A T-SQL function that encrypts data using a symmetric key that has already been opened, with an optional authenticator tying the ciphertext to its row. DECRYPTBYKEY does the reverse.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains ENCRYPTBYKEY in context, with comparison tables and the common traps.
Terms in this definition
- T-SQL
The dialect of SQL that Microsoft uses for Azure SQL and SQL Server. Azure Monitor logs are queried with KQL instead.
- Symmetric key
A key that both encrypts and decrypts data, for example AES_256. With cell-level encryption, a certificate protects the key and ENCRYPTBYKEY uses it to encrypt column data.
Related terms
- Column-level encryption
Encrypting values one at a time using a database-held symmetric key and T-SQL functions such as
ENCRYPTBYKEY. Always Encrypted works differently: here, the app itself has to call T-SQL to encrypt and decrypt.