quovadis
Honorary Master
TDE is fairly easy to implement, so is FDE. You may as well encrypt it all. If the data is sensitive enough and it's worth the effort, then introduce record level encryption too.
"Access to the endpoint" is a little vague. Please explain.
You're conflating so many issues its absolutely painful. Maybe google endpoint and copy and paste some more.