A key store local to Windows that can hold Always Encrypted column master keys. Since App Service managed identities cannot access it, Key Vault is used in that case.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Windows certificate store in context, with comparison tables and the common traps.
Terms in this definition
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - LSDOU
The sequence in which Group Policy is processed: the local policy first, followed by site, domain and organisational unit policies. The nearest, last-processed setting takes effect unless Enforced or Block Inheritance alters that.
- Always Encrypted
Client-side encryption of SQL columns using keys never revealed to the database engine, meaning cloud administrators and DBAs only ever see ciphertext.
- App Service
Managed PaaS hosting for web apps and Web App for Containers, run in a sandbox without OS access. Deployment slots and autoscale start at the Standard tier.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
Related terms
- Column master key
Protects the column encryption keys in Always Encrypted. It never lives in the database itself but in Azure Key Vault or the Windows certificate store, and client apps need permission to use it.
- Key Vault VM extension
Extension for VMs that checks Key Vault periodically and installs newer versions of watched certificates into a Linux path or the Windows certificate store. Keys and secrets aren't synchronised.