Concept and mechanism
Data access requires identity, networking, and operation design. When using SAS, limit resource, permissions, and duration, distribute over HTTPS, and plan expiry and revocation. A user delegation SAS avoids distributing the account key but does not support stored access policies as a service SAS does. An excessively long-lived token still represents exposure. Private endpoints are subresource-specific: Data Lake operations can need both DFS and Blob. Creating a private endpoint should not be treated as proof that public access is blocked; verify actual configuration and behavior. Clients should resolve the service name to the destination appropriate for their path.
Guided application
In SQL, auditing should produce retrievable events with known actions, destination, and time scope. An enabled portal setting does not prove the pipeline wrote evidence. TDE protects files at rest; it does not prevent an authorized user from querying plaintext through the engine. With a customer-managed key, the SQL identity needs protector access and a key lifecycle compatible with recovery. In a fictional incident following assignment removal, restoring required access differs from deleting and recreating a key under the same name. Matching names do not establish matching key material. During RUN handover, document cryptographic dependencies and validate the recovery procedure.
Database unavailable after key access removal: check that dependency before changing client firewalls.
Common pitfalls
SAS as nontransferable identity; one endpoint for every service; TDE as SQL authorization; key name as cryptographic material.
Related topics: Identity, access, and governance · Private networks and diagnosis · Agent and AI security
Protect data and keep the dependencies needed to read it recoverable.
Reference: Storage private endpoints and subresources · SC-500 guide updated 2026-05-13; Microsoft security documentation accessed 2026-09-30