Book Image

Professional Azure SQL Managed Database Administration - Third Edition

By : Ahmad Osama, Shashikant Shakya
Book Image

Professional Azure SQL Managed Database Administration - Third Edition

By: Ahmad Osama, Shashikant Shakya

Overview of this book

Despite being the cloud version of SQL Server, Azure SQL Database and Azure SQL Managed Instance stands out in various aspects when it comes to management, maintenance, and administration. Updated with the latest Azure features, Professional Azure SQL Managed Database Administration continues to be a comprehensive guide for becoming proficient in data management. The book begins by introducing you to the Azure SQL managed databases (Azure SQL Database and Azure SQL Managed Instance), explaining their architecture, and how they differ from an on-premises SQL server. You will then learn how to perform common tasks, such as migrating, backing up, and restoring a SQL Server database to an Azure database. As you progress, you will study how you can save costs and manage and scale multiple SQL databases using elastic pools. You will also implement a disaster recovery solution using standard and active geo-replication. Finally, you will explore the monitoring and tuning of databases, the key features of databases, and the phenomenon of app modernization. By the end of this book, you will have mastered the key aspects of an Azure SQL database and Azure SQL managed instance, including migration, backup restorations, performance optimization, high availability, and disaster recovery.
Table of Contents (14 chapters)
13
Index

Securing data traffic

SQL Database and SQL Managed instance data traffic is always encrypted if the client driver supports SSL/TLS encryption. Data between a managed instance, a SQL database, and an Azure VM or any Azure service never leaves the Azure backbone network. All the communication within Azure happens using this Azure backbone. For on-premises connections, Microsoft recommends setting up Azure ExpressRoute, which helps to avoid sending data over the internet. For public endpoint access, Microsoft peering configuration is required for an ExpressRoute circuit for public communication.

Let's look at how to enforce a minimum Transport Layer Security (TLS) version for SQL Database or SQL Managed Instance.

Enforcing a minimal TLS version for SQL Database and SQL Managed Instance

A minimum TLS version allows users to control the version of TLS used by SQL Database and SQL Managed Instance.

Currently, SQL Database and SQL Managed Instance support TLS 1.0, 1.1...