For the complete documentation index, see llms.txt. This page is also available as Markdown.

Credentials Store

Prisma Cloud seamlessly integrates with multiple third-party services and cloud providers, ensuring robust security and operational efficiency.

To streamline credential management, the Credentials Store (accessible under Manage > Authentication > Credentials Store) serves as a secure repository for storing and managing authentication credentials used in integrations.

Prisma Cloud makes a clear distinction between third-party integration credentials and cloud account credentials.

  • Third-party credentials—such as those used for scanning container registries, sending alerts, or managing Defender deployments—are securely stored and managed within the Credentials Store.

  • Cloud account credentials, however, are handled separately. They are not stored in the Credentials Store but are instead onboarded through the Manage > Cloud Accounts page, where Prisma Cloud manages authentication and permissions required for cloud workload protection.

Supported Integrations

The Credentials Store manages credentials used for:

  • Scanning container registries, serverless functions, and other environments

  • Sending alerts via third-party services (e.g., Slack, ServiceNow, email)

  • Deploying and managing Defender DaemonSets

  • Injecting secrets into running containers

The following diagram shows the architecture of the the credentials store.

credentials store arch

Managing Third-Party Credentials in Credentials Store

If a credential is actively in use, it cannot be deleted. To check its usage, select an entry from the credentials table and review the Usages list.

credentials store usage

You can refresh a credential’s values without deleting and reconfiguring the integration. If an integration relies on a credential and you update its parameters (e.g., username, password), Prisma Cloud automatically propagates the new values across the relevant modules.

Managing Cloud Account Credentials

To manage cloud account credentials, use the Manage > Cloud Accounts page under the Runtime Security component. This section handles the authentication and permissions required for cloud workload protection.

For information on onboarding cloud provider accounts, see the following topics: * Amazon Web Services * Microsoft Azure * Google Cloud Platform * Oracle Cloud Infrastructure

Last updated

Was this helpful?