Data Security - Microsoft SQL Server Blog http://approjects.co.za/?big=en-us/sql-server/blog/topic/data-security/ Official News from Microsoft’s Information Platform Tue, 14 Jul 2026 14:32:31 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.5 http://approjects.co.za/?big=en-us/sql-server/blog/wp-content/uploads/2018/08/cropped-cropped-microsoft_logo_element-150x150.png Data Security - Microsoft SQL Server Blog http://approjects.co.za/?big=en-us/sql-server/blog/topic/data-security/ 32 32 SQL Server 2016 end of support is here: Plan your next steps http://approjects.co.za/?big=en-us/sql-server/blog/2026/07/14/sql-server-2016-end-of-support-is-here-plan-your-next-steps/ Tue, 14 Jul 2026 16:00:00 +0000 http://approjects.co.za/?big=en-us/sql-server/blog/?p=51780 See what changes as SQL Server 2016 reaches end of support. Choose between cloud migration, upgrading SQL Server, and Extended Security Updates (ESU).

The post SQL Server 2016 end of support is here: Plan your next steps appeared first on Microsoft SQL Server Blog.

]]>

As of today, July 14, 2026, SQL Server 2016 has reached end of support.

For the past decade, SQL Server 2016 has helped organizations run mission-critical applications and support the data needs of their business. Whether it was end-to-end encryption with Always Encrypted or performance improvements with In-Memory OLTP, SQL Server 2016 was shaped by evolving data platform needs and what we heard directly from customers like you.

Last year, we shared guidance on how to prepare for this milestone: Protect and modernize SQL Server 2016 workloads with Microsoft. Now, after 10 years of powering innovation, the focus shifts to what comes next.

What does end of support mean for SQL Server 2016?

Microsoft Lifecycle Policy provides 10 years of support for SQL Server releases. With SQL Server 2016 now at the end of extended support, Microsoft no longer provides regular security updates or technical support for the product.

Continuing to run SQL Server 2016 without a plan can increase security and compliance risk, especially for business-critical applications and regulated workloads. These risks are further amplified in an AI-accelerated threat landscape, where increasingly automated attack techniques make unsupported systems more vulnerable over time.

The next step is to understand your database environment—including application dependencies, business criticality, performance needs, and modernization readiness—and use this to plan an effective transition.

Beyond end of support: Setting up your data platform for what’s next

For organizations running SQL Server 2016, this transition is an opportunity to improve how your database environment operates. Moving to a modern platform can help reduce operational overhead, avoid recurring upgrade cycles, and simplify database management. It can also support new scenarios such as advanced analytics and AI-driven applications built on operational data.

Organizations are already taking action by moving to Azure SQL or upgrading their SQL Server. The Mediterranean Shipping Company (MSC) upgraded to SQL Server 2025 to modernize its SQL Server deployment and streamline how operational data flows into Microsoft Fabric, enabling faster analytics and data-driven decision-making across its global operations.

SQL Server plays a key role in powering our systems, enabling us to operate at scale and deliver on our promise to customers everywhere.

—Javier Villegas, IT Director for Database Administration and Business Intelligence Services, MSC

Assessing your options for end-of-support workloads

For organizations that still run on SQL Server 2016, there are three paths that help you stay protected while planning the next phase of your data platform modernization:

  1. Move to Azure SQL: Modernize your data platform using Azure SQL, helping you reduce operational overhead and remove the need for ongoing upgrades. (Best to avoid future upgrade cycles.)
  2. Upgrade to SQL Server 2025: Move to the latest version of SQL Server with enhanced performance, security, and AI capabilities. (Best for keeping your databases on premises or in hybrid cloud.)
  3. Deploy Extended Security Updates (ESU): Get critical security updates for SQL Server 2016 while you’re planning a transition. (Best for short-term protection while planning next steps.)

Each path offers a way to maintain security and compliance while planning long-term business and infrastructure goals. Here’s what each of these options would mean in practice:

Option 1: Move to Azure SQL

Moving to Azure SQL provides a managed approach to updating your SQL Server environment. Azure SQL platform-as-a-service (PaaS) services handle patching and backups, provide high availability, and come with built-in version updates, allowing your team to focus less on infrastructure management and more on delivering value.

For many SQL Server 2016 workloads, Azure SQL PaaS provides a path to reduce ongoing maintenance and automate resiliency, scalability, and security. With strong backward compatibility, applications can be migrated with minimal changes in most scenarios—and where updates are required, GitHub Copilot can help accelerate code changes and modernization efforts.

Azure supports multiple options depending on your migration and modernization goals:

  1. Azure SQL Database: A managed database service designed for modern applications. Azure SQL Database Hyperscale enables independent scaling of compute and storage to handle growing data and workloads without changing your application. (Choose this if you don’t need instance-level features and want a simpler, app-focused model that can flexibly scale as your data grows.)
  2. Azure SQL Managed Instance: A SQL Server-compatible service that supports your existing workloads with minimal changes, enabling easier migration and reducing the need to manage your infrastructure. (Choose this if you want the closest PaaS experience to SQL Server with minimal application changes.)
  3. SQL Server on Azure Virtual Machines: A flexible option for running SQL Server in Azure while retaining full control over your SQL environment and operating system, including custom configurations and dependencies. (Choose this if you use software, configurations, or third-party components that require a specific SQL Server version or instance-level control of your SQL Server.)

Frontier Accelerate for Databases

Reduce the cost of migration by combining Microsoft-funded delivery support, Azure credits, and investment programs.

Person, in an office, standing in front of monitors.

Option 2: Upgrade to SQL Server 2025

Upgrading to SQL Server 2025 allows you to stay on a supported platform while bringing modern capabilities directly into your existing on-premises or hybrid environments.

SQL Server 2025 is built to support evolving application and data needs, helping teams modernize while preparing for AI-driven scenarios. It includes new and improved capabilities such as:

  • Performance and engine improvements: Optimizations across query processing, indexing, and concurrency help improve performance and stability for high-volume transactional workloads.
  • Security and data protection: Built on the existing SQL Server security model with continued investments in encryption, access control, and compliance support for regulated environments.
  • Built-in AI: Comes with native support for vector search and semantic workflows, enabling AI-driven applications directly on operational data without requiring separate data pipelines.
  • Integration with Microsoft Fabric: Enables mirroring of operational data into analytics environments for near real-time insights, without impacting core transactional workloads.

This path is especially relevant for organizations powering large-scale applications or complex data environments where control, performance, and consistency are essential. It allows you to modernize in place, retain your existing infrastructure, and prepare your platform for the next generation of applications without requiring the shift to a new operating model.

Option 3: Deploy Extended Security Updates (ESU)

Some migrations take time, and we understand that not every environment can move immediately. Extended Security Updates (ESU) provide a short-term option to maintain security coverage for SQL Server 2016 after end of support, helping reduce risk while you plan and execute your next step.

Extended Security Updates are available for workloads running in Azure, including SQL Server on Azure Virtual Machines and Azure VMware Solution, and for on-premises and multi-cloud environments through Azure Arc. They are offered as a paid program to extend security coverage while modernization work is underway.

This option is best suited for environments with application dependencies, testing requirements, or migration complexity that require additional time. Extended Security Updates are designed as a temporary bridge that helps you maintain your existing operations while you move to a supported platform like Azure SQL or SQL Server 2025.

Take the next step

As you plan this transition, there are clear paths to stay secure and move forward based on your environment and priorities. Whether you choose to modernize on Azure, upgrade to SQL Server 2025, or use Extended Security Updates as a bridge, taking a structured approach will allow you to reduce risk and ensure continuity.

If you need help evaluating your options or getting started, reach out to your Microsoft representative to explore the right path forward for your environment.

Resources

Explore the following resources to help you plan your next steps:

Migrate SQL Server workloads to Azure

Upgrade SQL Server to a supported version

Extended Security Updates (ESU)

The post SQL Server 2016 end of support is here: Plan your next steps appeared first on Microsoft SQL Server Blog.

]]>
Why migrate Windows Server and SQL Server to Azure: ROI, innovation, and free offers http://approjects.co.za/?big=en-us/sql-server/blog/2024/04/25/why-migrate-windows-server-and-sql-server-to-azure-roi-innovation-and-free-offers/ Thu, 25 Apr 2024 15:00:00 +0000 Learn more on how we're connecting with customers talking about the value of migration.

The post Why migrate Windows Server and SQL Server to Azure: ROI, innovation, and free offers appeared first on Microsoft SQL Server Blog.

]]>
Hey everyone!  

We’ve been on the road the last couple of weeks at MVP Summit, SQLBits and Fabric Con, connecting with customers talking about the value of migration and modernization. We want to dig into specifically, how Azure can deliver real business value through cost optimization and streamlined productivity for their Windows Server and SQL Server deployments when they migrate to Azure. 

We’ve helped countless organizations migrate their SQL Server and Windows workloads to Azure a critical 1st step in any transformation initiative. The move can help improve cybersecurity posture and business continuity, boost productivity, and lay the foundation for AI and other highly scalable data innovations, while automating updates, backups, and other time-consuming IT tasks. 

Modernize and lower total cost of ownership (TCO) 

Migration is a business strategy that pays off. In The Business Value of Microsoft Azure SQL Database and Azure SQL Managed Instance Workload,1 organizations that migrated to Azure SQL Managed Instance and Microsoft Azure SQL Database can get up to 406 percent return on investment over 3 years and can expect a 30-percent reduction in TCO over 5 years, protecting an additional $6.85 million in annual revenue.

A separate study found that customers that migrated both Windows Server and SQL Server workloads to Azure generated more value. According to The Business Value of Microsoft Azure for SQL Server and Windows Server Workloads,2 by optimizing costs, operations, and business opportunities, companies gained $15.85 million in total annual benefits while also increasing IT security efficiency by 43 percent with cloud tools and automation.

Azure SQL

Migrate, modernize, and innovate with the modern SQL family of cloud database services.

a group of people sitting at a table with a laptop

A smooth path to migration, a more powerful destination

Migrating to a cloud platform is an essential step on the journey to modernization, and there are many choices. 

What makes SQL unique is that it’s built on the same engine, no matter where you deploy, which means you can build on your existing SQL experience while gaining the layered security, intelligent threat detection, and data encryption that Azure provides. And as we shared with customers at SQLBits, there’s now an even more powerful option available for customers looking to leverage the full PaaS experience. Azure SQL Managed Instance Next-gen GP  brings significantly improved performance and scalability to power up your existing Azure SQL Managed Instance fleet, and help bring more mission-critical SQL workloads to Azure. With close to 100 percent feature compatibility with SQL Server, Azure SQL Managed Instance is the recommended choice to migrate and modernize SQL apps at scale and at your own pace.

Another option many of our customers start with is by running their Windows Server workloads on Azure Virtual Machines, benefiting from a simplified, managed experience and cloud-native support for SQL Server, .NET apps, and Remote Desktop Services. Or you can modernize your entire Windows Server estate, choosing from more than 200 Azure services and capabilities, including support for hybrid environments. 

Take the first step or the next: You have choices

When it comes to migration, Azure meets you where you are with options for moving on-premises workloads and for developing new cloud solutions. For example, many organizations start by moving Windows Server workloads to Azure Virtual Machines, enabling them to easily scale to support new developments and more efficiently manage peak loads. Hokkoku Bank took this step, migrating its Windows Server–based estate to Azure as part of a cloud-first initiative. Azure supports the bank’s modernization plans and helps provide a disaster recovery solution in an earthquake-prone region.  

Correios de Portugal, the country’s postal service, migrated its Windows Server workloads to Azure Virtual Machines backed by Azure SQL, which provides a smooth path to a cost-effective, highly scalable, fully managed PaaS database. It’s the best choice for modernizing your apps and getting the most out of your existing investments.

Many of our database customers move to SQL Server on Azure Virtual Machines for the cost benefits on top of the scalability and resilience of Azure. As an example, healthcare software manufacturer Allscripts migrated on-premises applications to Azure SQL Database Managed Instance when possible, but another 600 on-premises VMs needed a different migration approach. Allscripts moved them to SQL Server on Azure Virtual Machines, a quick, low-risk step for workloads it plans to optimize and modernize later. The lift-and-shift approach can be an easy first   step in your cloud journey.

Azure also offers hybrid solutions that bridge your on-premises and cloud resources. For example, you can move or extend on-premises VMware environments using Azure VMWare Solution. You can even use the free Windows Admin Center tool to manage across Windows Server environments—physical, virtual, on-premises, in Azure, or in a hosted environment—at no additional cost. To get started with a Windows Server migration, start discovering and assessing on-premises resources using the free Azure Migrate tool.

Watch the Migrate to Innovate digital event on demand and learn the business benefits of migrating to Azure.

Try it for free 

If you want to know how your workload will perform before migrating, try these Azure offers and get started building that proof-of-concept.  

  • Try Azure SQL Managed Instance for free. For 12 months, you can get up to two instances per Azure subscription, 750 vCore hours of compute per month, and 32 GB data storage and 32 GB backup storage per month. 
  • Try Azure SQL Database for free. Test and develop applications or run small production workloads for free. This offer provides the first 100,000 vCore seconds, 32 GB of data, and 32 GB of backup storage per month at no charge for the lifetime of your subscription. 

Learn more about Azure SQL

Stay tuned for more migration announcements in the coming months. To get started now: 

  • Discover why cloud economics make sense and get greater return on your investment. 

  1. IDC report, The Business Value of Microsoft Azure SQL Database and Azure SQL Managed Instance Workloads, IDC #US51073123, August 2023. 
  2. The Business Value of Microsoft Azure for SQL Server and Windows Server Workloads

The post Why migrate Windows Server and SQL Server to Azure: ROI, innovation, and free offers appeared first on Microsoft SQL Server Blog.

]]>
Microsoft Purview access policies for SQL Server 2022 http://approjects.co.za/?big=en-us/sql-server/blog/2022/08/11/microsoft-purview-access-policies-for-sql-server-2022/ Thu, 11 Aug 2022 15:00:00 +0000 The focus of this article is on using Microsoft Purview to enable access to user data as well as specific system metadata in SQL Server 2022.

The post Microsoft Purview access policies for SQL Server 2022 appeared first on Microsoft SQL Server Blog.

]]>
Part of the SQL Server 2022 blog series.

Overview

Microsoft Purview is a family of data governance, risk, and compliance solutions that help organizations:

  • Gain visibility into data assets across your organization. Data assets can be across data centers, multicloud, and software as a service (SaaS) data.
  • Enable secure access to your data.
  • Safeguard and manage sensitive data across clouds, apps, and endpoints.
  • Manage data risks and regulatory compliance end-to-end.
  • Empower your organization to govern, protect, and manage data in new, comprehensive ways.

The focus of this article is on using Microsoft Purview to enable access to user data as well as specific system metadata in SQL Server 2022 running on Azure Arc–enabled servers.

With the SQL Server 2022 release, the goal is to enable three main scenarios:

  • Browsing data in user-defined tables and views.
  • Performance monitoring with system commands, functions, and views.
  • Security auditing with security-related system functions and views.

How it works

To complete these scenarios the data owner first needs to author a policy. A purview policy is a set of purview statements, each containing a purview role, scope, and assigned Azure AD principal.

Depending on the scenario, a purview role would be one of the built-in roles: Read, SQL Performance Monitor, or SQL Security Auditor.

With scope, the policy author defines an applicable target for the statement. It could be either a specific SQL Server or a wider scope like a resource group or a subscription.

To apply the policy, the author then needs to publish it to the target resources. One thing to keep in mind here is that it takes a couple of minutes for a policy to become active as it takes that much time for the SQL engine to pull it in.

Once the policy is active, the assigned users will be able to connect and perform actions assigned by the policy. The Connect permission is implicit, so there is no need to create logins or database users using T-SQL.

Let’s see this in a more visual fashion using the scenario walkthrough.

Scenario walkthrough

For SQL Server to be able to use policies, it needs to be registered with a Microsoft Purview account and enabled for Data use management.

Microsoft Purview form showing the Name, Azure subscription.

In this scenario, Ana, who is an IT manager, wants to provide Chris, who is a data analyst, read-only access to tables in a SQL Server database so that Chris can create reports.

To accomplish this, Ana authors a policy that will allow Chris access to the target server.

Access Control Policy form showing the Name, Description, and Policy statements sections filled out.

When finished, Ana publishes this policy and applies it to SQL Server by publishing it.

Policy publish form showing FinanceSQLonArc selected.

Now Chris can connect to the SQL Server and execute queries against the server to which the policies are applied.

SQL Query showing actions taken previously to get user connected to SQL Server without explicit login.

As highlighted above, Chris could connect to SQL Server even though there is no explicit login.

Summary

The new access policies feature provides data owners the capability to author access policies through the Microsoft Purview data-governance service experience and then apply them to SQL Server 2022 data sources individually or at scale. With this approach users are empowered to assign permissions to Azure Active Directory users at a scale without using T-SQL or the need to explicitly create logins or users on a server. In this release, the following server roles are eligible for assignment: Read, SQL Performance Monitor, and SQL Security Auditor.

Next steps

Microsoft Purview access policies for SQL Server 2022 are just one of the many benefits of migrating to SQL Server 2022.

Download the latest release of SQL Server 2022 if you haven’t already done so and check out the SQL Server 2022 Overview and What’s New references. There are many new features and improved functionality being added to this release.

Learn More

For more information and to get started, check out the following references:

Read What’s New in SQL Server 2022

To learn more about Microsoft Purview check out What is Microsoft Purview? | Microsoft Docs.

For a detailed how-to on Microsoft Purview access policies for SQL Server 2022 visit Provision access by data owner for SQL Server on Azure Arc-enabled servers (preview) – Microsoft Purview | Microsoft Docs.

To see how Microsoft Purview access policies could be published at scale see Resource group and subscription access provisioning by data owner (preview) – Microsoft Purview | Microsoft Docs.

The post Microsoft Purview access policies for SQL Server 2022 appeared first on Microsoft SQL Server Blog.

]]>
Meet us at SQLBits 2022 and level up as a data professional http://approjects.co.za/?big=en-us/sql-server/blog/2022/02/10/meet-us-at-sqlbits-2022-and-level-up-as-a-data-professional/ Thu, 10 Feb 2022 16:00:00 +0000 We are excited to be the premium sponsor at this year’s SQLBits 2022, March 8 – 12, in-person in London and virtually.

The post Meet us at SQLBits 2022 and level up as a data professional appeared first on Microsoft SQL Server Blog.

]]>
It has been over two years since we have had the opportunity to meet face-to-face with our data community at a large event and we miss it. From hallway conversations to the energy that comes from solving problems and helping people understand complex concepts, we cannot wait to teach, meet and greet everyone. This is why we are excited to be the premium sponsor at this year’s SQLBits 2022, March 8 – 12, in-person in London and virtually.

As the lead sponsor, we will deliver content including the keynote, five full-day training days, and over fifty general sessions. With so many opportunities to educate, we are bringing the full Azure data team including folks from across the data platform, such as SQL Server, Azure SQL, Cosmos DB, Azure Purview, Azure Synapse Analytics, and Power BI.

Start the week with my team for two day-long training sessions where you will have a unique chance to work directly with Microsoft engineering:

The Hands-on Azure SQL Workshop on March 8 will help you translate your existing SQL Server skills to Azure SQL. Bring your laptop and get ready to learn hands-on. You will gain a foundational knowledge of what to use when, as well as how to configure, monitor, and troubleshoot the “meat and potatoes” of SQL Server in Azure: security, performance, and availability.

Migrate SQL Server to Azure on Wednesday, March 9 will help you migrate your SQL Server environments to Azure. In this session, the Microsoft engineering team will show you everything you need to know, including the tools and knowledge you need to make your migrations seamless, cost-efficient, and optimized for speed.

Other training sessions cover topics such as Azure SQL Database, Synapse Analytics, and Power BI.

All speaker proceeds from these sessions will be given back to a local charity.

The SQLBits event theme this year is Video Games—and in the “Level Up With Azure Data” keynote, Buck Woody has asked me to come talk about SQL Server 2022 and Azure Data. He assures me I will have help with some surprise guests so it should be interesting. It is always a fun keynote when Buck and I are on stage, and this year you really do not want to miss it!

You also have the opportunity to attend the Microsoft general sessions to learn about the entire Azure data platform.

Take a look at some of the learning available SQLBits 2022

Unified Data Governance with Azure PurviewGaurav Malhotra, Evangeline White
What’s New in Azure SQL MINiko Neugebauer
The fundamentals of building a lakehouse with SynapseLuke Moloney
SQL Server in Azure Virtual Machine ReimaginedPam Lahoud
Microsoft Database InnovationsAnna Hoffman
Azure Arc-Enabled Data ServicesJes Schultz, Buck Woody
Azure SQL Database customer success stories for IoT workloadsSilvano Coriani
Azure SQL availability and resiliencyEmily Lisa
Microsoft SQL Server 2022 Deep Dive (two parts)Pedro Lopes
Modernize your Oracle workloads to Azure DataAlexandra Ciortea
Empowering every individual with Power BIMohammad Ali, Patrick LeBlanc
AMA with the Microsoft Engineering team hosted by
Bob Ward
“Rockstars” of the engineering team

See all the opportunities to engage with Microsoft engineering by heading over to our blog on Microsoft Tech Community, Ready for SQLBits 2022. And don’t forget to stop by our booth, where you can get your questions answered by members of the Microsoft team.

SQLBits is a marathon of top-quality training from global specialists, with two days of full-day training sessions and three days of general sessions. As always with SQLBits, Saturday, March 12 is free to attend. Meet with community leaders sharing their real-world experience and Microsoft product teams providing deep insights into innovations that meet your needs.

Register today for SQLBits 2022

Join Microsoft at this hybrid event for the latest on the data platform and a chance to see whether Buck Woody or I have the best arcade game skills!

Register to attend, and we’ll see you there, in-person, or virtually!

The post Meet us at SQLBits 2022 and level up as a data professional appeared first on Microsoft SQL Server Blog.

]]>
PASS Data Community Summit keynote: a bridge to a new universe http://approjects.co.za/?big=en-us/sql-server/blog/2021/11/08/pass-data-community-summit-keynote-a-bridge-to-a-new-universe/ Mon, 08 Nov 2021 18:00:40 +0000 It is almost time for PASS Data Community Summit 2021, a free online conference for the Microsoft data platform professional.

The post PASS Data Community Summit keynote: a bridge to a new universe appeared first on Microsoft SQL Server Blog.

]]>
It is almost time for PASS Data Community Summit 2021, a free online conference for the Microsoft data platform professional. The conference, hosted by Redgate, will include the latest SQL Server and Azure data innovations, practical training, and networking to empower you to transform your career and your organization. This year’s event is coming to you online for free from November 8 – 12, 2021, and we will continue the tradition of a Microsoft day one keynote.

Deliver faster performance than ever before with SQL Server and Azure

Hear directly from Microsoft’s Rohan Kumar and senior Microsoft engineering leaders during the day one kick-off keynote as they take you on a journey to a new universe shaped by our past—and built to take us into a limitless future. The cloud has created a whole new universe and advancements in Microsoft data products and services are your bridge.

You’ll see how you can use your existing SQL Server and Azure skills, and learn about new tools and platforms available from Microsoft to deliver faster performance than ever before. You’ll see how to shape your data so you can harness its power to find a new galaxy of insights, answers, and predictions. And you will hear about new innovations that continue Microsoft’s rich heritage of data integrity and governance.

Additionally, in the special on-demand keynote, Microsoft Azure Data CTO Raghu Ramakrishnan and team will share a technical keynote and demos showing Azure Purview and SQL.

Register for the PASS Data Community Summit

Don’t miss this opportunity to see how Microsoft is uniquely positioned to provide you with an end-to-end data platform seamlessly integrating limitless database scale and performance, unmatched analytics and intelligence, and unified data governance.

After the keynotes, ground your learning with in-depth training in one of more than two dozen sessions Microsoft will be delivering. Hear the latest from the Engineering teams who develop the tools you use every day. After your sessions, don’t forget to visit the virtual exhibit hall where you can connect with our team across SQL Server 2022, Azure SQL, Azure Synapse Analytics, Microsoft Power BI, Azure Arc, and more.

Register for PASS Data Community Summit today.

The post PASS Data Community Summit keynote: a bridge to a new universe appeared first on Microsoft SQL Server Blog.

]]>
Announcing SQL Server 2022 preview: Azure-enabled with continued performance and security innovation http://approjects.co.za/?big=en-us/sql-server/blog/2021/11/02/announcing-sql-server-2022-preview-azure-enabled-with-continued-performance-and-security-innovation/ Tue, 02 Nov 2021 15:00:00 +0000 http://approjects.co.za/?big=en-us/sql-server/blog/?p=38283 Today we are announcing the preview of SQL Server 2022, the most Azure-enabled release of SQL Server yet.

The post Announcing SQL Server 2022 preview: Azure-enabled with continued performance and security innovation appeared first on Microsoft SQL Server Blog.

]]>
Today we are announcing the preview of SQL Server 2022, the most Azure-enabled release of SQL Server yet, with continued innovation in performance, security, and availability.

The rise of data represents a tremendous opportunity and also poses challenges. Companies are seeing their relational and nonrelational data proliferate exponentially on-premises, in the cloud, at the edge, and in hybrid environments. The most transformative companies drive predictive insights on current data, whereas others may struggle to drive even reactive insights to their historical data. Information may be siloed across geographies and divisions.

To empower customers amid this environment, Microsoft offers an end-to-end data platform of products and services that come together to meet these challenges. Operational databases cover all possible deployment locations, including SQL Server and Azure Arc-enabled data services, Azure SQL fully-managed cloud databases, and Azure SQL Edge for IoT devices. To enable real-time insights, Azure Synapse Analytics brings together data integration, enterprise data warehousing, and big data analytics, and customers can visualize their data with Power BI. Customers can discover, catalog, and govern their data wherever it resides with Azure Purview.

SQL Server 2022 integrates with Azure Synapse Link and Azure Purview to enable customers to drive deeper insights, predictions, and governance from their data at scale. Cloud integration is enhanced with disaster recovery (DR) to Azure SQL Managed Instance, along with no-ETL (extract, transform, and load) connections to cloud analytics, which allow database administrators to manage their data estates with greater flexibility and minimal impact to the end-user. Performance and scalability are automatically enhanced via built-in query intelligence. There is choice and flexibility across languages and platforms, including Linux, Windows, and Kubernetes.

SQL Server 2022: an industry-leader in performance and security, powered by Azure

Azure-enabled

Bi-directional HA/DR to Azure SQL

To ensure uptime, SQL Server 2022 is fully integrated with the new link feature in Azure SQL Managed Instance. With the new link feature for Azure SQL Managed Instance, you now get all the benefits of running a PaaS environment applied to disaster recovery—allowing you to spend less time on setup and management even when compared to an IaaS environment. This works by using a built-in Distributed Availability Group (DAG) to replicate data to a previously deployed Azure SQL Managed Instance as a DR replica site. The instance is ready and waiting for whenever you need it—no lengthy configuration or maintenance is required. You can also use this link feature in read scale-out scenarios to offload heavy requests that might otherwise affect database performance. And we are working on building out more capabilities to support bi-directional data movement.

Azure Synapse Link

Previously, moving data from on-premises databases, like SQL Server, to Synapse required you to use ETL. As we all know, setting up and running an ETL pipeline takes a lot of work, and insights lag behind what is happening at any moment. Azure Synapse Link for SQL Server 2022 provides automatic change feeds that capture the changes within SQL Server and feed those into Azure Synapse Analytics. It provides near real-time analysis and hybrid transactional and analytical processing with minimal impact on operational systems. Once the data hits Synapse, you can combine it with many different data sources regardless of their size, scale, or format and run powerful analytics over all of it using your choice of Azure Machine Learning, Spark, or Power BI. Since the automated change feeds only push what is new or different, data transfer happens much faster and now allows for near real-time insights, with minimal impact on the performance of the source database in SQL Server 2022.

Azure Purview integration

We recently announced the general availability of Azure Purview as a unified data governance and management service. We are excited to highlight that SQL Server is also integrated with Azure Purview for greater data discovery, allowing you to break down data silos. Through this integration you will be able to:

  • Automatically scan your on-premises SQL Server for free to capture metadata.
  • Classify data using built-in and custom classifiers and Microsoft Information Protection sensitivity labels.
  • Set up and control specific access rights to SQL Server.

Enhancements to performance, security, and availability

Performance

SQL Server offers differentiated performance, with number one OLTP performance1 and number one Non-Clustered DW performance on 1TB2, 3TB3, 10TB4, and 30TB5 according to the independent Transaction Processing Performance Council. Built-in query intelligence in SQL Server 2022 innovation includes:

  • For Query Store, we are adding support for read replicas and enabling query hints to improve performance and quickly mitigate issues without having to change the source T-SQL.
  • For Intelligent Query Processing, we’re expanding more scenarios based on common customer problems. For example, the “parameter sensitive plan” problem refers to a scenario where a single cached plan for a parameterized query is not optimal for all possible incoming parameter values. With SQL Server 2022’s Parameter Sensitive Plan optimization feature, we automatically enable the generation of multiple active cached plans for a single parameterized statement. These cached execution plans will accommodate different data sizes based on the provided runtime parameter values.

Security

Over the past ten years, SQL Server has had fewer vulnerabilities than the competition.6 Building on this, the new ledger feature creates an immutable track record of data modifications over time. This protects data from tampering by malicious actors and is beneficial for scenarios such as internal and external audits.

Availability

With the move to a more global distribution of workers and customers, many organizations are moving to a multi-write environment that allows changes to be made to the local database and pushed out to other replicas in a two-way flow of updates. However, if multiple people change the same row in the database and the different write replicas have different information in them, previously this peer-to-peer replica conflict would stall the whole operation until it was addressed. With SQL Server 2022, we are automating the last-writer wins rule. Now, when a conflict is detected, the most recent modification time will be chosen to be persisted on all replicas. This helps keep your multi-write scenarios running smoothly.

Learn more and apply for the preview today

At this point in time, we are onboarding a limited number of customers and partners to our SQL Server 2022 preview, in advance of public preview and general availability in the coming year.

Learn more about the SQL Server 2022 release on our webpage and by viewing deep-dive sessions at Microsoft Ignite, with Microsoft Mechanics, and at the upcoming free virtual PASS Data Community Summit. Read more about Azure at Ignite on the Azure blog.

Register today to apply for the SQL Server 2022 preview and stay informed about SQL Server 2022 updates.

Watch the video to learn more about what's next for SQL Server 2022


All TPC Claims as of October 6, 2021

1 http://www.tpc.org/4087

2 http://www.tpc.org/3374

3 http://www.tpc.org/3380

4 http://www.tpc.org/3362

5 http://www.tpc.org/3364

6 National Institute of Standards and Technology Comprehensive Vulnerability Database

The post Announcing SQL Server 2022 preview: Azure-enabled with continued performance and security innovation appeared first on Microsoft SQL Server Blog.

]]>
Move SQL Server licenses without Software Assurance to Azure http://approjects.co.za/?big=en-us/sql-server/blog/2021/08/30/move-sql-server-licenses-without-software-assurance-to-azure/ Mon, 30 Aug 2021 16:00:00 +0000 Azure offers unique benefits that no other cloud provider can match including dual-use rights, Azure Hybrid Benefit, and unlimited virtualization.

The post Move SQL Server licenses without Software Assurance to Azure appeared first on Microsoft SQL Server Blog.

]]>
Migrating your on-premises infrastructure and architecture to the cloud may seem like a daunting task, especially if you don’t have Software Assurance for your on-premises licenses. While this may seem difficult and challenging, there is a pain-free way to bring your existing on-premises licenses to the cloud through Azure Dedicated Host. Not only does Azure Dedicated Host provide you with your own private cloud on Azure, but it also allows you control over host maintenance and lets you continue using your existing licenses, and offers continued support for applications that would not otherwise be supported on other clouds. For example, when you run your Dedicated Host on Azure you can take advantage of free SQL Server 2008 or SQL Server 2012 Extended Security Updates, only in Azure.

Azure offers unique benefits that no other cloud provider can match including dual-use rights, Azure Hybrid Benefit, and unlimited virtualization, which lets you license the physical cores you have on-prem and those licenses will cover all the vCPUs on the host until the host runs out of resources. All of these benefits help you migrate to the cloud as cost-effectively as possible. We’ll go into more detail about each Azure-only benefit in this blog.

This blog will take you on a deep dive into moving SQL Server licenses to Azure Dedicated Host, its infrastructure benefits, and why it is the easiest way to bring your existing on-prem licenses to the cloud.

What is Azure Dedicated Host?

Azure Dedicated Host is an Azure service that provides you with a physical server, which you can host one or more virtual machines (VMs) on. Through physical, host-level isolation, you are the only tenant on the host; the server is dedicated to your organization and your workloads. With Azure Dedicated Host, you gain direct visibility to and control over all the Azure resources on the host. Essentially, Azure Dedicated Host allows you to create your own private cloud in Azure.

What are the benefits of Azure Dedicated Host?

Infrastructure benefits

With hardware isolation at the physical server level, Azure Dedicated Host provides servers solely for your subscription. You are the only one using the capacity and resources on the host. Physical isolation may be required by your company or industry, or integral to ensuring your workloads are able to perform as quickly as they should.

In addition to the physical isolation of the host and awareness of all Azure resources on the host, Azure Dedicated Host allows you to choose the combination of the number of processors, VM series, VM sizes, and the type of processor you use. Azure has a wide offering of various combinations of processor type and VM series. A full list of the available Dedicated Host SKUs, the combination of a VM series and processor type in a given region can be found on the Dedicated Host pricing page.

Azure Dedicated Host also gives you direct control over the maintenance on the host. Instead of adhering to Azure’s maintenance schedule, Maintenance Control allows you to delay platform updates and apply them during a 35-day window.

Licensing benefits

In addition to the infrastructure benefits, Azure Dedicated Host provides substantial financial benefits for those who already have on-premises SQL Server enterprise edition licenses, whether the license was purchased with or without Software Assurance. Software Assurance allows you to maximize your discounts and can unlock more benefits like Azure Hybrid Benefit, unlimited virtualization, and dual-use rights, which are not available for the license only. Microsoft highly recommends purchasing Software Assurance for your migration to Azure.

Migration (getting to Azure) Azure Hybrid Benefit (only on Azure) * Unlimited virtualization (only on Azure) Dual-use rights (only on Azure)
License-only, purchased pre-Oct. 1, 2019 Recommended: Move to Azure Dedicated Host at no additional license cost. N/A N/A N/A
License-only, purchased on or after Oct. 1, 2019 Move to the cloud by purchasing SQL Server on Azure VM with pay-as-you-go license pricing. N/A N/A N/A
License + Software Assurance, purchased pre-Oct. 1, 2019 Move to Azure Dedicated Host or Azure VMs at no additional license cost using Azure Hybrid Benefit. Included in Software Assurance. License the physical cores and the licenses will cover all the vCPUs on the host until the host runs out of resources. Grace period to use your licenses on-prem and in Azure as you migrate.
License + Software Assurance, purchased on or after Oct. 1, 2019 Recommended: Move to Azure Dedicated Host with Azure Hybrid Benefit and unlimited virtualization. Provides deep discounts while moving your licenses to the cloud. License the physical cores and the licenses will cover all the vCPUs on the host until the host runs out of resources. Grace period to use your licenses on-prem and in Azure as you migrate.

*Azure Hybrid Benefit allows you to bring your on-premises SQL Server licenses with Software Assurance to Azure at no additional cost.

Software application licenses can be applied at one of two places: the host or the VM. By applying the licenses at the host level, rather than the VM level, your license will cover all the physical cores rather than the virtual cores. With more virtual cores than physical cores on a host, this allows you to stretch your existing licenses further. For example, instead of licensing all 80 virtual cores on the Esv4-Type1 Dedicated Host, you can instead save 28 core licenses by licensing the 52 physical cores on the host. In doing so, you can license up to 80 virtual cores on the host while only applying the licenses on 52 virtual cores. This is only available on Azure.

The practice of licensing the physical cores to minimize your overall licensing cost is called unlimited virtualization. With SQL Enterprise Edition, Software Assurance, and unlimited virtualization, customers can apply the license to the physical cores, at the host level, and create as many VMs as the host allows. All VMs created on that host are then covered by unlimited virtualization and are covered by the host-level licenses. Unlimited virtualization is unique to Azure.

How you go about achieving unlimited virtualization depends on the license type. For SQL Server 2008, you can achieve unlimited virtualization at no additional cost by applying the licenses at the host level. For those with SQL Server 2008 R2 and later, by purchasing Software Assurance, you can unlock unlimited virtualization on your Dedicated Host.

Azure allows for dual-use rights while migrating your on-prem workloads to the cloud through Azure Hybrid Benefit. You can migrate to the cloud and simultaneously use your existing on-prem SQL Server licenses in Azure for up to 180 days. This allows you to avoid buying more licenses to cover the migration period and furthers the use of your existing licenses. You must have Software Assurance in order to use dual-use rights while migrating.

To better understand how much you can save through Azure Dedicated Host, Software Assurance, and unlimited virtualization, please check out the Azure pricing calculator.

Extended Security Update benefits

Customers who migrate their SQL Server 2012 licenses to Azure will receive free Extended Security Updates, only in Azure. Extended Security Updates are critical security patches for legacy services that need to be run past the end of support date. After the July 12, 2022 end of SQL Server 2008 and 2008 R2 Extended Security Updates on-premises, you can migrate to Azure and take advantage of one year of additional SQL Server 2008 extended security updates, only in Azure, for free. Extended security updates for both SQL Server 2008 and SQL Server 2012 are free only in Azure, making Azure the prime choice for SQL workloads running on either version.

Moving to the cloud doesn’t have to be challenging. There are proven ways to get to Azure that drive business impact. Through Azure Dedicated Host, you can bring your existing licenses to Azure. By purchasing Software Assurance, you maximize your licensing discounts and unlock more benefits, such as Azure Hybrid Benefit, unlimited virtualization, and dual-use rights.

Learn more about our product and pricing offers for SQL Server migration:

Get started with your migration to Azure using Azure Migrate.

The post Move SQL Server licenses without Software Assurance to Azure appeared first on Microsoft SQL Server Blog.

]]>
Real-time data intelligence and security at the edge with Azure SQL Edge http://approjects.co.za/?big=en-us/sql-server/blog/2020/09/22/real-time-data-intelligence-and-security-at-the-edge-with-azure-sql-edge/ Tue, 22 Sep 2020 15:00:54 +0000 http://approjects.co.za/?big=en-us/sql-server/blog/?p=32208 Today we introduce the availability of Azure SQL Edge, a real-time data engine, optimized for IoT workloads and backed by the security and performance of the same engine that powers SQL Server and Azure SQL.

The post Real-time data intelligence and security at the edge with Azure SQL Edge appeared first on Microsoft SQL Server Blog.

]]>
Today we introduce the availability of Azure SQL Edge, a real-time data engine, optimized for IoT workloads and backed by the security and performance of the same engine that powers SQL Server and Azure SQL.

Azure SQL Edge is a small-footprint container that enables localized IoT solutions for edge servers, gateways, and devices by offering data streaming, storage, and analytics in connected or disconnected environments.

Built on the same code base as Microsoft SQL Server and Azure SQL, Azure SQL Edge provides the same industry-leading security, the same familiar developer experience, and the same tooling that many teams already know and trust—now extended to IoT deployments for real-time intelligence.

And best of all, Azure SQL Edge has simplified pricing that is right-sized for IoT deployments, available as low as $60 per year per device for a 3-year commitment or at $10 per month, per device subscription.

Data and compute are pushing closer to the edge

The explosion of the internet of things (IoT) has changed the way we collect and analyze data. As compute becomes more powerful in smaller form factors, edge devices such as sensors and cameras are being adopted across industries to digitally transform their operations.

Gartner estimates that by 2025, 75 percent of enterprise-generated data will be created and processed at the edge, up from less than 20 percent today.1 This technological shift towards edge gateways and devices puts data collection and compute together at the same location, reducing latency, and enabling real-time insight and impact whether on the manufacturing floor or on a remote wind farm.

A data engine built, optimized, and priced for IoT deployments

 Azure SQL Edge provides affordable solutions for even the most demanding edge architectures:

  • Time series, data streaming, and AI built-in. Stream, store, and analyze data while it is in motion or at rest. Real-time analytics and simultaneous event-processing whether online or off.
  • Your choice of platform. Run SQL on ARM 64 and x64 architectures. A small footprint under 500mb means you can deploy on IoT devices as small as a Raspberry Pi.
  • Develop once, deploy anywhere from edge to cloud. Consistent app development, security, and management from Azure SQL to SQL Server to the IoT edge.
  • Native integration with Azure products and services. Simplify and strengthen your cloud-to-edge architecture with native integration to Azure products and services such as Azure IoT Edge and Azure Stack Edge.
  • Simplified pricing for IoT. No upfront cost and subscriptions offers as low as $60 per year per device for a 3-year commitment.2 It’s as simple as that.

Azure SQL Edge meets the demands of IoT with the performance and security of SQL

“This is a game changer.”

For more than 57 years, Fugro has delivered projects in some of the most remote and challenging environments around the world. It uses the latest technology to provide comprehensive information about the world’s environment and structures to contribute to a safe and livable world. Its ocean fleet largely relied on on-premises servers to collect and analyze data, slowing down their time to insights.

“Traditionally, it took two weeks to prep each client’s monthly data, to verify the report, and for the client to receive it. Now we deliver the first draft of that report in eight minutes. This is a game changer, it massively simplifies everything we do.” – Richard Corless, Lead Cloud Architect, Fugro

Fugro now uses Microsoft Azure IoT Edge and Azure SQL Edge to connect its vessels and onshore assets to boost efficiency and speed innovation

“The decision-maker, the worker, the line manager—everyone is able to make decisions earlier, quicker, and more accurately.”

A leading technology enterprise in the fields of optics and optoelectronics, ZEISS embarked on a digitization process with the goal of creating a connected smart factory that can execute intelligent, flexible manufacturing for optimal efficiency, precision, and accuracy.

“Collecting this data helps everyone at every level of the factory. The decision-maker, the worker, the line manager—everyone is able to make decisions earlier, quicker, and more accurately.”  – Jochen Scheuerer, Head of Connected Smart Factory, ZEISS

Achieving these smart production goals requires measurement and inspection technology, that can capture and analyze quality data at different sites with greater flexibility and speed. Azure SQL Edge was added to production lines for eyeglass lenses, mechanical parts, and spectroscopic solutions.

Azure SQL Edge is now available

Get started today, or view whitepapers, case studies, and more.


1 “Edge Computing Solutions for Industrial IoT.” July 2018, Gartner, “Top Strategic IoT Trends and Technologies Through 2023.” September 2018, Gartner

2 Restrictions apply. See Azure.com for more information.

The post Real-time data intelligence and security at the edge with Azure SQL Edge appeared first on Microsoft SQL Server Blog.

]]>
Advanced data security for SQL Server is coming to Azure Virtual Machines http://approjects.co.za/?big=en-us/sql-server/blog/2019/05/23/advanced-data-security-for-sql-server-is-coming-to-azure-virtual-machines/ Thu, 23 May 2019 16:00:35 +0000 This post was written by Michael Makhlevich Our customers have asked for this and we’ve been listening – advanced data security is now available for SQL Server on Azure Virtual Machines! Using just a few simple steps, you can now protect your SQL Server installations on Azure VMs with Microsoft’s advanced data security capabilities.

The post Advanced data security for SQL Server is coming to Azure Virtual Machines appeared first on Microsoft SQL Server Blog.

]]>
This post was written by Michael Makhlevich

Our customers have asked for this and we’ve been listening – advanced data security is now available for SQL Server on Azure Virtual Machines! Using just a few simple steps, you can now protect your SQL Server installations on Azure VMs with Microsoft’s advanced data security capabilities.

Advanced data security for SQL Server on Azure VM currently includes functionality for surfacing and mitigating potential database vulnerabilities and detecting anomalous activities that could indicate a threat to your server. To get started today, read the Advanced data security for SQL Server on VM setup instructions.

Why you should enable advanced data security for SQL Server on Azure VM

While in public preview, advanced data security for SQL Server on Azure VM is free and includes: 

  1. Vulnerability assessment – A database scanning service that can discover, track, and help you remediate potential database vulnerabilities. Detected vulnerabilities across all connected SQL Servers will appear in one unified dashboard!
  2. Advanced threat protection – A detection service that continuously monitors your database for suspicious activities and provides action-oriented security alerts on anomalous database access patterns. All alerts will appear in your centralized go-to location for security management in the Azure portal – the Azure Security Center threats dashboard.

For full details regarding threat detectors in Public Preview, read the Advanced data security for SQL Server on VM documentation.

These advanced security features have evolved and benefited from continuous improvement over the past couple of years, and have already been running on more than 1 million databases in the corresponding Azure SQL Database service – Advanced data security for Azure SQL databases.

How does it work?

Using the Azure Log Analytics agent, you connect your SQL Server’s hosting machine to a Log Analytics workspace. The agent collects audit logs for login events (omitting any sensitive data like queries or user’s data) and uploads them from the machine to the workspace, where our security analytics capabilities go into action. In addition, the agent also collects results from the vulnerability assessment scans and sends those to the workspace as well.

Advanced data security data flow chart for SQL Server on virtual machine.

Logs and assessment results will appear in the workspace and are entirely under your control and can be queried for more insights. You can also identify the logs that triggered Advanced Threat Protection alerts for further investigation. Finally, the workspace contains a built-in dashboard for intuitive analysis of the vulnerability assessment results.

For a complete set of instructions, review the documentation for Advanced data security for SQL Server on VM.

We want to hear from you!

We greatly appreciate your feedback and want to hear from you. Please contact us directly through SQL Security Feedback sqlsecurityfd@microsoft.com.

The post Advanced data security for SQL Server is coming to Azure Virtual Machines appeared first on Microsoft SQL Server Blog.

]]>
Confidential computing using Always Encrypted with secure enclaves in SQL Server 2019 preview http://approjects.co.za/?big=en-us/sql-server/blog/2018/12/17/confidential-computing-using-always-encrypted-with-secure-enclaves-in-sql-server-2019-preview/ http://approjects.co.za/?big=en-us/sql-server/blog/2018/12/17/confidential-computing-using-always-encrypted-with-secure-enclaves-in-sql-server-2019-preview/#comments Mon, 17 Dec 2018 17:00:07 +0000 SQL Server 2019 preview brings encryption technology to a broader set of scenarios by enabling rich confidential computing capabilities with the enhanced Always Encrypted feature, Always Encrypted with secure enclaves.

The post Confidential computing using Always Encrypted with secure enclaves in SQL Server 2019 preview appeared first on Microsoft SQL Server Blog.

]]>
SQL Server 2019 preview brings encryption technology to a broader set of scenarios by enabling rich confidential computing capabilities with the enhanced Always Encrypted feature, Always Encrypted with secure enclaves. Always Encrypted with secure enclaves allows rich computations on encrypted data, boosts performance when encrypting large columns of data or complex schemas, and enables customers to protect sensitive Personally Identifiable Information (PII) data when running rich queries.

Always Encrypted debuted in SQL Server 2016 as a solution for protecting sensitive data used during the processing of Transact-SQL queries. With Always Encrypted, the data is encrypted and decrypted on the client-side, and is not exposed in plaintext in memory of the SQL Server process. As a result, even DBAs and administrators of machines hosting the database can’t see plaintext data. This makes Always Encrypted a great way to keep your data secure, but it restricts computations that SQL Server can perform on the data.

The only operation SQL Server 2016 and 2017 support on encrypted database columns is equality comparison, providing you use deterministic encryption. For anything else, your apps need to download the data to perform the computations outside of the database. Similarly, if you need to encrypt your data for the first time or re-encrypt it later (e.g. to rotate your keys), you need to use special tools that move the data and perform crypto operations on a different machine than your SQL Server computer. These restrictions are not an issue if equality comparison is all your applications need and if the tables containing your sensitive data are small. However, many types of sensitive information, e.g. a person’s name or phone number, often require richer operations, including pattern matching and sorting, and it’s not uncommon for sensitive data to be too large to move outside of the database for processing.

To address the above challenges, Always Encrypted in SQL Server 2019 is enhanced with secure enclaves. A secure enclave is a protected region of memory that appears as a black box to the containing process and to other processes running on the machine, including the operating system. There is no way to view the data or code inside the enclave from the outside, which makes enclaves ideal for processing sensitive data. There are several enclave technologies that differ in how enclave isolation is accomplished. SQL Server 2019 preview uses a Windows Server technology called Virtualization Based Security (VBS), which relies on Hypervisor to protect and isolate enclaves.

A SQL Server 2019 instance can be configured to contain a secure enclave that is used for computations on data protected with Always Encrypted, which is illustrated in the diagram below. This secure enclave logically extends client applications’ trust boundary to the server side. While it is contained by the SQL Server environment, the secure enclave is not accessible to SQL Server, the operating system, or the database or system administrators. This means the enclave can safely perform cryptographic operations on sensitive data or decrypt the data to perform rich computations on the plaintext, without exposing the data to potential adversaries in the database environment.

If you are wondering how it all works under the covers, please see the online documentation and other resources listed at the end of this post. In the remainder of this article, we will focus on the benefits of Always Encrypted with secure enclaves and discuss the new scenarios the enhanced feature enables.

Boost performance of encrypting columns in large tables or complex database schemas

Always Encrypted with secure enclaves allows you to encrypt your data and re-encrypt it (e.g. to rotate column encryption keys) in-place, inside a server-side secure enclave. In contrast, without secure enclaves, crypto operations on columns protected with Always Encrypted requires loading the data to a trusted machine, where the operations are performed and then the data is uploaded back to the database. This process is prone to network errors and can take a long time if your sensitive data resides in large tables. In-place encryption with secure enclaves improves the resiliency and dramatically reduces the duration of cryptographic operations. As a result, it makes Always Encrypted a practical solution for protecting sensitive data in large tables.

Always Encrypted with secure enclaves also gives you the option to perform cryptographic operations using ALTER TABLE ALTER COLUMN Transact-SQL statements, which is particularly useful if you have a very large database schema that contains many database objects. Until now, cryptographic operations have required using tools such as the Always Encrypted wizard in SQL Server Management Studio (SSMS) or the Set-SqlColumnEncryption PowerShell cmdlet. These tools automatically handle all dependencies between the columns and other database objects, such as foreign key constraints, indexes, stored procedures, views, etc. Both SSMS and PowerShell leverage DAC Framework to detect, remove, and (after completing cryptographic operations) re-create all dependencies. This convenience, however, can be costly: if your database contains thousands of objects, the tools need to issue many queries to retrieve the metadata for your database, which can take a long time and consume a lot of resources, both on the server side and on the machine running the tool. When using Transact-SQL for cryptographic operations, you need to manually create scripts for handling dependencies. While this requires manual work, it gives you more control over handling dependencies and is typically a better or in some cases the only practical method for running such operations on databases with large schemas.

Please note in the current preview of SQL Server 2019 (CTP 2.1), in-place encryption is only supported when using ALTER TABLE ALTER COLUMN. SSMS and PowerShell will be updated later to take advantage of in-place encryption if your database configuration supports secure enclaves.

Here is an example of an ALTER TABLE ALTER COLUMN statement triggering a crypto operation. The example assumes the LastName column is not encrypted initially. Once the statement is completed, the column will become encrypted using randomized encryption and the specified key.

ALTER TABLE [dbo].[Patients]
ALTER COLUMN [LastName] [nvarchar](50) 
ENCRYPTED WITH (COLUMN_ENCRYPTION_KEY = [CEK1], ENCRYPTION_TYPE = Randomized, ALGORITHM = 'AEAD_AES_256_CBC_HMAC_SHA_256') NOT NULL
WITH (ONLINE = ON)
GO

Note the use of the ONLINE=ON switch, which causes the operation to perform in the online mode to minimize interruptions for applications that may be querying the table. Also note that the statement must be issued over a connection with Always Encrypted enabled and the user must have access to the column master key, protecting the column encryption key (CEK1) that is being used. This requirement is the same when running the wizard or the above-mentioned PowerShell cmdlet. Full details on this can be found in the Getting started with Always Encrypted with secure enclaves using SSMS documentation.

Protect PII and other sensitive data while running rich queries

Besides making encryption and key rotation easier, the main goal of secure enclaves is to enable SQL Server to support rich computations on encrypted database columns, while preserving the security benefits of Always Encrypted. Equipped with a secure enclave, a SQL Server instance can delegate computations to the enclave, which decrypts the data and performs the requested operations on plaintext. SQL Server 2019 preview supports pattern matching using the LIKE operator and comparison operators (<, >, =, etc.) on columns using randomized encryption. The example below shows a query searching patient records based on the last name prefix (assuming the LastName column is encrypted):

DECLARE @SearchPattern nvarchar(11) = N'Ab%'
SELECT * FROM [dbo].[Patients] WHERE [LastName] LIKE @SearchPattern
GO

Enabling rich queries unlocks Always Encrypted to a much broader set of scenarios, including applications that process PII such as people’s names or phone numbers, which typically require more complex computations than just equality comparison supported in SQL Server 2016/2017. This makes both preventing insider attacks and meeting regulatory compliance requirements, such as the EU General Data Protection Regulation (GDPR), much easier. With secure enclave, you do not need to re-engineer your apps to load the data and implement your query logic inside the applications. Instead, you can continue running your rich queries inside the database.

Note: Rich computations are pending several performance optimizations and include limited functionality (e.g., you cannot create indexes to support rich computations yet). Therefore, they remain disabled by default in SQL Server 2019 CTP 2.1. You can see the online documents on how to enable rich queries here.

Conclusion and next steps

Always Encrypted with secure enclaves in SQL Server 2019 preview helps you protect your sensitive data from malicious insiders and cloud operators or malware while supporting richer processing of your data inside the database. Here are the types of applications that can particularly benefit from using the enhanced Always Encrypted technology:

  • Applications that store sensitive data in large tables. With in-place encryption, you can encrypt columns or change the encryption scheme of columns in large tables much faster, as you don’t need to move the data to a machine running an encryption tool, such as SSMS or PowerShell.
  • Applications using databases with large schemas, containing thousands of database objects. Always Encrypted with secure enclaves gives you the flexibility of triggering cryptographic operations using Transact-SQL and create custom scripts that typically handle database dependencies more efficiently, unlike the client-side tools (SSMS, PowerShell). This makes encrypting columns in databases with large database schemas feasible or much faster.
  • Applications that process PII or other types of sensitive information that require pattern matching or range queries to be performed inside the database. You can protect the confidentiality of your sensitive data without re-implementing your business logic inside your apps, which is often expensive or even impossible, depending on the size of your data.

Here are a few links to learn more information about Always Encrypted using enclaves:

We would love to learn about your scenarios and requirements for protecting sensitive data, partner with you on your Proof of Concept projects, and help you become early adopters of Always Encrypted with secure enclaves. We also welcome your feedback while we continue our journey to the RTM of SQL Server 2019 and beyond. Please contact us directly at AEwithEnclaves@microsoft.com or by signing up for the SQL Server Early Adoption Program.

To get started with SQL Server 2019 preview, you can find download instructions on the SQL Server 2019 web page.

We look forward to working with and learning from you!

The post Confidential computing using Always Encrypted with secure enclaves in SQL Server 2019 preview appeared first on Microsoft SQL Server Blog.

]]>
http://approjects.co.za/?big=en-us/sql-server/blog/2018/12/17/confidential-computing-using-always-encrypted-with-secure-enclaves-in-sql-server-2019-preview/feed/ 2