Auditors want the canal authority to hold the TDE protector for lock-lab Azure SQL. What change meets that requirement without turning this into Key Vault administration?
Select an answer to reveal the explanation.
Short Explanation
Service-managed TDE is Microsoft holding the protector. Point SQL at your Key Vault or Managed HSM key and let the SQL identity unwrap it—that’s customer-managed TDE, not a vault redesign project.
Full Explanation
Azure SQL can use a service-managed TDE protector or a customer-managed key stored in Azure Key Vault or Managed HSM. Configuring the logical server or managed instance to use the CMK, with the SQL managed identity permitted to unwrap the key, satisfies customer key custody for TDE. Detailed Key Vault network hardening, rotation schedules, and backup of vault objects are Domain 4 administration tasks; this item focuses on SQL consuming the protector.