Hi @David Chase ,
Please make sure to deploy the certificate to each machine hosting your application/service to the right store location (Local Machine).
Please try to grant the IIS application pool user who's going to run the web app the permission to be able to read private keys. Please refer to Always Encrypted Feature - Failed to decrypt column and Why my app user couldn't find always encrypted certificate which could help.
Best Regards,
Amelia
If the answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.
What can I do if my transaction log is full?--- Hot issues November
How to convert Profiler trace into a SQL Server table -- Hot issues November