SSMS v19/v20连接Always Encrypted表时无认证弹窗的解决求助
- 数据库内有多张包含Always Encrypted列的表
- 使用SSMS v18连接(地址格式:
数据库名,端口)时,会自动弹出Azure账号认证窗口,选择有权限账号后可正常查看明文数据 - 使用SSMS v19或v20连接(地址格式:
数据库名.mycompanyname.com,端口)时,无认证弹窗,查询表时触发解密失败报错,信息如下:
Msg 0, Level 11, State 0, Line 2
Failed to decrypt column 'MyColumn'.
Msg 0, Level 11, State 0, Line 2
Failed to decrypt a column encryption key using key store provider: 'AZURE_KEY_VAULT'. Verify the properties of the column encryption key and its column master key in your database. The last 10 bytes of the encrypted column encryption key are: 'AA-BB-CC-DD-EE-F7-60-A2-23-C7'.
Msg 0, Level 11, State 0, Line 2
Retry failed after 4 tries. Retry settings can be adjusted in ClientOptions.Retry or by configuring a custom retry policy in ClientOptions.RetryPolicy.
1. 配置SSMS的Always Encrypted认证设置
打开SSMS v19/v20的连接窗口:
- 点击「选项 >>」切换到高级设置
- 选择「Always Encrypted」标签页,勾选启用Always Encrypted(列加密)
- 确认「Azure Key Vault认证方式」设置为交互式认证(弹出窗口),若无该选项,勾选「使用Azure Active Directory交互式认证」相关项
- 保存设置后重新连接数据库
2. 验证连接地址格式的影响
尝试在v19/v20中改用v18的连接格式(数据库名,端口)重新连接:
- 若改用旧格式后弹窗正常,说明
数据库名.mycompanyname.com地址可能存在DNS或路由限制,导致客户端无法触发Azure Key Vault认证流程,需联系运维确认域名解析的正确性
3. 确认Azure账户权限与SSMS账户关联
- 打开SSMS的「工具」->「选项」->「Azure服务」->「账户」,添加并设为默认有权限访问目标Azure Key Vault的账号
- 登录Azure门户,确认该账户拥有目标Key Vault的
Microsoft.KeyVault/vaults/keys/decrypt/action和Microsoft.KeyVault/vaults/keys/encrypt/action权限
4. 强制指定加密连接参数
若以上步骤无效,在连接窗口的「附加连接参数」中添加以下参数,强制启用列加密触发认证:
Column Encryption Setting=Enabled
内容的提问来源于stack exchange,提问作者lem

