Public-key encryption algorithm. For storage customer-managed keys, RSA and RSA-HSM keys of 2048, 3072 or 4096 bits are accepted; a SQL TDE protector cannot use 4096 bits.
Also called Rivest–Shamir–Adleman.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500AZ-400AZ-802MD-102
Each book explains RSA in context, with comparison tables and the common traps.
Terms in this definition
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - Customer-managed keys
RSA or RSA-HSM key of 2048, 3072 or 4096 bits that you keep in Key Vault or Managed HSM to wrap a storage account's encryption key. You can switch it on later, except for tables and queues, whose CMK support must be chosen at creation.
- BITS
A Windows service for downloads. Delivery Optimization hands downloads to it in Bypass mode (100), a mode now deprecated for Windows 11 that can cause failures with error 0x80d03002.
- Serverless
Compute tier for single Azure SQL databases that scales automatically, pauses when idle and charges by the second. It is offered in General Purpose and Hyperscale, not Business Critical, and reserved capacity does not apply.
- TDE protector
The key that encrypts (wraps) the TDE data encryption key: an asymmetric RSA key the customer manages and keeps in Key Vault or Managed HSM.
Related terms
- AES
Short for Advanced Encryption Standard, a symmetric cipher. With TDE, the RSA TDE protector wraps an AES-256 data encryption key.
- Customer-managed keys (Azure AI Search)
Adds a further encryption layer to Azure AI Search, protecting indexes and synonym maps with an RSA key you hold in Key Vault or Managed HSM, which the service reaches using its managed identity. Expect queries up to 30-60% slower and no added capacity.
- Key
RSA or EC key held in Key Vault, which carries out operations like signing, encryption and key wrapping for you. Normally its private part never leaves the vault.
- Key encryption key
Optional Key Vault RSA key whose job is to wrap, or encrypt, a second encryption key such as the secret used by Azure Disk Encryption. Its versioned key URL identifies it.
- Key Vault Standard
Lower Key Vault tier, offering software-protected RSA and EC keys at FIPS 140 Level 1. Keys backed by an HSM require Premium, though key rotation policies are available on either tier.