Your company has a strict policy that Azure SQL Database backups must be encrypted with customer-managed keys stored in Azure Key Vault. You configure TDE with AKV integration. After a key rotation, you find that long-running queries start failing with encryption errors. What is the most likely cause?
Trap 1: The service principal used for AKV access has expired.
Permission issues would cause access denied errors, not encryption errors.
Trap 2: The new key is in a different Azure region than the database.
AKV keys can be in any region; region mismatch is not an issue.
Trap 3: The database is using service-managed TDE and cannot switch to…
The error occurred after rotation, not during initial setup.
- A
The service principal used for AKV access has expired.
Why it fails: Permission issues would cause access denied errors, not encryption errors.
- B
The previous key version was disabled or deleted in AKV.
TDE with AKV integration requires every key version protecting the database encryption key to remain accessible. Disabling or deleting the previous version breaks unwrap operations for data still encrypted under it, so long-running queries touching those pages fail with encryption errors.
- C
The new key is in a different Azure region than the database.
Why it fails: AKV keys can be in any region; region mismatch is not an issue.
- D
The database is using service-managed TDE and cannot switch to customer-managed keys.
Why it fails: The error occurred after rotation, not during initial setup.