Your database
Security & compliance
Encryption at rest off (SQL Server TDE)
Part of the Database security posture check · fix arrives as a guide
What it is
Transparent Data Encryption is not enabled on a SQL Server database.
Why it matters
Data files, log files, and backups are stored unencrypted, so anyone who obtains the files — from a backup share, a snapshot, or a decommissioned disk — reads the contents without needing database credentials.
How to fix it
Enable TDE on the database and confirm the certificate is backed up and stored separately. Without that backup, an encrypted database cannot be restored elsewhere.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.