Public Preview of Transparent Data Encryption and Credential Rotation for Arc SQL Managed Instance
We are thrilled to announce the Public Preview of Transparent Data Encryption (TDE) and Service-Managed Credential Rotation for Arc-enabled SQL Managed Instance. With a strong focus on data security and management, this release introduces cutting-edge features that ensure your sensitive information is protected.
Transparent Data Encryption Overview
Azure Arc-enabled SQL Managed Instance now supports a managed solution for encrypting-at-rest all your databases within a managed instance. TDE offers robust encryption to safeguard your data against unauthorized access.
Transparent Data Encryption Modes
There are two modes that a user can specify when using Transparent Data Encryption: Customer-managed and Service-managed. This feature can be enabled via the Kubernetes spec and az CLI.
|
|
Customer-managed keys (CMK) |
Service-managed keys (SMK) |
Disabled |
|
Use Cases |
Businesses that would like full control on the certificates encrypting their data. |
Businesses that would like the arc-enabled data controller to manage the certificates for them. |
Businesses would like to manually manage encryption of each database and their managed instance themselves. |
|
Characteristics |
User managed. Users bring the certificate to encrypt their data. |
Service managed. The service will create the certificate automatically. |
User managed. Users must manually load and enable encryption-at-rest on their managed instances. |
|
Deployment Process |
Users must create a Kubernetes secret with their certificate, then update their SQL MI Custom Resource spec. |
Users update their SQL MI Custom Resource spec. |
A series of Kubernetes exec commands as well as T-SQL commands for each database. |
Service Managed Credential Rotation Overview
Azure Arc-enabled SQL Managed Instance now supports a simple way to rotate some service-managed credentials in your SQL Managed Instance for both the general purpose and business critical service tiers. The primary benefit of credential rotation is enhanced security. By automatically and regularly refreshing access credentials, potential security vulnerabilities due to compromised or outdated credentials are mitigated. This proactive approach significantly reduces the risk of unauthorized access and data breaches, ensuring that only authorized users have valid and up-to-date credentials to access sensitive information or critical systems.
|
Credential Management |
Credential Types |
Documentation Link |
|
Service-managed |
Most certificates, logins |
Rotate SQL Managed Instance service-managed credentials (preview) - Azure Arc | Microsoft Learn |
|
Customer-managed |
TLS certificate |
In conclusion, the Public Preview release of Transparent Data Encryption (TDE) and Credential Rotation for Arc-enabled SQL Managed Instance is aimed towards bolstering data security and management. With TDE, your sensitive information remains shielded from prying eyes, while Credential Rotation ensures that access credentials are automatically and seamlessly refreshed, providing protection against potential cyber threats. We invite you to take advantage of these cutting-edge features to fortify your data infrastructure and stay one step ahead of evolving security challenges.
Published on:
Learn moreRelated posts
Azure Adaptive Cloud Pre-Days at Microsoft Ignite 2024
As the excitement builds for Microsoft Ignite 2024, tech enthusiasts and professionals worldwide are eagerly anticipating the Azure Adaptive C...
Launching the Arc Jumpstart Newsletter: October 2024 Edition
๐ Welcome! We are excited to kick off this monthly newsletter, where you can get the latest updates on everything happening in the Arc Jumpst...
Announcing Public Preview of Windows Server Hotpatch enabled by Azure Arc
Weโre excited to announce the Public Preview of Hotpatch enabled by Azure Arc for Windows Sever 2025 Datacenter and Standard editions! ...
Public Preview of Azure Container Storage enabled by Azure Arc Edge Volumes
Release Summary We are thrilled to announce the Public Preview of Azure Container Storage enabled by Azure Arc Edge Volumes, a groundbre...
Introducing ArcBox 3.0 General Availability
Today, the Arc Jumpstart team is excited to announce the general availability of ArcBox 3.0! Since it was first introduced in 2021, Ar...
CloudCasa for Azure Arc
Azure Arc is a platform that helps users build and develop their applications by extending Azure to their datacenters, edge, or even to multic...
Generally Available: Transition to WS2012 / R2 ESUs enabled by Azure Arc from Volume Licensing
Customers that have enrolled in WS2012/ R2 ESUs through Volume Licensing for Year 1 can transition to Azure Arc for Year 2 of the program. Ext...
Comparing feature sets for AKS enabled by Azure Arc deployment options
This article shows a comparison of features available for the different deployment options under AKS enabled by Azure Arc. ...
Increasing Security for SQL Server Enabled by Azure Arc
Back in November 2023, the least privileges deployment model was introduced as a public preview. After thorough testing, we are excited to ann...
Five Key Updates on WS2012 ESUs enabled by Azure Arc
We have a myriad of key updates for customers enrolled in WS2012/R2 ESUs enabled by Azure Arc! As we continue to refine and expand the offer, ...