Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Encryption in context, with comparison tables and the common traps.
Terms in this definition
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - TURN
If a direct link can't be made, RDP Shortpath for Windows 365 relays UDP traffic via Microsoft servers on port 3478 instead.
- Hashing
A one-way function that converts data of any size into a fixed-length digest. Identical input always yields the identical digest, which makes it useful for detecting tampering and for storing passwords (usually salted); unlike encryption, the original cannot be recovered.
Related terms
- AD RMS
Active Directory Rights Management Services, Microsoft's older rights management server run on premises. Organisations still relying on it have to move to Azure Rights Management before Purview Message Encryption can be used.
- Always Encrypted
Client-side encryption of SQL columns using keys never revealed to the database engine, meaning cloud administrators and DBAs only ever see ciphertext.
- az cognitiveservices account create
Azure CLI command creating a Foundry Tools or Foundry resource based on
--location,--skuand--kind. Customer-managed key configuration belongs in--encryption;--assign-identitymerely creates a managed identity. - Azure Files
Azure's managed file shares over SMB or NFS. There is no Archive tier, and a single encryption key applies across the whole storage account.
- Azure Rights Management
The service that does the actual encrypting behind sensitivity labels, message encryption and DKE in Purview Information Protection, attaching usage rights to protected content. Newer tenants get it switched on automatically; older ones turn it on with PowerShell.
- BitLocker
Full-volume encryption built into Windows; drives used with Azure Import/Export are protected with AES-256 BitLocker.
- BYOK
Customer-managed key approach where the key lives in your own Key Vault, serving for instance as the TDE protector or as a storage account's encryption key.
- Column master key
Protects the column encryption keys in Always Encrypted. It never lives in the database itself but in Azure Key Vault or the Windows certificate store, and client apps need permission to use it.