hashicorp/terraform · error

subscription id not specified

Error message

subscription id not specified

What it means

Thrown by Azure buildClient in the armAuthRequired block when config.SubscriptionID is still empty after attempting to infer it from an Azure CLI default subscription. ARM calls (listing access keys, looking up the blob endpoint) require a subscription id, and there is no other fallback.

Solutions

  1. Set subscription_id in the azurerm backend block, or export ARM_SUBSCRIPTION_ID.
  2. If relying on Azure CLI inference, run `az login` then `az account set --subscription <id>` in the same shell before running Terraform.
  3. Verify the auth flow actually produces an AzureCliAuthorizer; SP/certificate flows do not carry a default subscription and need it supplied explicitly.
  4. Confirm the subscription id GUID is valid and that the SP has access to it.

Example fix

# before: SP auth, no subscription id
export ARM_CLIENT_ID=...
export ARM_CLIENT_SECRET=...
export ARM_TENANT_ID=...
# error: subscription id not specified -> after
export ARM_SUBSCRIPTION_ID=22222222-2222-2222-2222-222222222222
Defensive patterns

Strategy: validation

Validate before calling

func ensureSubscription(c *BackendConfig) error {
    if c.SubscriptionID != "" { return nil }
    // only CLI auth can infer it; everything else must set it.
    return fmt.Errorf("subscription_id is required (set ARM_SUBSCRIPTION_ID or run 'az account set')")
}

Type guard

null

Try / catch

client, err := azure.NewClient(ctx, cfg)
if err != nil && strings.Contains(err.Error(), "subscription id not specified") {
    // tell the user to export ARM_SUBSCRIPTION_ID or run `az account set`
}

Prevention

When it happens

Trigger: armAuthRequired is true, config.SubscriptionID == "", the resourceManagerAuth is not a CachedAuthorizer wrapping an AzureCliAuthorizer (or it is, but DefaultSubscriptionID is also empty), so the second `if config.SubscriptionID == ""` check fails and returns this error.

Common situations: Service principal auth configured without a subscription_id and the SP flow does not provide one; CLI-based auth expected but `az account set` was never run or the CLI is not logged in; CI assumed the subscription would be auto-detected but used SP auth instead of CLI auth.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/84d3913449799375. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/azure/api_client.go:92

	}

	if armAuthRequired {
		resourceManagerAuth, err := auth.NewAuthorizerFromCredentials(ctx, *config.AuthConfig, config.AuthConfig.Environment.ResourceManager)
		if err != nil {
			return nil, fmt.Errorf("unable to build authorizer for Resource Manager API: %+v", err)
		}

		// When using Azure CLI to auth, the user can leave the "subscription_id" unspecified. In this case the subscription id is inferred from
		// the Azure CLI default subscription.
		if config.SubscriptionID == "" {
			if cachedAuth, ok := resourceManagerAuth.(*auth.CachedAuthorizer); ok {
				if cliAuth, ok := cachedAuth.Source.(*auth.AzureCliAuthorizer); ok && cliAuth.DefaultSubscriptionID != "" {
					config.SubscriptionID = cliAuth.DefaultSubscriptionID
				}
			}
		}
		if config.SubscriptionID == "" {
			return nil, fmt.Errorf("subscription id not specified")
		}

		// Setup the SA client.
		client.storageAccountsClient, err = storageaccounts.NewStorageAccountsClientWithBaseURI(config.AuthConfig.Environment.ResourceManager)
		if err != nil {
			return nil, fmt.Errorf("building Storage Accounts client: %+v", err)
		}
		client.configureClient(client.storageAccountsClient.Client, resourceManagerAuth)

		// Populating the storage account detail
		storageAccountId := commonids.NewStorageAccountID(config.SubscriptionID, config.ResourceGroupName, client.storageAccountName)
		resp, err := client.storageAccountsClient.GetProperties(ctx, storageAccountId, storageaccounts.DefaultGetPropertiesOperationOptions())
		if err != nil {
			return nil, fmt.Errorf("retrieving %s: %+v", storageAccountId, err)
		}
		if resp.Model == nil {
			return nil, fmt.Errorf("retrieving %s: model was nil", storageAccountId)
		}

View on GitHub (pinned to d32a084675)