Enabling Always Encrypted in Azure SQL

Pluralsight Hands-On Lab — Azure Data Security

Enabling Always Encrypted in Azure SQL

Pluralsight Hands-On Lab — Security


At a Glance

PlatformPluralsight
CategoryAzure Data Security
Lab TypeGuided + Challenge Mode
EnvironmentAzure Portal, Windows VM via Remote Desktop, SQL Server Management Studio
Completed2026

Overview

Always Encrypted is an Azure SQL feature that ensures sensitive data is encrypted at rest and in transit, and is never exposed in plaintext to database administrators or backup operators — only the application holds the decryption keys. In this lab, I acted as a cloud data engineer tasked with protecting customer data so that privileged users with direct database access cannot read sensitive columns. I created an Azure SQL database, provisioned a Key Vault to store the column master key, and used the Always Encrypted wizard in SQL Server Management Studio to encrypt the FirstName, MiddleName, and LastName columns on the customer table, then confirmed the data was no longer readable in plaintext.


What I Did


← Back to Pluralsight Labs