Loading...

Public Preview of Transparent Data Encryption and Credential Rotation for Arc SQL Managed Instance

Public Preview of Transparent Data Encryption and Credential Rotation for Arc SQL Managed Instance

We are thrilled to announce the Public Preview of Transparent Data Encryption (TDE) and Service-Managed Credential Rotation for Arc-enabled SQL Managed Instance. With a strong focus on data security and management, this release introduces cutting-edge features that ensure your sensitive information is protected.  

 

Transparent Data Encryption Overview 

 

Azure Arc-enabled SQL Managed Instance now supports a managed solution for encrypting-at-rest all your databases within a managed instance. TDE offers robust encryption to safeguard your data against unauthorized access.  

 

Transparent Data Encryption Modes 

 

There are two modes that a user can specify when using Transparent Data Encryption: Customer-managed and Service-managed. This feature can be enabled via the Kubernetes spec and az CLI. 

 

 

Customer-managed keys (CMK) 

Service-managed keys (SMK) 

Disabled 

Use Cases 

Businesses that would like full control on the certificates encrypting their data. 

Businesses that would like the arc-enabled data controller to manage the certificates for them. 

Businesses would like to manually manage encryption of each database and their managed instance themselves. 

Characteristics 

User managed. Users bring the certificate to encrypt their data. 

Service managed. The service will create the certificate automatically. 

User managed. Users must manually load and enable encryption-at-rest on their managed instances. 

Deployment Process 

Users must create a Kubernetes secret with their certificate, then update their SQL MI Custom Resource spec. 

Users update their SQL MI Custom Resource spec. 

A series of Kubernetes exec commands as well as T-SQL commands for each database. 

 

Service Managed Credential Rotation Overview 

 

Azure Arc-enabled SQL Managed Instance now supports a simple way to rotate some service-managed credentials in your SQL Managed Instance for both the general purpose and business critical service tiers. The primary benefit of credential rotation is enhanced security. By automatically and regularly refreshing access credentials, potential security vulnerabilities due to compromised or outdated credentials are mitigated. This proactive approach significantly reduces the risk of unauthorized access and data breaches, ensuring that only authorized users have valid and up-to-date credentials to access sensitive information or critical systems. 

 

Credential Management 

Credential Types 

Documentation Link 

Service-managed 

Most certificates, logins 

Rotate SQL Managed Instance service-managed credentials (preview) - Azure Arc | Microsoft Learn 

Customer-managed 

TLS certificate 

Rotate certificate Azure Arc-enabled SQL Managed Instance (indirectly connected) โ€“ Azure Arc | Microsoft Learn 

 

In conclusion, the Public Preview release of Transparent Data Encryption (TDE) and Credential Rotation for Arc-enabled SQL Managed Instance is aimed towards bolstering data security and management. With TDE, your sensitive information remains shielded from prying eyes, while Credential Rotation ensures that access credentials are automatically and seamlessly refreshed, providing protection against potential cyber threats. We invite you to take advantage of these cutting-edge features to fortify your data infrastructure and stay one step ahead of evolving security challenges.  

Published on:

Learn more
Azure Arc Blog articles
Azure Arc Blog articles

Azure Arc Blog articles

Share post:

Related posts

Azure Adaptive Cloud Pre-Days at Microsoft Ignite 2024

As the excitement builds for Microsoft Ignite 2024, tech enthusiasts and professionals worldwide are eagerly anticipating the Azure Adaptive C...

1 year ago

Launching the Arc Jumpstart Newsletter: October 2024 Edition

๐Ÿ‘‹ Welcome! We are excited to kick off this monthly newsletter, where you can get the latest updates on everything happening in the Arc Jumpst...

1 year ago

Announcing Public Preview of Windows Server Hotpatch enabled by Azure Arc

Weโ€™re excited to announce the Public Preview of Hotpatch enabled by Azure Arc for Windows Sever 2025 Datacenter and Standard editions!   ...

1 year ago

Public Preview of Azure Container Storage enabled by Azure Arc Edge Volumes

Release Summary  We are thrilled to announce the Public Preview of Azure Container Storage enabled by Azure Arc Edge Volumes, a groundbre...

1 year ago

Introducing ArcBox 3.0 General Availability

Today, the Arc Jumpstart team is excited to announce the general availability of ArcBox 3.0!   Since it was first introduced in 2021, Ar...

2 years ago

CloudCasa for Azure Arc

Azure Arc is a platform that helps users build and develop their applications by extending Azure to their datacenters, edge, or even to multic...

2 years ago

Generally Available: Transition to WS2012 / R2 ESUs enabled by Azure Arc from Volume Licensing

Customers that have enrolled in WS2012/ R2 ESUs through Volume Licensing for Year 1 can transition to Azure Arc for Year 2 of the program. Ext...

2 years ago

Comparing feature sets for AKS enabled by Azure Arc deployment options

This article shows a comparison of features available for the different deployment options under AKS enabled by Azure Arc.    ...

2 years ago

Increasing Security for SQL Server Enabled by Azure Arc

Back in November 2023, the least privileges deployment model was introduced as a public preview. After thorough testing, we are excited to ann...

2 years ago

Five Key Updates on WS2012 ESUs enabled by Azure Arc

We have a myriad of key updates for customers enrolled in WS2012/R2 ESUs enabled by Azure Arc! As we continue to refine and expand the offer, ...

2 years ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts โ€” delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.