{"record":{"id":"bdc065fbbea7b5e1","repo":"hashicorp/terraform","slug":"one-of-access-key-sas-token-use-azuread-aut","errorCode":null,"errorMessage":"One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified","messagePattern":"One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/azure/backend.go","lineNumber":456,"sourceCode":"\t\tEnableAuthenticationUsingGitHubOIDC:        enableOidc,\n\t\tEnableAuthenticationUsingADOPipelineOIDC:   enableOidc,\n\t}\n\n\tbackendConfig := BackendConfig{\n\t\tAuthConfig:               authConfig,\n\t\tSubscriptionID:           data.String(\"subscription_id\"),\n\t\tResourceGroupName:        data.String(\"resource_group_name\"),\n\t\tStorageAccountName:       data.String(\"storage_account_name\"),\n\t\tLookupBlobEndpoint:       data.Bool(\"lookup_blob_endpoint\"),\n\t\tAccessKey:                data.String(\"access_key\"),\n\t\tSasToken:                 data.String(\"sas_token\"),\n\t\tUseAzureADAuthentication: data.Bool(\"use_azuread_auth\"),\n\t}\n\n\tneedToLookupAccessKey := backendConfig.AccessKey == \"\" && backendConfig.SasToken == \"\" && !backendConfig.UseAzureADAuthentication\n\tif backendConfig.ResourceGroupName == \"\" {\n\t\tif needToLookupAccessKey {\n\t\t\treturn backendbase.ErrorAsDiagnostics(fmt.Errorf(\"One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified\"))\n\t\t}\n\t\tif backendConfig.LookupBlobEndpoint {\n\t\t\treturn backendbase.ErrorAsDiagnostics(fmt.Errorf(\"`resource_group_name` is required when `lookup_blob_endpoint` is set\"))\n\t\t}\n\t}\n\n\tclient, err := buildClient(ctx, backendConfig)\n\tif err != nil {\n\t\treturn backendbase.ErrorAsDiagnostics(err)\n\t}\n\n\tb.apiClient = client\n\treturn nil\n}\n","sourceCodeStart":438,"sourceCodeEnd":471,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/azure/backend.go#L438-L471","documentation":"Validation error in Backend.Configure when resource_group_name is empty AND none of access_key / sas_token / use_azuread_auth is set. In that combination the backend has no credential for the data plane and no resource group to look one up via ARM, so configuration cannot proceed.","triggerScenarios":"Backend block sets only storage_account_name and container (and key), with no auth method and no resource_group_name. needToLookupAccessKey evaluates true.","commonSituations":"Operator expects implicit env-based auth (e.g. az login) but forgot that the default path still needs resource_group_name to call ListKeys; minimal backend block copied from a tutorial that omitted auth.","solutions":["Add resource_group_name to the backend block (enables ARM key lookup).","Provide access_key or sas_token directly.","Set use_azuread_auth = true (recommended).","Re-run `terraform init -reconfigure` after fixing."],"exampleFix":"// before\nterraform {\n  backend \"azurerm\" {\n    storage_account_name = \"acct\"\n    container_name       = \"tfstate\"\n    key                  = \"prod.tfstate\"\n  }\n}\n// after\nterraform {\n  backend \"azurerm\" {\n    resource_group_name  = \"rg-tfstate\"\n    storage_account_name = \"acct\"\n    container_name       = \"tfstate\"\n    key                  = \"prod.tfstate\"\n  }\n}","handlingStrategy":"validation","validationCode":"// Validate the backend block before `terraform init`.\nfunc validateBackendBlock(b BackendConfig) error {\n    needToLookupAccessKey := b.AccessKey == \"\" && b.SasToken == \"\" && !b.UseAzureADAuthentication\n    if b.ResourceGroupName == \"\" && needToLookupAccessKey {\n        return fmt.Errorf(\"One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always pair a default-auth backend block with resource_group_name.","Codify backend blocks as a versioned module so auth fields cannot be silently dropped.","Run a `terraform init -backend=false` then `terraform init` smoke test in CI to catch config errors early."],"tags":["azure","configuration","validation","authentication","terraform-backend"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}