transparent Data Encryption Key Vault Key Id
The fully versioned Key Vault Key URL (e.g. 'https://<YourVaultName>.vault.azure.net/keys/<YourKeyName>/<YourKeyVersion>) to be used as the Customer Managed Key(CMK/BYOK) for the Transparent Data Encryption(TDE) layer.
NOTE: To successfully deploy a
Microsoft SQL Serverin CMK/BYOK TDE theKey Vaultmust haveSoft-deleteandpurge protectionenabled to protect from data loss due to accidental key and/or key vault deletion. TheKey Vaultand theMicrosoft SQL ServerUser Managed Identity Instancemust belong to the sameAzure Active Directorytenant. NOTE: Cross-tenantKey VaultandMicrosoft SQL Serverinteractions are not supported. Please see the product documentation for more information. NOTE: When using a firewall with aKey Vault, you must enable the optionAllow trusted Microsoft services to bypass the firewall.