Instead of DataMasing, enable Always Encrypted for the SecurityPin column. Scenario: Users' SecurityPin must be stored in such a way that access to the database does not allow the viewing of SecurityPins. The web application is the only system that should have access to SecurityPins.