← AZ-500: Azure security, historical path
AZ-500 and Azure Security Engineer Associate retired August31,2026. Independent historical content without Microsoft affiliation, accreditation, or certification award. SC-500 has its own syllabus. Editorial review without independent specialist verification. No live Azure changes, access policies, or real containment actions were executed. Fictional cases do not represent internal BNP Paribas policies. Trademarks belong to their respective owners.
04 / 6 · 40 MIN

Data protection and use

Choose controls according to threat and legitimate operation.

Concept and mechanism

Reading Storage account properties is not equivalent to reading blobs through an Entra token. The identity needs the appropriate data role at minimum scope, with time and evidence for propagation. For temporary access, limit SAS resource, operations, and lifetime and treat it as a credential. An account key or year-long writable SAS does not match a one-hour read. For retention, a locked immutable policy cannot be shortened to free space. Legal hold preserves data until explicit hold removal; it differs from a known retention deadline. These commitments should be reviewed before locking configuration.

Guided application

In SQL, start with the specific threat. TDE protects data at rest and lets the engine decrypt pages for authorized queries. Dynamic data masking changes presentation for covered users, but administrators such as db_owner can see unmasked values. If the requirement separates database administration from reading sensitive columns, assess Always Encrypted, key protection, and client support. The traditional model encrypts at the client and limits operations on encrypted columns. Secure enclaves extend some operations in a protected server region and should be treated as a specific model. Validate queries, performance, recovery, and key access to preserve legitimate application function without inadvertently expanding the trust boundary.

IN PRACTICE

The DBA sees a column with TDE and masking active. This does not prove failed at-rest encryption; it shows the chosen controls do not meet the required separation.

Common pitfalls

Management Reader treated as Blob Data Reader; masking treated as encryption; locked retention treated as freely reversible.

Related topics: Identity and temporary privilege · Network boundaries and private access · Compute and operational access

Take this idea with you

Connect threat, control, privilege, and functionality before approving design.

Create account

Reference: Always Encrypted and enclave boundaries · AZ-500 objectives2026-01-22; retired2026-08-31