Configure Data Masking in Azure SQL Database
Pluralsight Hands-On Lab — Security
At a Glance
| Platform | Pluralsight |
| Category | Azure Data Security |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Azure SQL Query Editor |
| Completed | 2026 |
Overview
Dynamic Data Masking in Azure SQL limits sensitive data exposure by masking it for non-privileged users at query time, without changing the underlying data. In this lab, I created an Azure SQL database pre-loaded with sample data, configured a masking rule on the EmailAddress column using the Email masking format, created a non-admin database user, and verified that the masked user saw obfuscated email addresses while the data itself remained unaltered in the database.
What I Did
- Created an Azure SQL Server with SQL authentication and a Standard-tier single database (sampledb1) pre-loaded with sample data, with public endpoint access enabled for the current client IP
- Navigated to Dynamic Data Masking under the Security section and added a masking rule on the SalesLT.Customer table targeting the EmailAddress column with the Email masking format (aXXX@XXXX.com)
- Saved the masking rule and opened the Query Editor, authenticating as cloud_user
- Created a non-admin database user and granted it the db_datareader role using T-SQL
- Switched login to the non_admin user and ran a SELECT query on FirstName, LastName, and EmailAddress
- Confirmed the EmailAddress column was masked in the query results, demonstrating that Dynamic Data Masking enforces column-level data obfuscation for non-privileged users without modifying stored data
← Back to Pluralsight Labs