Concept and mechanism
An Azure management role controls resource operations without automatically granting table access. Inside a database, users, roles, and grants define permitted actions. A contained identity needs the correct database context in its connection. Managed identity avoids distributing passwords but still requires authorization. Networking is another dimension: creating a private endpoint proves neither private resolution from clients nor automatic closure of the public endpoint. Confirm DNS, routes, connection approval, and public network access. Use the appropriate service name and retain TLS validation; switching to an IP or disabling encryption to bypass an error can break the destination identity contract. Diagnose these layers separately before adding privileges.
Guided application
In a fictional incident, an operator can modify a portal resource but SELECT fails. Check SQL identity and grants instead of requesting subscription Owner. For sensitive data, distinguish TDE, which protects storage, from Always Encrypted, which can separate column protection from ordinary engine administration. Drivers, keys, and supported operations belong in the design. Enclaves enable additional capabilities with requirements varying across VBS, SGX, and platforms. The April outline names VBS enclaves; the announced October update uses secure enclaves. That wording change does not make every technology equivalent. Validate the threat model and key path in the actual environment, including behavior after migration or recovery.
SQL Server Contributor in the portal is not equivalent to GRANT SELECT on a table.
Common pitfalls
RBAC as SQL grant; created endpoint as validated network; TDE as protection against every read; universal enclave.
Related topics: Platform, capacity, and migration · Sensitive data and evidence · Query Store and concurrency
Verify each boundary using the actual identity and client.
Reference: Database users and privileges · DP-300 English objectives effective 2026-04-24