hashicorp/terraform · error

One of `access_key`, `sas_token`, `use_azuread_auth` and…

Error message

One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified

What it means

Validation error in Backend.Configure when resource_group_name is empty AND none of access_key / sas_token / use_azuread_auth is set. In that combination the backend has no credential for the data plane and no resource group to look one up via ARM, so configuration cannot proceed.

Solutions

  1. Add resource_group_name to the backend block (enables ARM key lookup).
  2. Provide access_key or sas_token directly.
  3. Set use_azuread_auth = true (recommended).
  4. Re-run `terraform init -reconfigure` after fixing.

Example fix

// before
terraform {
  backend "azurerm" {
    storage_account_name = "acct"
    container_name       = "tfstate"
    key                  = "prod.tfstate"
  }
}
// after
terraform {
  backend "azurerm" {
    resource_group_name  = "rg-tfstate"
    storage_account_name = "acct"
    container_name       = "tfstate"
    key                  = "prod.tfstate"
  }
}
Defensive patterns

Strategy: validation

Validate before calling

// Validate the backend block before `terraform init`.
func validateBackendBlock(b BackendConfig) error {
    needToLookupAccessKey := b.AccessKey == "" && b.SasToken == "" && !b.UseAzureADAuthentication
    if b.ResourceGroupName == "" && needToLookupAccessKey {
        return fmt.Errorf("One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified")
    }
    return nil
}

Prevention

When it happens

Trigger: Backend block sets only storage_account_name and container (and key), with no auth method and no resource_group_name. needToLookupAccessKey evaluates true.

Common situations: Operator expects implicit env-based auth (e.g. az login) but forgot that the default path still needs resource_group_name to call ListKeys; minimal backend block copied from a tutorial that omitted auth.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/bdc065fbbea7b5e1. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/azure/backend.go:456

		EnableAuthenticationUsingGitHubOIDC:        enableOidc,
		EnableAuthenticationUsingADOPipelineOIDC:   enableOidc,
	}

	backendConfig := BackendConfig{
		AuthConfig:               authConfig,
		SubscriptionID:           data.String("subscription_id"),
		ResourceGroupName:        data.String("resource_group_name"),
		StorageAccountName:       data.String("storage_account_name"),
		LookupBlobEndpoint:       data.Bool("lookup_blob_endpoint"),
		AccessKey:                data.String("access_key"),
		SasToken:                 data.String("sas_token"),
		UseAzureADAuthentication: data.Bool("use_azuread_auth"),
	}

	needToLookupAccessKey := backendConfig.AccessKey == "" && backendConfig.SasToken == "" && !backendConfig.UseAzureADAuthentication
	if backendConfig.ResourceGroupName == "" {
		if needToLookupAccessKey {
			return backendbase.ErrorAsDiagnostics(fmt.Errorf("One of `access_key`, `sas_token`, `use_azuread_auth` and `resource_group_name` must be specified"))
		}
		if backendConfig.LookupBlobEndpoint {
			return backendbase.ErrorAsDiagnostics(fmt.Errorf("`resource_group_name` is required when `lookup_blob_endpoint` is set"))
		}
	}

	client, err := buildClient(ctx, backendConfig)
	if err != nil {
		return backendbase.ErrorAsDiagnostics(err)
	}

	b.apiClient = client
	return nil
}

View on GitHub (pinned to d32a084675)