QuestionQ44

Implement a secure environment

You have a SQL pool in Azure Synapse that includes a table named dbo.Customers. The table has a column named Email.

You need to stop nonadministrative users from viewing complete email addresses in the Email column. Instead, users must see values in the format [email protected].

What should you do?

Explanation

Dynamic data masking hides sensitive values in query results for nonprivileged users while retaining the original values in the database. An email mask exposes only a limited email-style value, such as aXX@XXXX.com. Azure Synapse Analytics supports dynamic data masking for dedicated SQL pools; configuring the mask with T-SQL through SQL Server Management Studio satisfies this requirement. Sensitivity classification does not mask returned data, and column-level SELECT denial prevents access instead of returning a masked value.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!