Skip to content

Still not right#8844

Merged
Jak-MS merged 2 commits into
MicrosoftDocs:livefrom
chschulsie:patch-1
Apr 19, 2023
Merged

Still not right#8844
Jak-MS merged 2 commits into
MicrosoftDocs:livefrom
chschulsie:patch-1

Conversation

@chschulsie
Copy link
Copy Markdown
Contributor

  • When AKV is behind a firewall, it applies to both user-assigned AND system-assigned managed identity (which was the issue we had). Still not reflected correctly in the documentation.
  • The next sense also does not make sense: Once this option is enabled, available keys can't be listed in the SQL server TDE menu in the Azure portal. It should be either: -- if this option is disabled, available keys can't be listed in the SQL server TDE menu in the Azure portal. or
    -- This option must be enabled for keys to be successfully listed in the SQL server TDE menu in the Azure portal.

- When AKV is behind a firewall, it applies to both user-assigned AND system-assigned managed identity (which was the issue we had). Still not reflected correctly in the documentation. 
- The next sense also does not make sense: Once this option is enabled, available keys can't be listed in the SQL server TDE menu in the Azure portal. It should be either: 
-- if this option is disabled, available keys can't be listed in the SQL server TDE menu in the Azure portal.
or
-- This option must be enabled for keys to be successfully listed in the SQL server TDE menu in the Azure portal.
@prmerger-automator
Copy link
Copy Markdown
Contributor

@chschulsie : Thanks for your contribution! The author(s) have been notified to review your proposed change.

@learn-build-service-prod
Copy link
Copy Markdown
Contributor

Learn Build status updates of commit 06f73f9:

✅ Validation status: passed

File Status Preview URL Details
azure-sql/database/transparent-data-encryption-byok-identity.md ✅Succeeded

For more details, please refer to the build report.

For any questions, please:

@Court72
Copy link
Copy Markdown
Contributor

Court72 commented Apr 13, 2023

@GithubMirek

Can you review the proposed changes?

When the changes are ready for publication, add a #sign-off comment to signal that the PR is ready for the review team to merge.

#label:"aq-pr-triaged"
@MicrosoftDocs/public-repo-pr-review-team

@prmerger-automator prmerger-automator Bot added the aq-pr-triaged tracking label for the PR review team label Apr 13, 2023
Copy link
Copy Markdown
Contributor

@strehan1993 strehan1993 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

'Once this option is enabled'
is correct, once AKV is behind a firewall it's not possible to view the available keys.

Please scope this change to 'or system-assigned managed identity'

## Limitations and known issues

- If the key vault is behind a VNet that uses a firewall, the option to **Allow Trusted Microsoft Services to bypass this firewall** must be enabled in the key vault's **Networking** menu if you want to use a user-assigned managed identity. Once this option is enabled, available keys can't be listed in the SQL server TDE menu in the Azure portal. To set an individual CMK, a *key identifier* must be used. When the option to **Allow Trusted Microsoft Services to bypass this firewall** isn't enabled, the following error is returned:
- If the key vault is behind a VNet that uses a firewall, the option to **Allow Trusted Microsoft Services to bypass this firewall** must be enabled in the key vault's **Networking** menu if you want to use a user-assigned managed identity or system-assigned managed identity. If this option is disabled, available keys can't be listed in the SQL server TDE menu in the Azure portal. To set an individual CMK, a *key identifier* must be used. When the option to **Allow Trusted Microsoft Services to bypass this firewall** isn't enabled, the following error is returned:
Copy link
Copy Markdown
Contributor

@strehan1993 strehan1993 Apr 13, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

'Once this option is enabled'
is correct, once AKV is behind a firewall it's not possible to view the available keys.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reverted the incorrect statement on this.

@learn-build-service-prod
Copy link
Copy Markdown
Contributor

Learn Build status updates of commit cbe419b:

✅ Validation status: passed

File Status Preview URL Details
azure-sql/database/transparent-data-encryption-byok-identity.md ✅Succeeded

For more details, please refer to the build report.

For any questions, please:

@VanMSFT
Copy link
Copy Markdown
Member

VanMSFT commented Apr 19, 2023

#sign-off

@prmerger-automator
Copy link
Copy Markdown
Contributor

Invalid command: '#sign-off'. Only the assigned author of one or more file in this PR can sign off. @GithubMirek

@Jak-MS Jak-MS merged commit 14b28bb into MicrosoftDocs:live Apr 19, 2023
@prmerger-automator
Copy link
Copy Markdown
Contributor

PR 8844 has been merged from chschulsie:patch-1 to MicrosoftDocs:live by Jak-MS.

@chschulsie, @VanMSFT

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants