Transparent Data Encryption
Transparent Data Encryption (TDE) encrypts the user data at rest and therefore protects the database from offline malicious activity. TDE is enabled by default in newly deployed SQL databases and managed instances. TDE encrypts/decrypts the database, transaction log, and database backups in real time without any change in the application.
TDE works by encrypting each page before writing it to disk and decrypting each page when reading it from the disk. The encryption is done using a symmetric key known as a database encryption key (DEK). The DEK is protected by a TDE protector, which is either a service-managed certificate or a customer-managed asymmetric key stored in a key vault.
For more details on TDE, refer to https://docs.microsoft.com/azure/azure-sql/database/transparent-data-encryption-tde-overview.