Before You Begin
You must connect to the same CSP Vault cluster that the primary SQL Server VM is connected to.
The user group must be the same as the primary VM. The default user group is Cloud Admin Group.
You have to make the keys accessible on this VM in addition to the original VM.
Note: To restore a TDE encrypted database on the same VM, see Restoring the TDE Encrypted Database .
Procedure
Copy the bundle that you downloaded in Downloading the TDE Script Bundle for Microsoft SQL Server.
Extract the bundle on the new VM and copy the modified entrust.conf from the primary and overwrite the configuration file that you just extracted.
Run the following PowerShell script to set up the new client:
PS> .\setup.ps1 -node other -config .\entrust.conf
Note: The
-nodeparameter must beother.Edit the entrust.conf file and update the following parameters:
Parameter
Description
db_server_name
The name of the SQL server instance where you are restoring the backup.
sysadmin_user
If you are using SQL server authentication, then set its value to the correct sysadmin user for the node that you are restoring.
If you are using Windows authentication, keep this line commented out.
sysadmin_password
If you are using SQL Server authentication, you can either write the password here or keep this line commented out to be prompted for the password.
If you are using Windows authentication, keep this line commented out.
Fetch the thumbprint of the master key. This can be done using one of the following ways:
If you retrieved the master key thumbprint immediately before running the backup, you can skip this section.
If you attempt to restore the backup without the thumbprint, the thumbprint is printed in the failure message.
Microsoft SQL Server Management Studio example: