---
title: "Get-DbaDbMasterKey"
description: "Retrieves database master key information from SQL Server databases"
url: "https://dbatools.io/Get-DbaDbMasterKey/"
availability: "Windows, Linux, macOS"
tags: ["Certificate", "Security"]
author: "Chrissy LeMaire (@cl), netnerds.net"
source: "https://github.com/dataplat/dbatools/blob/master/public/Get-DbaDbMasterKey.ps1"
last_updated: "2024-01-01"
---

# Get-DbaDbMasterKey

## Synopsis

Retrieves database master key information from SQL Server databases

## Description

Retrieves database master key objects and their metadata from one or more SQL Server databases. Database master keys are used to encrypt sensitive data through features like Transparent Data Encryption (TDE), column-level encryption, and certificate-based encryption. This function helps DBAs inventory encryption keys across their environment for security audits, compliance reporting, and encryption management. Returns key details including creation date, last modified date, and server encryption status.

## Syntax

```powershell
Get-DbaDbMasterKey
    [[-SqlInstance] <DbaInstanceParameter[]>]
    [[-SqlCredential] <PSCredential>]
    [[-Database] <String[]>]
    [[-ExcludeDatabase] <String[]>]
    [[-InputObject] <Database[]>]
    [-EnableException]
    [<CommonParameters>]

```

## Examples

### Example 1: Gets all master database keys

```powershell
PS C:\> Get-DbaDbMasterKey -SqlInstance sql2016
```

### Example 2: Gets the master key for the db1 database

```powershell
PS C:\> Get-DbaDbMasterKey -SqlInstance Server1 -Database db1
```

### Optional Parameters

##### -SqlInstance

The target SQL Server instance

| Property | Value |
| --- | --- |
| Alias |  |
| Required | False |
| Pipeline | false |
| Default Value |  |

##### -SqlCredential

Login to the target instance using alternative credentials. Accepts PowerShell credentials (Get-Credential).  
Windows Authentication, SQL Server Authentication, Active Directory - Password, and Active Directory - Integrated are all supported.  
For MFA support, please use Connect-DbaInstance.

| Property | Value |
| --- | --- |
| Alias |  |
| Required | False |
| Pipeline | false |
| Default Value |  |

##### -Database

Specifies which databases to check for database master keys. Accepts wildcards for pattern matching.  
Use this when you need to audit encryption keys for specific databases instead of scanning all databases on the instance.

| Property | Value |
| --- | --- |
| Alias |  |
| Required | False |
| Pipeline | false |
| Default Value |  |

##### -ExcludeDatabase

Specifies databases to skip when checking for master keys. Accepts wildcards for pattern matching.  
Use this to exclude system databases or databases you know don't use encryption features during security audits.

| Property | Value |
| --- | --- |
| Alias |  |
| Required | False |
| Pipeline | false |
| Default Value |  |

##### -InputObject

Accepts database objects from Get-DbaDatabase through the pipeline for master key analysis.  
Use this when you need to check master keys for databases that match specific criteria like compatibility level or size.

| Property | Value |
| --- | --- |
| Alias |  |
| Required | False |
| Pipeline | true (ByValue) |
| Default Value |  |

##### -EnableException

By default, when something goes wrong we try to catch it, interpret it and give you a friendly warning message.  
This avoids overwhelming you with "sea of red" exceptions, but is inconvenient because it basically disables advanced scripting.  
Using this switch turns this "nice by default" feature off and enables you to catch exceptions with your own try/catch.

| Property | Value |
| --- | --- |
| Alias |  |
| Required | False |
| Pipeline | false |
| Default Value | False |

## Outputs

**Microsoft.SqlServer.Management.Smo.MasterKey**

Returns one MasterKey object per database that contains a master key. If a database does not have a master key, it is skipped (no output for that database).

**Default display properties (via Select-DefaultView):**

- ComputerName: The computer name of the SQL Server instance
- InstanceName: The SQL Server instance name
- SqlInstance: The full SQL Server instance name (computer\instance)
- Database: Name of the database containing the master key
- CreateDate: DateTime when the master key was created
- DateLastModified: DateTime when the master key was last modified
- IsEncryptedByServer: Boolean indicating if the master key is encrypted by the server master key
All properties from the base SMO MasterKey object are accessible via Select-Object *.

---

Part of [dbatools](https://dbatools.io/), a free and open source PowerShell module for SQL Server administration. Full command index: https://dbatools.io/commands/
