transparent Data Encryption Key Vault Key Id
The fully versioned Key Vault
Key
URL (e.g. 'https://<YourVaultName>.vault.azure.net/keys/<YourKeyName>/<YourKeyVersion>
) to be used as the Customer Managed Key
(CMK/BYOK) for the Transparent Data Encryption
(TDE) layer.
Note: To successfully deploy a
Microsoft SQL Server
in CMK/BYOK TDE theKey Vault
must haveSoft-delete
andpurge protection
enabled to protect from data loss due to accidental key and/or key vault deletion. TheKey Vault
and theMicrosoft SQL Server
User Managed Identity Instance
must belong to the sameAzure Active Directory
tenant
. Note: Cross-tenantKey Vault
andMicrosoft SQL Server
interactions are not supported. Please see the product documentation for more information. Note: When using a firewall with aKey Vault
, you must enable the optionAllow trusted Microsoft services to bypass the firewall
.