Enabling Always Encrypted in Azure SQL
Pluralsight Hands-On Lab — Security
At a Glance
| Platform | Pluralsight |
| Category | Azure Data Security |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Windows VM via Remote Desktop, SQL Server Management Studio |
| Completed | 2026 |
Overview
Always Encrypted is an Azure SQL feature that ensures sensitive data is encrypted at rest and in transit, and is never exposed in plaintext to database administrators or backup operators — only the application holds the decryption keys. In this lab, I acted as a cloud data engineer tasked with protecting customer data so that privileged users with direct database access cannot read sensitive columns. I created an Azure SQL database, provisioned a Key Vault to store the column master key, and used the Always Encrypted wizard in SQL Server Management Studio to encrypt the FirstName, MiddleName, and LastName columns on the customer table, then confirmed the data was no longer readable in plaintext.
What I Did
- Created an Azure SQL Server with SQL authentication and a Standard-tier single database (sampledb1) pre-loaded with sample data, with public endpoint access enabled for Azure services
- Provisioned an Azure Key Vault with Standard pricing, vault access policy permission model, and full Key Management and Cryptographic Operations permissions assigned to the lab user
- Connected to the lab VM via Remote Desktop and launched SQL Server Management Studio
- Connected to the Azure SQL Server using SQL Server Authentication and viewed unencrypted customer data in the SalesLT.Customer table
- Launched the Always Encrypted wizard from SSMS, selected the FirstName, MiddleName, and LastName columns, and configured Deterministic encryption for each — chosen over Randomized to preserve support for search and grouping operations
- Configured Azure Key Vault as the column master key store and authenticated to Azure to authorize key creation
- Completed the encryption process and confirmed all three columns now display fully encrypted ciphertext when queried directly from SSMS
← Back to Pluralsight Labs