← Azure SQL administration: migration and operations
02 / 8 · 45 MIN

Identity, networking, and encryption

Separate Azure management, SQL authorization, and data protection.

Concept and mechanism

An Azure management role controls resource operations without automatically granting table access. Inside a database, users, roles, and grants define permitted actions. A contained identity needs the correct database context in its connection. Managed identity avoids distributing passwords but still requires authorization. Networking is another dimension: creating a private endpoint proves neither private resolution from clients nor automatic closure of the public endpoint. Confirm DNS, routes, connection approval, and public network access. Use the appropriate service name and retain TLS validation; switching to an IP or disabling encryption to bypass an error can break the destination identity contract. Diagnose these layers separately before adding privileges.

Guided application

In a fictional incident, an operator can modify a portal resource but SELECT fails. Check SQL identity and grants instead of requesting subscription Owner. For sensitive data, distinguish TDE, which protects storage, from Always Encrypted, which can separate column protection from ordinary engine administration. Drivers, keys, and supported operations belong in the design. Enclaves enable additional capabilities with requirements varying across VBS, SGX, and platforms. The April outline names VBS enclaves; the announced October update uses secure enclaves. That wording change does not make every technology equivalent. Validate the threat model and key path in the actual environment, including behavior after migration or recovery.

IN PRACTICE

SQL Server Contributor in the portal is not equivalent to GRANT SELECT on a table.

Common pitfalls

RBAC as SQL grant; created endpoint as validated network; TDE as protection against every read; universal enclave.

Related topics: Platform, capacity, and migration · Sensitive data and evidence · Query Store and concurrency

Take this idea with you

Verify each boundary using the actual identity and client.

Create account

Reference: Database users and privileges · DP-300 English objectives effective 2026-04-24