hashicorp/terraform · error
One of `access_key`, `sas_token`, `use_azuread_auth` and…
Error message
One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified
What it means
Validation error in Backend.Configure when resource_group_name is empty AND none of access_key / sas_token / use_azuread_auth is set. In that combination the backend has no credential for the data plane and no resource group to look one up via ARM, so configuration cannot proceed.
Solutions
- Add resource_group_name to the backend block (enables ARM key lookup).
- Provide access_key or sas_token directly.
- Set use_azuread_auth = true (recommended).
- Re-run `terraform init -reconfigure` after fixing.
Example fix
// before
terraform {
backend "azurerm" {
storage_account_name = "acct"
container_name = "tfstate"
key = "prod.tfstate"
}
}
// after
terraform {
backend "azurerm" {
resource_group_name = "rg-tfstate"
storage_account_name = "acct"
container_name = "tfstate"
key = "prod.tfstate"
}
} Defensive patterns
Strategy: validation
Validate before calling
// Validate the backend block before `terraform init`.
func validateBackendBlock(b BackendConfig) error {
needToLookupAccessKey := b.AccessKey == "" && b.SasToken == "" && !b.UseAzureADAuthentication
if b.ResourceGroupName == "" && needToLookupAccessKey {
return fmt.Errorf("One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified")
}
return nil
} Prevention
- Always pair a default-auth backend block with resource_group_name.
- Codify backend blocks as a versioned module so auth fields cannot be silently dropped.
- Run a `terraform init -backend=false` then `terraform init` smoke test in CI to catch config errors early.
When it happens
Trigger: Backend block sets only storage_account_name and container (and key), with no auth method and no resource_group_name. needToLookupAccessKey evaluates true.
Common situations: Operator expects implicit env-based auth (e.g. az login) but forgot that the default path still needs resource_group_name to call ListKeys; minimal backend block copied from a tutorial that omitted auth.
Related errors
- auth must be one of ' ' or ' ' or ' ' or ' ' or ' ' or
- can not get private_key or private_key_path from Terraform…
- can not get from Terraform configuration (SecurityToken)
- missing profile in provider block
- new blob client
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/bdc065fbbea7b5e1.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/azure/backend.go:456
EnableAuthenticationUsingGitHubOIDC: enableOidc,
EnableAuthenticationUsingADOPipelineOIDC: enableOidc,
}
backendConfig := BackendConfig{
AuthConfig: authConfig,
SubscriptionID: data.String("subscription_id"),
ResourceGroupName: data.String("resource_group_name"),
StorageAccountName: data.String("storage_account_name"),
LookupBlobEndpoint: data.Bool("lookup_blob_endpoint"),
AccessKey: data.String("access_key"),
SasToken: data.String("sas_token"),
UseAzureADAuthentication: data.Bool("use_azuread_auth"),
}
needToLookupAccessKey := backendConfig.AccessKey == "" && backendConfig.SasToken == "" && !backendConfig.UseAzureADAuthentication
if backendConfig.ResourceGroupName == "" {
if needToLookupAccessKey {
return backendbase.ErrorAsDiagnostics(fmt.Errorf("One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified"))
}
if backendConfig.LookupBlobEndpoint {
return backendbase.ErrorAsDiagnostics(fmt.Errorf("`resource_group_name` is required when `lookup_blob_endpoint` is set"))
}
}
client, err := buildClient(ctx, backendConfig)
if err != nil {
return backendbase.ErrorAsDiagnostics(err)
}
b.apiClient = client
return nil
}
View on GitHub (pinned to d32a084675)