It is not possible to restrict permissions of a db_owner, and therefore prevent an administrative account from viewing user data. If there's highly sensitive data in a database, Always Encrypted can be used to safely prevent db_owners or any other DBA from viewing it. Reference: https://learn.microsoft.com/en-us/azure/azure-sql/database/security-best-practice?view=azuresql