> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/look-ahead-planned-updates-on-prisma-cloud/look-ahead-secure-the-infrastructure.md).

# Look Ahead Updates to Secure the Infrastructure

Here are the changes planned in the next Prisma Cloud release to ensure the security of your infrastructure.

Read this section to learn about what is planned in the 26.8.1 CSPM Platform, Agentless Container Host, Agentless Host Security, CIEM, Data Security, and CDEM releases.

The Look Ahead announcements are for an upcoming release and is not a cumulative list of all announcements.

The details and functionalities listed below are a preview and the actual release date is subject to change.

* [API Ingestions](#api-ingestions)
* [Policy Updates](#policy-updates)
* [Deprecation Notices](#deprecation-notices)

### API Ingestions

| Service                                                            | API Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Amazon Bedrock</strong><br></p>                         | <p><strong>aws-bedrock-prompt</strong><br><br>Additional permissions required:<br>- <code>bedrock:ListPrompts</code><br>- <code>bedrock:GetPrompt</code><br>- <code>bedrock:ListTagsForResource</code><br><br>The Security Audit role does not include <code>bedrock:GetPrompt</code>. A custom role is required.</p>                                                                                                                                                                                                                                     |
| <p><strong>Amazon Bedrock</strong><br></p>                         | <p><strong>aws-bedrock-flow</strong><br><br>Additional permissions required:<br>- <code>bedrock:ListFlows</code><br>- <code>bedrock:GetFlow</code><br>- <code>bedrock:ListTagsForResource</code><br><br>The Security Audit role does not include <code>bedrock:GetFlow</code>. A custom role is required.</p>                                                                                                                                                                                                                                             |
| <p><strong>Amazon Bedrock</strong><br></p>                         | <p><strong>aws-bedrock-flow-alias</strong><br><br>Additional permissions required:<br>- <code>bedrock:ListFlows</code><br>- <code>bedrock:ListFlowAliases</code><br>- <code>bedrock:GetFlowAlias</code><br>- <code>bedrock:ListTagsForResource</code><br><br>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                        |
| <p><strong>Amazon Bedrock</strong><br></p>                         | <p><strong>aws-bedrock-guardrail</strong><br><br>Additional permissions required:<br>- <code>bedrock:ListGuardrails</code><br>- <code>bedrock:GetGuardrail</code><br>- <code>bedrock:ListTagsForResource</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                           |
| <p><strong>Amazon Bedrock AgentCore</strong><br></p>               | <p><strong>aws-bedrock-agentcore-browser-session</strong><br><br>Additional permissions required:<br>- <code>bedrock-agentcore:ListBrowsers</code><br>- <code>bedrock-agentcore:ListBrowserSessions</code><br>- <code>bedrock-agentcore:GetBrowserSession</code><br><br>The Security Audit role includes <code>bedrock-agentcore:ListBrowsers</code>. A custom role is required for <code>bedrock-agentcore:ListBrowserSessions</code> and <code>bedrock-agentcore:GetBrowserSession</code>.</p>                                                          |
| <p><strong>Amazon Bedrock AgentCore</strong><br></p>               | <p><strong>aws-bedrock-agentcore-code-interpreter-session</strong><br><br>Additional permissions required:<br>- <code>bedrock-agentcore:ListCodeInterpreters</code><br>- <code>bedrock-agentcore:ListCodeInterpreterSessions</code><br>- <code>bedrock-agentcore:GetCodeInterpreterSession</code><br><br>The Security Audit role includes <code>bedrock-agentcore:ListCodeInterpreters</code>. A custom role is required for <code>bedrock-agentcore:ListCodeInterpreterSessions</code> and <code>bedrock-agentcore:GetCodeInterpreterSession</code>.</p> |
| <p><strong>Amazon AppFlow</strong><br></p>                         | <p><strong>aws-appflow-connector</strong><br><br>Additional permissions required:<br>- <code>appflow:DescribeConnectors</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Amazon CloudFront</strong><br></p>                      | <p><strong>aws-cloudfront-vpc-origin</strong><br><br>Additional permissions required:<br>- <code>cloudfront:ListVpcOrigins</code><br><br>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Amazon Connect</strong><br></p>                         | <p><strong>aws-connect-contact-flow</strong><br><br>Additional permissions required:<br>- <code>connect:ListInstances</code><br>- <code>connect:ListContactFlows</code><br>- <code>connect:DescribeContactFlow</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                     |
| <p><strong>Amazon Connect</strong><br></p>                         | <p><strong>aws-connect-security-profile-application</strong><br><br>Additional permissions required:<br>- <code>connect:ListInstances</code><br>- <code>connect:ListSecurityProfiles</code><br>- <code>connect:ListSecurityProfileApplications</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                     |
| <p><strong>Amazon Connect</strong><br></p>                         | <p><strong>aws-qconnect-assistant</strong><br><br>Additional permissions required:<br>- <code>wisdom:ListAssistants</code><br>- <code>wisdom:GetAssistant</code><br>- <code>wisdom:ListTagsForResource</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                             |
| <p><strong>AWS Database Migration Service</strong><br></p>         | <p><strong>aws-dms-data-migration</strong><br><br>Additional permissions required:<br>- <code>dms:DescribeDataMigrations</code><br><br>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Amazon EC2 Image Builder</strong><br></p>               | <p><strong>aws-imagebuilder-lifecycle-policy</strong><br><br>Additional permissions required:<br>- <code>imagebuilder:ListLifecyclePolicies</code><br>- <code>imagebuilder:GetLifecyclePolicy</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                                      |
| <p><strong>Amazon Elastic Load Balancing</strong><br></p>          | <p><strong>aws-elbv2-describe-load-balancers</strong> (update)<br><br>The API now ingests additional listener-level attributes, including routing, mTLS/TLS header routing, CORS, and security-header response attributes.<br><br>Additional permissions required:<br>- <code>elasticloadbalancing:DescribeListenerAttributes</code><br><br>The Security Audit role includes the permissions.</p>                                                                                                                                                         |
| <p><strong>AWS Glue</strong><br></p>                               | <p><strong>aws-glue-table</strong><br><br>Additional permissions required:<br>- <code>glue:GetDatabases</code><br>- <code>glue:GetTables</code><br>- <code>glue:GetTable</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                                                           |
| <p><strong>AWS Lambda</strong><br></p>                             | <p><strong>aws-lambda-get-function-recursion-config</strong><br><br>Additional permissions required:<br>- <code>lambda:ListFunctions</code><br>- <code>lambda:GetFunction</code><br>- <code>lambda:GetFunctionRecursionConfig</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                      |
| <p><strong>Amazon Route53 Resolver</strong><br></p>                | <p><strong>aws-route53resolver-dnssec-config</strong><br><br>Additional permissions required:<br>- <code>route53resolver:ListResolverDnssecConfigs</code><br>- <code>route53resolver:GetResolverDnssecConfig</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                       |
| <p><strong>Amazon S3</strong><br></p>                              | <p><strong>aws-s3api-get-bucket-acl</strong> (update)<br><br>The API now ingests the additional attribute <code>bucketKeyEnabled</code>.</p>                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Amazon SageMaker</strong><br></p>                       | <p><strong>aws-sagemaker-mlflow-tracking-server</strong><br><br>Additional permissions required:<br>- <code>sagemaker:ListMlflowTrackingServers</code><br>- <code>sagemaker:DescribeMlflowTrackingServer</code><br>- <code>sagemaker:ListTags</code><br><br>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                         |
| <p><strong>AWS Systems Manager</strong><br></p>                    | <p><strong>aws-ssm-command-invocation</strong><br><br>Additional permissions required:<br>- <code>ssm:ListCommandInvocations</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                                                                                                       |
| <p><strong>AWS Systems Manager</strong><br></p>                    | <p><strong>aws-ssm-ops-item-related-item</strong><br><br>Additional permissions required:<br>- <code>ssm:DescribeOpsItems</code><br>- <code>ssm:ListOpsItemRelatedItems</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                                                            |
| <p><strong>AWS Systems Manager</strong><br></p>                    | <p><strong>aws-ssm-ops-metadata</strong><br><br>Additional permissions required:<br>- <code>ssm:ListOpsMetadata</code><br>- <code>ssm:GetOpsMetadata</code><br>- <code>ssm:ListTagsForResource</code><br><br>The Security Audit role includes <code>ssm:ListOpsMetadata</code> and <code>ssm:GetOpsMetadata</code>. A custom role is required for <code>ssm:ListTagsForResource</code>.</p>                                                                                                                                                               |
| <p><strong>AWS Systems Manager</strong><br></p>                    | <p><strong>aws-ssm-quicksetup-configuration</strong><br><br>Additional permissions required:<br>- <code>ssm-quicksetup:ListConfigurations</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                                                                                          |
| <p><strong>Amazon Textract</strong><br></p>                        | <p><strong>aws-textract-adapter</strong><br><br>Additional permissions required:<br>- <code>textract:ListAdapters</code><br>- <code>textract:GetAdapter</code><br><br>The Security Audit role does not include the permissions. A custom role is required.</p>                                                                                                                                                                                                                                                                                            |
| <p><strong>Google BigQuery</strong><br></p>                        | <p><strong>gcloud-bigquery-model</strong><br><br>Additional permissions required:<br>- <code>bigquery.datasets.get</code><br>- <code>bigquery.models.list</code><br><br>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>Google Cloud Conversational Insights</strong><br></p>   | <p><strong>gcloud-conversational-insights-conversation-analysis</strong><br><br>Additional permissions required:<br>- <code>contactcenterinsights.conversations.list</code><br>- <code>contactcenterinsights.analyses.list</code><br><br>The Viewer role includes the permissions.<br><br>> <strong>Note:</strong> This API is not enabled by default and can be enabled on request.</p>                                                                                                                                                                  |
| <p><strong>Google Cloud Customer Engagement Suite</strong><br></p> | <p><strong>gcloud-ces-app</strong><br><br>Additional permissions required:<br>- <code>ces.locations.list</code><br>- <code>ces.apps.list</code><br>- <code>ces.apps.get</code><br>- <code>ces.tools.list</code><br>- <code>ces.toolsets.list</code><br><br>The Viewer role includes the permissions.<br><br>> <strong>Note:</strong> This API is not enabled by default and can be enabled on request.</p>                                                                                                                                                |
| <p><strong>Google Cloud Customer Engagement Suite</strong><br></p> | <p><strong>gcloud-ces-app-conversation</strong><br><br>Additional permissions required:<br>- <code>ces.locations.list</code><br>- <code>ces.apps.list</code><br>- <code>ces.conversations.list</code><br>- <code>ces.conversations.get</code><br><br>The Viewer role includes the permissions.<br><br>> <strong>Note:</strong> This API is not enabled by default and can be enabled on request.</p>                                                                                                                                                      |

***

### Policy Updates

| Policy Name                                                                        | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ---------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><strong>GCP Vertex AI Workbench User-Managed Notebook Policies</strong><br></p> | <p><strong>Changes:</strong> The following policies are deprecated because GCP deprecated Vertex AI Workbench user-managed notebooks, with support ending January 30, 2025 and final migration of existing resources on March 30, 2026.<br><br>- GCP Vertex AI Workbench user-managed notebook's JupyterLab interface access mode is set to single user<br>- GCP Vertex AI Workbench user-managed notebook is using default service account with the editor role<br>- GCP Vertex AI Workbench user-managed notebook has vTPM disabled<br>- GCP Vertex AI Workbench user-managed notebook auto-upgrade is disabled<br>- GCP Vertex AI Workbench user-managed notebook has Integrity monitoring disabled<br><br><strong>Impact:</strong> Alerts related to these policies resolve when the policies are deleted.</p> |

### Policy Updates - Metadata

| Policy Name                                                                                                        | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>AWS Application Load Balancer (ALB) is not using the latest predefined security policy</strong><br></p> | <p><strong>Severity:</strong> Low<br><br><strong>Changes:</strong> The RQL is updated to include <code>ELBSecurityPolicy-TLS13-1-2-Res-FIPS-PQ-2025-09</code> as an accepted secure policy, replacing the previously listed <code>ELBSecurityPolicy-TLS13-1-2-FIPS-PQ-2025-09</code>.<br><br><strong>Current RQL:</strong><br><code>\<br>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and listeners\[?any(protocol equals HTTPS and sslPolicy exists and sslPolicy is not member of ('ELBSecurityPolicy-TLS13-1-2-Res-2021-06','ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09','ELBSecurityPolicy-TLS13-1-2-FIPS-PQ-2025-09'))] exists\<br></code><br><br><strong>Updated RQL:</strong><br><code>\<br>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and listeners\[?any(protocol equals HTTPS and sslPolicy exists and sslPolicy is not member of ('ELBSecurityPolicy-TLS13-1-2-Res-2021-06', 'ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09','ELBSecurityPolicy-TLS13-1-2-Res-FIPS-PQ-2025-09'))] exists\<br></code><br><br><strong>Impact:</strong> Low. This update may re-open existing resolved alerts on AWS ALB resources not using the latest AWS recommended security policy.</p> |

### Deprecation Notices

| **Deprecated Endpoints**                                                                                       | **Deprecated** | **Sunset** | **Replacement Endpoints**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| -------------------------------------------------------------------------------------------------------------- | -------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <mark style="background-color:orange;">**Deprecation of Asset Inventory and Compliance Trendline APIs**</mark> | 26.4.1         | -          | <ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/asset-inventory-trend-v-3/">get /asset/v3/inventory/trend</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-method-asset-inventory-trend-v-3/">post /v3/inventory/trend</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-compliance-posture-trend-v-2/">get /v2/compliance/posture/trend</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-compliance-posture-trend-v-2/">post /v2/compliance/posture/trend</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-compliance-posture-trend-for-standard-v-2/">get /v2/compliance/posture/trend:complianceId</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-compliance-posture-trend-for-standard-v-2/">post /v2/compliance/posture/trend/:complianceId</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-compliance-posture-trend-for-requirement-v-2/">get /v2/compliance/posture/trend/:complianceId:requirementId</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-compliance-posture-trend-for-requirement-v-2/">post /v2/compliance/posture/trend/:complianceId/:requirementId</a></li></ul> |
| <mark style="background-color:orange;">**Deprecation of End Timestamp in Config Search**</mark>                | -              | -          | The end timestamp in the date selector for Config Search will soon be deprecated after which it will be ignored for all existing RQLs. You will only need to choose a start timestamp without having to specify the end timestamp.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/look-ahead-planned-updates-on-prisma-cloud/look-ahead-secure-the-infrastructure.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
