MDC70's avatar
MDC70
Advocate I
2 months ago
Status:
New

Support for Always Encrypted / Client-Side Column Encryption in Microsoft Fabric

We currently have two important use cases—one in the financial sector and another in healthcare—where administrators need to manage and operate the platform, but under no circumstances must they be able to read sensitive data.

SQL Server already provides a proven solution for this scenario through Always Encrypted with client-side column encryption. This feature ensures that even database administrators cannot access the plaintext values of highly sensitive columns.

For both use cases, support for a similar capability in Microsoft Fabric would be a key requirement for migration to the platform.

In our scenarios:

  • Sensitive data would remain encrypted at all times within Fabric.
  • Administrators could manage workloads, operations, backups, and performance without being able to view the protected data.
  • If encrypted tables appear in a mirrored database, it would be acceptable for the encrypted columns to remain unreadable.
  • Alternatively, an option to exclude such tables from mirroring would also be a valid approach.

This capability would significantly strengthen Fabric's position for regulated industries such as banking, insurance, healthcare, and public sector organizations where separation of duties and data confidentiality are mandatory requirements.

Question to the community and product team: Are there plans to support a Fabric equivalent of SQL Server's Always Encrypted with client-side key management and column-level encryption?

No CommentsBe the first to comment

Recent ideas