Concept and mechanism
Reading Storage account properties is not equivalent to reading blobs through an Entra token. The identity needs the appropriate data role at minimum scope, with time and evidence for propagation. For temporary access, limit SAS resource, operations, and lifetime and treat it as a credential. An account key or year-long writable SAS does not match a one-hour read. For retention, a locked immutable policy cannot be shortened to free space. Legal hold preserves data until explicit hold removal; it differs from a known retention deadline. These commitments should be reviewed before locking configuration.
Guided application
In SQL, start with the specific threat. TDE protects data at rest and lets the engine decrypt pages for authorized queries. Dynamic data masking changes presentation for covered users, but administrators such as db_owner can see unmasked values. If the requirement separates database administration from reading sensitive columns, assess Always Encrypted, key protection, and client support. The traditional model encrypts at the client and limits operations on encrypted columns. Secure enclaves extend some operations in a protected server region and should be treated as a specific model. Validate queries, performance, recovery, and key access to preserve legitimate application function without inadvertently expanding the trust boundary.
The DBA sees a column with TDE and masking active. This does not prove failed at-rest encryption; it shows the chosen controls do not meet the required separation.
Common pitfalls
Management Reader treated as Blob Data Reader; masking treated as encryption; locked retention treated as freely reversible.
Related topics: Identity and temporary privilege · Network boundaries and private access · Compute and operational access
Connect threat, control, privilege, and functionality before approving design.
Reference: Always Encrypted and enclave boundaries · AZ-500 objectives2026-01-22; retired2026-08-31