1 - Assign a managed identity to Server1. 2 - Create an Azure key vault and grant the managed identity permissions to the key vault. 3 - Add key1 to the Azure key vault. 4 - Configure key1 as the TDE protector for Server1. 5 - Enable TDE on Pool1. Reference: https://docs.microsoft.com/en-us/azure/azure-sql/managed-instance/scripts/transparent-data-encryption-byok-powershell