Transparent Data Encryption (TDE)

SQLServerCentral Article

Key Rotation in TDE

  • Article

Transparent Data Encryption (TDE) has been around for a long time. It first appeared in SQL Server 2008, and after a rocky start with some bugs, it has become a regularly used feature for many organizations. While not perfect, it does provide some protection and auditors like to see physical protection features being used. It's […]

You rated this post out of 5. Change rating

2019-08-29

15,982 reads

Technical Article

How to Send a TDE Encrypted Backup to Someone Outside Your Organization

  • Article

Once you enable your database to be encrypted with Transparent Data Encryption (TDE), the physical database files, and the database backups are encrypted. If your database and database backup are encrypted, then how can you send the encrypted backup to a person outside your organization?

You rated this post out of 5. Change rating

2018-03-27

2,947 reads

Technical Article

What is the State of My Transparent Data Encrypted Database?

  • Article

When using Transparent Data Encryption, you might wonder “What is the state of my transparent data encrypted database?” Read on to learn the many different states that a transparent data encrypted database might go through.

You rated this post out of 5. Change rating

2018-03-19

2,510 reads

Technical Article

How to Enable Transparent Data Encryption

  • Article

By default, SQL Server does not encrypt data in a SQL Server database in an encrypted format. When SQL Server 2008 was introduced, Microsoft implemented Transparent Data Encryption (TDE). When TDE is enabled on a database SQL Server will encrypt the database as data is written to the disk.

(1)

You rated this post out of 5. Change rating

2018-02-28

2,572 reads

Technical Article

How to Move a TDE Encryption Key to Another SQL Server Instance

  • Article

If you have a database backup of a Transparent Data Encryption (TDE) enabled database, the database backup will contain encrypted data. Because the database backup contains encrypted data you can’t just restore it to any instance. You can only restore the database backup to an instance that contains the same certificate used to originally encrypt the database.

You rated this post out of 5. Change rating

2018-02-20

2,970 reads

External Article

Encrypting SQL Server: Transparent Data Encryption (TDE)

  • Article

Transparent Data Encryption (TDE) encrypts the data within the physical files of the database, the 'data at rest'. Without the original encryption certificate and master key, the data cannot be read when the drive is accessed or the physical media is stolen. The data in unencrypted data files can be read by restoring the files to another server. TDE requires planning but can be implemented without changing the database. Robert Sheldon explains how to implement TDE.

2017-03-24

5,410 reads

Blogs

Microsoft Fabric OneLake Shortcuts: When to Use Them and When Not To

By

An architecture scenario Imagine separate Sales, Finance, Shared Data, and Executive Analytics workspaces. Sales...

SQL Server Security Hardening Guide Using the DoD STIG Checklist

By

Security on your SQL Server is important. That doesn’t need any explaining. But where...

EightKB 2026: Registration is Open!

By

It’s that time of year again! EightKB is back on August 20th at 13:00...

Read the latest Blogs

Forums

Backing Up a DMK

By Steve Jones - SSC Editor

Comments posted to this topic are about the item Backing Up a DMK

The Quiet Part

By Steve Jones - SSC Editor

Comments posted to this topic are about the item The Quiet Part

BIT_COUNT in SQL Server

By john.martin

Comments posted to this topic are about the item BIT_COUNT in SQL Server

Visit the forum

Question of the Day

Backing Up a DMK

In SQL Server 2025, I have a database with a Database Masker Key (DMK). I want to back up this key and keep a copy offline. When do I have to open this key before running the backup?

See possible answers