1 - Assign a managed identity to Server1 2 - Create an Azure key vault and grant the managed identity permissions to the vault 3 - Add key1 to the Azure key vault 4 - Configure key1 as the TDE protector for Server1 5 - Enable TDE on Pool1 Reference: https://docs.microsoft.com/en-us/azure/azure-sql/managed-instance/scripts/transparent-data-encryption-byok-powershell