Where each Azure SQL data protection feature works and who it protects data from.
From Ultra Transcenders SC-500 by Tony Rough (publishing soon)
Always Encrypted protects individual columns so that even database administrators never see plaintext. It is the choice when data owners must be kept apart from the people who run the database.
Common trap: Giving developers both the column encryption key and the column master key - they need credentials and the CMK only; the CEK is protected by the CMK and delivered by the database.
Common trap: Generating a key on an HSM device to let apps use the column master key - generating a key doesn’t authorise any identity to use it; a Key Vault access policy does.
| Encryption type | Behaviour | Use for |
|---|---|---|
| Deterministic | Same plaintext always gives the same ciphertext, so it supports point lookups, equality joins, grouping and indexing. It can reveal patterns. | Exact-match values such as government ID numbers |
| Randomized | More secure; no equality operations | Data not searched by exact value, such as free-text comments |
image data type can’t be encrypted with Always Encrypted.This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · Free SC-500 glossary · All SC-500 study notes
How PIM activation, approval, maximum duration and notifications work, and what each role setting controls.
How a Conditional Access policy is built and how multiple policies combine.
Why control-plane roles can't read secrets, and which Key Vault role or access policy each task needs.
What Deny, Audit, Append, Modify and DeployIfNotExists do, and when you need a remediation task and managed identity.
Account keys, account and service SAS, user delegation SAS and Entra RBAC compared by scope and revocability.
How security admin rules are evaluated before NSGs, and when to use Allow, Deny or Always allow.
How JIT locks management ports and opens them on request, with the plan and permissions it needs.