hashicorp/terraform · error
subscription id not specified
Error message
subscription id not specified
What it means
Thrown by Azure buildClient in the armAuthRequired block when config.SubscriptionID is still empty after attempting to infer it from an Azure CLI default subscription. ARM calls (listing access keys, looking up the blob endpoint) require a subscription id, and there is no other fallback.
Solutions
- Set subscription_id in the azurerm backend block, or export ARM_SUBSCRIPTION_ID.
- If relying on Azure CLI inference, run `az login` then `az account set --subscription <id>` in the same shell before running Terraform.
- Verify the auth flow actually produces an AzureCliAuthorizer; SP/certificate flows do not carry a default subscription and need it supplied explicitly.
- Confirm the subscription id GUID is valid and that the SP has access to it.
Example fix
# before: SP auth, no subscription id export ARM_CLIENT_ID=... export ARM_CLIENT_SECRET=... export ARM_TENANT_ID=... # error: subscription id not specified -> after export ARM_SUBSCRIPTION_ID=22222222-2222-2222-2222-222222222222
Defensive patterns
Strategy: validation
Validate before calling
func ensureSubscription(c *BackendConfig) error {
if c.SubscriptionID != "" { return nil }
// only CLI auth can infer it; everything else must set it.
return fmt.Errorf("subscription_id is required (set ARM_SUBSCRIPTION_ID or run 'az account set')")
} Type guard
null
Try / catch
client, err := azure.NewClient(ctx, cfg)
if err != nil && strings.Contains(err.Error(), "subscription id not specified") {
// tell the user to export ARM_SUBSCRIPTION_ID or run `az account set`
} Prevention
- Always set ARM_SUBSCRIPTION_ID in CI, even when you think it can be inferred.
- For CLI-based auth, verify `az account show` returns the expected subscription before running terraform.
- Treat subscription_id as a required field when using SP/certificate auth.
When it happens
Trigger: armAuthRequired is true, config.SubscriptionID == "", the resourceManagerAuth is not a CachedAuthorizer wrapping an AzureCliAuthorizer (or it is, but DefaultSubscriptionID is also empty), so the second `if config.SubscriptionID == ""` check fails and returns this error.
Common situations: Service principal auth configured without a subscription_id and the SP flow does not provide one; CLI-based auth expected but `az account set` was never run or the CLI is not logged in; CI assumed the subscription would be auto-detected but used SP auth instead of CLI auth.
Related errors
- building Storage Accounts client: %+v
- unable to build authorizer for Resource Manager API: %+v
- populating details for
- retrieving : model was nil
- retrieving : %+v
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/84d3913449799375.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/azure/api_client.go:92
}
if armAuthRequired {
resourceManagerAuth, err := auth.NewAuthorizerFromCredentials(ctx, *config.AuthConfig, config.AuthConfig.Environment.ResourceManager)
if err != nil {
return nil, fmt.Errorf("unable to build authorizer for Resource Manager API: %+v", err)
}
// When using Azure CLI to auth, the user can leave the "subscription_id" unspecified. In this case the subscription id is inferred from
// the Azure CLI default subscription.
if config.SubscriptionID == "" {
if cachedAuth, ok := resourceManagerAuth.(*auth.CachedAuthorizer); ok {
if cliAuth, ok := cachedAuth.Source.(*auth.AzureCliAuthorizer); ok && cliAuth.DefaultSubscriptionID != "" {
config.SubscriptionID = cliAuth.DefaultSubscriptionID
}
}
}
if config.SubscriptionID == "" {
return nil, fmt.Errorf("subscription id not specified")
}
// Setup the SA client.
client.storageAccountsClient, err = storageaccounts.NewStorageAccountsClientWithBaseURI(config.AuthConfig.Environment.ResourceManager)
if err != nil {
return nil, fmt.Errorf("building Storage Accounts client: %+v", err)
}
client.configureClient(client.storageAccountsClient.Client, resourceManagerAuth)
// Populating the storage account detail
storageAccountId := commonids.NewStorageAccountID(config.SubscriptionID, config.ResourceGroupName, client.storageAccountName)
resp, err := client.storageAccountsClient.GetProperties(ctx, storageAccountId, storageaccounts.DefaultGetPropertiesOperationOptions())
if err != nil {
return nil, fmt.Errorf("retrieving %s: %+v", storageAccountId, err)
}
if resp.Model == nil {
return nil, fmt.Errorf("retrieving %s: model was nil", storageAccountId)
}View on GitHub (pinned to d32a084675)