If you are backing up a database that uses cell encryption keys, you should ensure that all sensitive data is encrypted first before back-up commences. Before back-up, remove the cell encryption key references from the database itself. If key references are not removed from the database, they will be stored within the database back-up. This should be avoided from a security point of view. If you are backing up a database that is both cell and TDE encrypted, perform the above instructions for the cell encryption keys before continuing with the following instructions for backing up a TDE encrypted database.
When backing up a TDE encrypted database, you must have the TDE credential and database wrapping key (TDEKEK) present.
Your backup will include data content of your selected database, but may not include backups of SQL Server logins or credentials. For further details, see the Microsoft SQL Server documentation.
Important:
If you plan to restore this backup to an alternate database, we recommend that you retrieve the thumbprint of the master key before the backup. This will be required when you restore the backup. Because administrators usually rotate the master key after creating a backup, you will not be able to fetch the thumbprint at that time.
Use the following SQL statements to get the thumbprint:
use master
GO
SELECT DB_NAME(database_id) AS DatabaseName,encryption_state,percent_complete,encryptor_thumbprint, encryptor_type FROM sys.dm_database_encryption_keys
GO
Select * from sys.dm_database_encryption_keys
Select * from sys.asymmetric_keys
GOUse the following SQL statement to backup the encrypted database:
BACKUP DATABASE [testdb] TO DISK = N'D:\testdb.bak'