You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SSMS v19/v20连接Always Encrypted表时无认证弹窗的解决求助

问题描述
  • 数据库内有多张包含Always Encrypted列的表
  • 使用SSMS v18连接(地址格式:数据库名,端口)时,会自动弹出Azure账号认证窗口,选择有权限账号后可正常查看明文数据
  • 使用SSMS v19或v20连接(地址格式:数据库名.mycompanyname.com,端口)时,无认证弹窗,查询表时触发解密失败报错,信息如下:

Msg 0, Level 11, State 0, Line 2
Failed to decrypt column 'MyColumn'.
Msg 0, Level 11, State 0, Line 2
Failed to decrypt a column encryption key using key store provider: 'AZURE_KEY_VAULT'. Verify the properties of the column encryption key and its column master key in your database. The last 10 bytes of the encrypted column encryption key are: 'AA-BB-CC-DD-EE-F7-60-A2-23-C7'.
Msg 0, Level 11, State 0, Line 2
Retry failed after 4 tries. Retry settings can be adjusted in ClientOptions.Retry or by configuring a custom retry policy in ClientOptions.RetryPolicy.

解决步骤

1. 配置SSMS的Always Encrypted认证设置

打开SSMS v19/v20的连接窗口:

  • 点击「选项 >>」切换到高级设置
  • 选择「Always Encrypted」标签页,勾选启用Always Encrypted(列加密)
  • 确认「Azure Key Vault认证方式」设置为交互式认证(弹出窗口),若无该选项,勾选「使用Azure Active Directory交互式认证」相关项
  • 保存设置后重新连接数据库

2. 验证连接地址格式的影响

尝试在v19/v20中改用v18的连接格式(数据库名,端口)重新连接:

  • 若改用旧格式后弹窗正常,说明数据库名.mycompanyname.com地址可能存在DNS或路由限制,导致客户端无法触发Azure Key Vault认证流程,需联系运维确认域名解析的正确性

3. 确认Azure账户权限与SSMS账户关联

  • 打开SSMS的「工具」->「选项」->「Azure服务」->「账户」,添加并设为默认有权限访问目标Azure Key Vault的账号
  • 登录Azure门户,确认该账户拥有目标Key Vault的Microsoft.KeyVault/vaults/keys/decrypt/action和Microsoft.KeyVault/vaults/keys/encrypt/action权限

4. 强制指定加密连接参数

若以上步骤无效,在连接窗口的「附加连接参数」中添加以下参数,强制启用列加密触发认证:

Column Encryption Setting=Enabled

内容的提问来源于stack exchange,提问作者lem

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 16:30:17