For the complete documentation index, see llms.txt. This page is also available as Markdown.

Configure Agentless Scanning

Agentless scanning provides visibility into vulnerabilities and compliance risks on cloud workloads by scanning the root volumes of snapshots. The agentless scanning architecture lets you inspect a host and the container images in that host without having to install an agent or affecting its execution.

To learn more about the architecture and scan results, see How agentless scanning works?

To configure agentless scanning for your cloud accounts, you must onboard the accounts to Prisma Cloud.

Ensure you can connect to the Prisma Cloud Console over HTTPS from your cloud account. Ideally, your security group denies all incoming traffic and allows one egress port. Review the egress port configuration needed to enable access to the Prisma Cloud console.

Complete the steps in the following pages to enable agentless scanning as you onboard accounts from the supported cloud providers.

When you onboard the account on Prisma Cloud, you can grant the needed permissions for all accounts in your organization. The onboarded accounts show up in Runtime Security > Manage > Cloud accounts after up to 24 hours.

You can change the configuration after onboarding your cloud accounts in Runtime Security > Manage > Cloud accounts.

Disable Accounts

When you disable an account in Prisma Cloud, the account remains available under Runtime Security > Manage > Cloud accounts for up to 24 hours. After that time, the disabled account is removed from Runtime Security > Manage > Cloud accounts. Until the account is removed, errors occur when you run discovery, agentless, or serverless scans. Any updates to the disabled account are ignored.

The disabled account is marked as deleted in Runtime Security > Manage > Cloud accounts with a garbage bin icon next to it, and you can delete it safely. If you had deleted the account in Runtime Security > Manage > Cloud accounts but then disabled it, the account will show up again in Runtime Security > Manage > Cloud accounts with a garbage bin icon next to it, and you can delete it safely.

Bulk Actions

Prisma Cloud supports performing agentless configuration at scale. Different cloud providers and authentication subtypes require different configuration fields, which also limits your ability to change accounts in bulk. The Prisma Cloud Console displays all the configuration fields that can be changed across all the selected accounts, and hides those that differ to prevent accidental misconfiguration.

Only change the configuration of multiple accounts from the same cloud provider and of the same authentication subtype. If you select accounts from different providers, you can’t change agentless configuration fields.

The following procedure shows the steps needed to configure agentless scanning for multiple accounts at the same time.

  1. Go to Runtime Security > Manage > Cloud accounts

    manage cloud accounts
  2. Select multiple accounts.

    Only select accounts from the same cloud provider and of the same authentication subtype. If you select accounts from different providers, you can’t change agentless configuration fields.

  3. Click the Bulk actions dropdown.

  4. Select the Agentless configuration button.

    bulk actions
  5. Change the configuration values for the selected accounts.

    agentless configuration bulk
    • Select Save to save the configuration for the selected accounts.

Last updated

Was this helpful?