The Encryption keys can only be stored in either Azure Key vault or the windows certificate store. From the implementation shown below, you can see that these are the sources you can use for storing the encryption keys. https://docs.microsoft.com/en-us/azure/azure-sql/database/always-encrypted-azure-key-vault- configure?tabs=azure-powershell