptionID != \"\" {\n\t\t\t\t\tconfig.SubscriptionID = cliAuth.DefaultSubscriptionID\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\t\tif config.SubscriptionID == \"\" {\n\t\t\treturn nil, fmt.Errorf(\"subscription id not specified\")\n\t\t}\n\n\t\t// Setup the SA client.\n\t\tclient.storageAccountsClient, err = storageaccounts.NewStorageAccountsClientWithBaseURI(config.AuthConfig.Environment.ResourceManager)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"building Storage Accounts client: %+v\", err)\n\t\t}\n\t\tclient.configureClient(client.storageAccountsClient.Client, resourceManagerAuth)\n\n\t\t// Populating the storage account detail\n\t\tstorageAccountId := commonids.NewStorageAccountID(config.SubscriptionID, config.ResourceGroupName, client.storageAccountName)\n\t\tresp, err := client.storageAccountsClient.GetProperties(ctx, storageAccountId, storageaccounts.DefaultGetPropertiesOperationOptions())\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"retrieving %s: %+v\", storageAccountId, err)\n\t\t}\n\t\tif resp.Model == nil {\n\t\t\treturn nil, fmt.Errorf(\"retrieving %s: model was nil\", storageAccountId)\n\t\t}","sourceCodeStart":74,"sourceCodeEnd":110,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/azure/api_client.go#L74-L110","documentation":"Thrown by Azure buildClient in the armAuthRequired block when config.SubscriptionID is still empty after attempting to infer it from an Azure CLI default subscription. ARM calls (listing access keys, looking up the blob endpoint) require a subscription id, and there is no other fallback.","triggerScenarios":"armAuthRequired is true, config.SubscriptionID == \"\", the resourceManagerAuth is not a CachedAuthorizer wrapping an AzureCliAuthorizer (or it is, but DefaultSubscriptionID is also empty), so the second `if config.SubscriptionID == \"\"` check fails and returns this error.","commonSituations":"Service principal auth configured without a subscription_id and the SP flow does not provide one; CLI-based auth expected but `az account set` was never run or the CLI is not logged in; CI assumed the subscription would be auto-detected but used SP auth instead of CLI auth.","solutions":["Set subscription_id in the azurerm backend block, or export ARM_SUBSCRIPTION_ID.","If relying on Azure CLI inference, run `az login` then `az account set --subscription <id>` in the same shell before running Terraform.","Verify the auth flow actually produces an AzureCliAuthorizer; SP/certificate flows do not carry a default subscription and need it supplied explicitly.","Confirm the subscription id GUID is valid and that the SP has access to it."],"exampleFix":"# before: SP auth, no subscription id\nexport ARM_CLIENT_ID=...\nexport ARM_CLIENT_SECRET=...\nexport ARM_TENANT_ID=...\n# error: subscription id not specified -> after\nexport ARM_SUBSCRIPTION_ID=22222222-2222-2222-2222-222222222222","handlingStrategy":"validation","validationCode":"func ensureSubscription(c *BackendConfig) error {\n    if c.SubscriptionID != \"\" { return nil }\n    // only CLI auth can infer it; everything else must set it.\n    return fmt.Errorf(\"subscription_id is required (set ARM_SUBSCRIPTION_ID or run 'az account set')\")\n}","typeGuard":"null","tryCatchPattern":"client, err := azure.NewClient(ctx, cfg)\nif err != nil && strings.Contains(err.Error(), \"subscription id not specified\") {\n    // tell the user to export ARM_SUBSCRIPTION_ID or run `az account set`\n}","preventionTips":["Always set ARM_SUBSCRIPTION_ID in CI, even when you think it can be inferred.","For CLI-based auth, verify `az account show` returns the expected subscription before running terraform.","Treat subscription_id as a required field when using SP/certificate auth."],"tags":["azure","backend","configuration","subscription","arm"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}