At-rest encryption of database files and nothing more; any user able to query the database still reads the data in plaintext.
Also called TDE, TDE.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Transparent Data Encryption in context, with comparison tables and the common traps.
Terms in this definition
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- Schema
The middle part of a Unity Catalog name (
catalog.schema.table), grouping tables, views, volumes, functions and models inside a catalog. A grant on it covers everything in it now and later, and nothing inside can be reached withoutUSE SCHEMA. - Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
Related terms
- AES
Short for Advanced Encryption Standard, a symmetric cipher. With TDE, the RSA TDE protector wraps an AES-256 data encryption key.
- FILESTREAM
Lets SQL Server keep varbinary(max) data as ordinary NTFS files that still stay transactionally consistent with the database. TDE doesn't encrypt this data, and ledger tables can't use it.
- Logical server
In Azure SQL, the parent resource for a set of databases, carrying their logins, Entra admin, firewall rules, auditing and TDE configuration. Think of it as a management boundary; it isn't an instance of SQL Server.
- TDE protector
The key that encrypts (wraps) the TDE data encryption key: an asymmetric RSA key the customer manages and keeps in Key Vault or Managed HSM.