Onboard Accounts for Agentless Scanning
Agentless scanning provides visibility into vulnerabilities and compliance risks on cloud workloads by scanning the root volumes of snapshots. The agentless scanning architecture lets you inspect a host and the container images in that host without having to install an agent or affecting its execution.
To learn more about the architecture and scan results, see How agentless scanning works?
Bulk Actions
Prisma Cloud supports performing agentless configuration at scale. Different cloud providers and authentication subtypes require different configuration fields, which also limits your ability to change accounts in bulk. The Prisma Cloud Console displays all the configuration fields that can be changed across all the selected accounts, and hides those that differ to prevent accidental misconfiguration.
Only change the configuration of multiple accounts from the same cloud provider and of the same authentication subtype. If you select accounts from different providers, you can’t change agentless configuration fields.
The following procedure shows the steps needed to configure agentless scanning for multiple accounts at the same time.
Go to Compute > Manage > Cloud accounts

Select multiple accounts.
Only select accounts from the same cloud provider and of the same authentication subtype. If you select accounts from different providers, you can’t change agentless configuration fields.
Click the Bulk actions dropdown.
Select the Agentless configuration button.

Change the configuration values for the selected accounts.

Select Save to save the configuration for the selected accounts.
Agentless Scanning for Cloud Accounts
During Onboarding: When cloud accounts are onboarded to Prisma Cloud with the "Agentless Scanning" option enabled, scanning starts immediately. This provides instant visibility into the vulnerabilities and configurations risks for the account. If this option is disabled before onboarding, Prisma Cloud does not scan the workloads in the account. The account remains unscanned until agentless scanning is enabled.
To modify the scan settings, see Edit Agentless Scan Settings.
For existing accounts: Enabling agentless scanning for existing accounts in Prisma Cloud does not initiate an immediate scan. Instead, these accounts are added to the next scheduled scan cycle, which occurs every 24 hours by default. This ensures that scans are conducted systematically according to the scan cycle, rather than starting immediately upon enabling.
To modify the scan cycle, see Modify the Agentless Scan Interval.
Account Origin Filter
The Account Origin filter on the Runtime Security > Manage > Cloud Accounts page categorizes cloud accounts based on their source, making it easier to distinguish them during onboarding and scanning:
Local accounts – Accounts created in Runtime Security only (not present in the Prisma Cloud console).
Manually imported accounts – Accounts manually imported from the Prisma Cloud console to Runtime Security before the Lagrange release (end of 2022).
Auto-imported accounts – Accounts that originated in the Prisma Cloud console and were automatically imported into Runtime Security.
Edit Agentless Scan Settings
You can safely enable agentless scanning settings for disabled accounts on the Runtime Security > Manage > Cloud accounts page. After enabling agentless scan, the scan will trigger with the correct configuration in place.
To edit agentless scan settings, complete the following steps:
Go to Runtime Security > Manage > Cloud accounts.
Select Edit Account icon from the Actions column for the account.
In Account and Agentless setup, go to Agentless scanning section.
Modify the agentless configuration options in this section.
Select Save.
After the configuration is modified, the next scan uses the updated settings.
Modify the Agentless Scan Interval
By default, agentless scans are triggered every 24 hours.
To change the interval, complete the following steps.
Go to Runtime Security > Manage > System.
Select the Scan tab.
In the Scheduling section, in Agentless box, type the new duration for the scan cycle.
Select Save

Manually Start Agentless Scanning
To manually start a scan, complete the following steps.
Go to Runtime Security > Manage > Cloud accounts.
In the Scan in your environment section, select Start Agentless scan.

Note: Scanning starts for all the accounts that have the agentless scanning option enabled.
Select the Scan icon in the top-right corner of the console to view the scan status.
To view the results, complete the following steps.
Go to Runtime Security > Monitor > Vulnerabilities > Hosts or Runtime Security > Monitor > Vulnerabilities > Images.
Select Filter hosts.

Select the Scanned by filter.

Select the Agentless filter.

Last updated
Was this helpful?

