1 - Create an Azure AD service principal and grant the service principal permission for Vault1. 2 - On SQL1, create an asymmetric key. 3 - On SQL1, create a cryptographic provider and a Microsoft SQL Server credential. 4 - On SQL1, create a login from the asymmetric key.