Data Protection by Database

Overview

The Data Protection by Database report is the instance view of the database level Data Protection page. It answers which databases on this instance hold sensitive columns with no protection, and which use Always Encrypted, masking, row-level security or ledger?

Each user database is read with the same query and the same rules as the database page, so the counts and the warnings agree on both.


Columns

Column Meaning
Database The user database.
Status How many findings the database page shows and what the first one is about, “No findings”, or why the database could not be read.
Sensitive Columns that are classified, encrypted or masked, or whose name matches a Sensitive Data rule.
Unprotected Sensitive columns that are neither encrypted, masked nor classified.
Classified Only Sensitive columns that are labeled but not encrypted or masked.
Masked Columns with dynamic data masking.
Encrypted Columns encrypted with Always Encrypted.
RLS Policies / RLS Off Row-level security policies, and how many are disabled.
Master Keys Always Encrypted column master keys.
UNMASK Grants Explicit UNMASK permissions.
Ledger Tables Updatable and append-only ledger tables (SQL Server 2022).

“n/a” means the feature is newer than the instance.


Using it

The databases are read one after another with a progress line and a Cancel button. A database that is offline or that the login cannot open is listed with the reason. Double click a row, or right-click and choose Open Data Protection, to open that database’s page.

On SQL Server 2014 and older, which has none of these features, the page says so.


Report Why you would go there
Sensitive Data by Database Which columns look sensitive in each database, and how many are classified.
TDE Status Encryption at rest for every database.
Permissions Matrix Who can reach each database.
Security Posture The instance level security checks.