Protecting column encryption keys with dual control

You can secure column encryption keys with dual control using the create encryption key command.

If you specify create encryption key with dual_control, but do not specify a user password, the column encryption key is protected by the master key and the dual master key.

If you specify with dual_control and include a user-specific password, the column encryption key is protected by the master key and the user password.

See “Changing a key’s protection method” to alter existing keys to use dual control.