AZ611: Masked columns still readable
A masked column is read through the policy's view, so applying takes SELECT on the table's masked columns away from the app role. Something still grants it: SELECT on the table or those columns to PUBLIC, or to a role the app role belongs to. Revoke that grant, then apply again.
Reported when the policy is applied (rowfence push, apply, a migration), against the database.