A reviewer checklist treats “disable MI public endpoint,” “enable TDE,” and “set a Microsoft Entra admin” as one networking task. Which items belong in the Domain 2 network-security configuration for Azure SQL Managed Instance?
Select an answer to reveal the explanation.
Short Explanation
Networking for MI is public-endpoint off plus subnet NSG/VNet injection. TDE, Entra admin, masking, and Always Encrypted are a different checklist—don’t mash them into one networking task.
Full Explanation
Plan and implement network security for Azure SQL Managed Instance covers VNet injection, subnet NSG/UDR, and public-endpoint state. Transparent Data Encryption, Microsoft Entra database authentication, auditing, dynamic masking, and Always Encrypted are data-security controls outside that networking skill. Treating encryption or Entra admin as substitutes for disabling the public endpoint and maintaining MI network placement mixes domains and leaves the instance exposed at the network edge.