> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-cspm-release-information/features-introduced-in-april-2023.md).

# Features Introduced in April 2023

Learn what’s new on Prisma® Cloud in April 2023.

* [New Features Introduced in 23.4.2](#new-features-apr-2)
* [New Features Introduced in 23.4.1](#new-features-apr-1)

## New Features Introduced in 23.4.2

* [New Features](#new-features2)
* [API Ingestions](#api-ingestions2)
* [New Policies](#new-policies2)
* [Policy Updates](#policy-updates2)
* [Changes in Existing Behavior](#changes-in-existing-behavior2)
* [REST API Updates](#rest-api-updates2)
* [Deprecation Notice](#deprecation-notices)

## New Features

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>FEATURE</td><td>DESCRIPTION</td></tr><tr><td><strong>Simplified Onboarding of AWS, Azure, and GCP Cloud Accounts</strong></td><td><p>Prisma Cloud now provides a simplified onboarding experience to adapt to your security priorities in a streamlined manner with support for CSPM, CWPP, Data Security, and Identity Security grouped as Foundational and/or Advanced capabilities (with a few enabled by default). The updated onboarding workflow provides a Faster First Time to Value (FTTV) by allowing you to onboard your <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-aws">AWS</a>, <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-azure-account">Azure</a>, or <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-gcp">GCP</a> cloud accounts and selecting the security capabilities in fewer clicks.</p><p><img src="/files/VxeRwlJvtQesmPDKwcV5" alt="" data-size="original"></p></td></tr><tr><td><strong>Support for New Regions on GCP</strong></td><td><p>Prisma Cloud now ingests data for resources deployed in the Doha and Turin cloud regions on GCP.</p><p>To review a list of supported regions, select "Inventory > Assets", and choose <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/cloud-service-provider-regions-on-prisma-cloud#id091e5e1f-e6d4-42a8-b2ff-85840eb23396_idd6a79d35-57c0-4f25-8309-aceedae32b7a">Cloud Region</a> from the filter drop-down.</p><p><img src="/files/JfBdWGPj7aVWXIXQ5kcr" alt="" data-size="original"></p></td></tr><tr><td><strong>Addition of New IP Addresses</strong></td><td>Prisma Cloud has added new <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/get-started-with-prisma-cloud/enable-access-prisma-cloud-console#id7cb1c15c-a2fa-4072-b074-063158eeec08_idcb6d3cd4-d1bf-450a-b0ec-41c23a4d4280">NAT IP addresses</a> to the existing list. Make sure to review the list and update the IP addresses in your allow lists.</td></tr><tr><td><mark style="background-color:orange;">Enhancement</mark> <strong>Intelligent Network Graph Provides Contextual View</strong></td><td><p>Enhancements to Prisma Cloud’s Investigate Graph provide you with a comprehensive understanding of where your assets are deployed, potential environmental vulnerabilities and their risk level, to help you determine if further investigation is warranted.</p><p>The new <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/investigate-incidents-on-prisma-cloud/investigate-network-incidents-on-prisma-cloud">Intelligent Network Graph</a> now provides a contextual view of cloud traffic patterns by automatically grouping assets based on parent relationships and creating a top-down hierarchy for every IP address associated with Prisma Cloud monitored assets.</p><p>Expand the graph to the level of the asset you’re investigating and select <strong>View Details</strong> link in the sidecar to analyze specific network traffic flows.</p><p>You can also download a CSV report of the traffic flow of your entire network, a node, an instance, or a specific connection between a source and a destination node.</p><p>You can save Searches under <strong>My Saved Searches</strong>. Use Saved Searches to create custom policies to generate alerts when a specific pattern of network flow is detected.</p></td></tr><tr><td><mark style="background-color:orange;">Enhancement</mark> <strong>Adoption Advisor Thresholds</strong></td><td><p>The thresholds on the <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/manage-prisma-cloud-administrators/adoption-advisor">Adoption Advisor</a> are updated to give you a more accurate progress indicator for the following checks:</p><ul><li>Onboard and Configure Cloud Accounts</li><li>Enable Audit Logs</li><li>Enable Flow Logs</li><li>Define Alert Rules</li><li>Policies— Create Config Policies, Create Network Policies, and Create Audit Policies</li></ul><p>With this enhancement, your adoption progress should better reflect the checks you’re enforcing for your business needs, making it easier for you to see how well you’re doing.</p></td></tr><tr><td><mark style="background-color:orange;">Enhancement</mark> <strong>IsSubset method for RQL _Set function</strong></td><td><p>The <code>_Set function</code> is enhanced to add support for the <code>_Set.isSubset</code> method that enables you to identify whether a specific value or comma separated list of values returned by the JSON path of the resource is fully contained within the target list.</p><p>The syntax is:</p><pre><code>_Set.isSubset(&#x3C;path>, &#x3C;targelist>) is [ true | false ]
</code></pre><p>where</p><p><code>&#x3C;path> = JSON path</code></p><p><code>&#x3C;target_list> = a set of strings without any whitespace.</code></p><p>Example:</p><pre><code>config from cloud.resource where api.name= 'aws-ec2-describe-security-groups' AND json.rule = groupName contains rql and _Set.isSubset(tags[*].key,(Name,"no_value",rql***auto)) is true
</code></pre></td></tr></tbody></table>

## API Ingestions

| SERVICE                                                                    | API DETAILS                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Amazon Firewall Manager**                                                | <p><strong>aws-fms-admin-account</strong></p><p>Additional permission required:</p><ul><li><code>fms:GetAdminAccount</code></li></ul><p>You must manually add the permission or update the CFT template to enable them.</p>                                                                                                                                                                                                                          |
| **Amazon Firewall Manager**                                                | <p><strong>aws-fms-compliance-status</strong></p><p>Additional permissions required:</p><ul><li><code>fms:ListPolicies</code></li><li><code>fms:ListComplianceStatus</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                        |
| **Amazon Firewall Manager**                                                | <p><strong>aws-fms-policy</strong></p><p>Additional permissions required:</p><ul><li><code>fms:GetAdminAccount</code></li><li><code>fms:ListPolicies</code></li><li><code>fms:GetPolicy</code></li></ul><p>The Security Audit role only includes the permission <code>fms:ListPolicies</code>.</p><p>You must manually add the permissions or update the CFT template to enable <code>fms:GetPolicy</code> and <code>fms:GetAdminAccount</code>.</p> |
| <mark style="background-color:orange;">Update</mark> **Amazon RDS**        | <p><strong>aws-rds-db-cluster</strong></p><p>This API is updated to include a new field <code>dBclusterParameterGroupArn</code> in the resource JSON.</p>                                                                                                                                                                                                                                                                                            |
| **Azure CDN**                                                              | <p><strong>azure-frontdoor-standardpremium-origin-groups</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Cdn/profiles/read</code></li><li><code>Microsoft.Cdn/profiles/origingroups/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                 |
| **Azure CDN**                                                              | <p><strong>azure-frontdoor-standardpremium-security-policies</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Cdn/profiles/read</code></li><li><code>Microsoft.Cdn/profiles/securitypolicies/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                         |
| <mark style="background-color:orange;">Update</mark> **Azure Event Hubs**  | <p><strong>azure-event-hub-namespace</strong></p><p>This API is updated to include the following new fields in the resource JSON:</p><ul><li><code>MinimumTlsVersion</code></li><li><code>disableLocalAuth</code></li></ul>                                                                                                                                                                                                                          |
| <mark style="background-color:orange;">Update</mark> **Azure Service Bus** | <p><strong>azure-service-bus-namespace</strong></p><p>This API is updated to include a new field <code>MinimumTlsVersion</code> in the resource JSON.</p>                                                                                                                                                                                                                                                                                            |
| **Google Cloud Function**                                                  | <p><strong>gcloud-cloud-function-v2</strong></p><p>Additional permissions required:</p><ul><li><code>cloudfunctions.locations.list</code></li><li><code>cloudfunctions.functions.list</code></li><li><code>cloudfunctions.functions.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                    |
| **Google Cloud Memorystore for Memcached**                                 | <p><strong>gcloud-memorystore-memcached-instance</strong></p><p>Additional permissions required:</p><ul><li><code>memcache.locations.list</code></li><li><code>memcache.instances.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                              |
| **OCI Database**                                                           | <p><strong>oci-database-autonomous-database</strong></p><p>Additional permission required:</p><ul><li><code>AUTONOMOUS\_DATABASE\_INSPECT</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permission.</p>                                                                                                                                                                                     |
| **OCI Database**                                                           | <p><strong>oci-database-db-home</strong></p><p>Additional permission required:</p><ul><li><code>DB\_HOME\_INSPECT</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permission.</p>                                                                                                                                                                                                             |
| **OCI Database**                                                           | <p><strong>oci-database-db-home-patch</strong></p><p>Additional permission required:</p><ul><li><code>DB\_HOME\_INSPECT</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permission.</p>                                                                                                                                                                                                       |
| **OCI Database**                                                           | <p><strong>oci-database-db-system-patch</strong></p><p>Additional permission required:</p><ul><li><code>DB\_SYSTEM\_INSPECT</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permission.</p>                                                                                                                                                                                                   |
| **OCI DataLabeling**                                                       | <p><strong>oci-datalabeling-dataset</strong></p><p>Additional permissions required:</p><ul><li><code>DATA\_LABELING\_DATASET\_INSPECT</code></li><li><code>DATA\_LABELING\_DATASET\_READ</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permissions.</p>                                                                                                                                     |
| **OCI File Storage**                                                       | <p><strong>oci-file-storage-mount-target</strong></p><p>Additional permissions required:</p><ul><li><code>COMPARTMENT\_INSPECT</code></li><li><code>MOUNT\_TARGET\_INSPECT</code></li><li><code>MOUNT\_TARGET\_READ</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permissions.</p>                                                                                                          |
| **OCI JMS**                                                                | <p><strong>oci-jms-fleet</strong></p><p>Additional permissions required:</p><ul><li><code>FLEET\_INSPECT</code></li><li><code>FLEET\_READ</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permissions.</p>                                                                                                                                                                                    |
| **OCI Service Mesh**                                                       | <p><strong>oci-service-mesh-access-policy</strong></p><p>Additional permissions required:</p><ul><li><code>MESH\_ACCESS​\_POLICY\_LIST</code></li><li><code>MESH\_ACCESS​\_POLICY\_READ</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permissions.</p>                                                                                                                                      |
| **OCI Service Mesh**                                                       | <p><strong>oci-service-mesh-virtual-deployment</strong></p><p>Additional permissions required:</p><ul><li><code>MESH\_VIRTUAL​\_DEPLOYMENT\_LIST</code></li><li><code>MESH\_VIRTUAL​\_DEPLOYMENT\_READ</code></li><li><code>MESH\_VIRTUAL\_DEPLOYMENT​\_PROXY\_CONFIG\_READ</code></li><li><code>MESH\_PROXY\_DETAILS\_READ</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permissions.</p>  |
| **OCI Service Mesh**                                                       | <p><strong>oci-service-mesh-meshes</strong></p><p>Additional permissions required:</p><ul><li><code>SERVICE\_MESH\_LIST</code></li><li><code>SERVICE\_MESH\_READ</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permissions.</p>                                                                                                                                                             |
| **OCI Speech**                                                             | <p><strong>oci-speech-transcription-job</strong></p><p>Additional permissions required:</p><ul><li><code>AI\_SERVICE\_SPEECH\_TRANSCRIPTION\_JOB\_INSPECT</code></li><li><code>AI\_SERVICE\_SPEECH\_TRANSCRIPTION\_JOB\_READ</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permissions.</p>                                                                                                 |
| **OCI Vision**                                                             | <p><strong>oci-vision-model</strong></p><p>Additional permissions required:</p><ul><li><code>AI\_SERVICE\_VISION\_MODEL\_INSPECT</code></li><li><code>AI\_SERVICE\_VISION\_MODEL\_READ</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permissions.</p>                                                                                                                                       |
| **OCI Vision**                                                             | <p><strong>oci-vision-project</strong></p><p>Additional permissions required:</p><ul><li><code>AI\_SERVICE\_VISION\_PROJECT\_INSPECT</code></li><li><code>AI\_SERVICE\_VISION\_PROJECT\_READ</code></li></ul><p>You must download and execute the Terraform template from the console to enable the permissions.</p>                                                                                                                                 |

## New Policies

| NEW POLICIES                                                                                                                        | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ----------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Workload Protection Policies**                                                                                                    | <p>For protecting hosts and containers from runtime incidents and detecting vulnerabilities on these workloads, you have 3 new out-of-the-box policies:</p><ul><li>Serverless Functions detected with known Vulnerabilities (Workload Vulnerability)</li><li>Host VM Images detected with known Vulnerabilities (Workload Vulnerability)</li><li>Apps Embedded detected with Runtime Incidents (Workload Incident)</li></ul><p>To find these policies, select <strong>Policies</strong> and filter on the <strong>Policy Type</strong> Workload Incident and Workload Vulnerability.</p><p>The <strong>Apps Embedded detected with Runtime Incidents</strong> policy will only work for GCP GCR and AWS Fargate, not AWS EKS and Azure ACI.</p>                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **AWS EC2 instance publicly exposed with critical/high exploitable vulnerabilities and unusual high volume data transfer activity** | <p>Identifies AWS EC2 instances which are publicly exposed, have critical or high vulnerabilities and high volume data transfer activity. The high volume data transfer could be a data exfiltration attempt. Exfiltration consists of techniques that adversaries may use to steal data from your network. Once they’ve collected data, adversaries often package it to avoid detection while removing it. This can include compression and encryption. Attackers can exploit vulnerabilities on the EC2 instance to compromise the confidentiality, integrity and availability of the affected EC2 instance and perform malicious actions. If network connectivity with remote systems known for high volume data transfer activity is observed on a publicly exposed and exploitable EC2 instance, it could indicate that the instance is already under attack or has been compromised. Immediate attention is required to investigate the high volume data transfer activity, remediate the critical or high vulnerabilities and restrict the public exposure reported for the EC2 instance as soon as possible.</p><p><strong>Policy Severity—</strong> Critical.</p> |
| **AWS EC2 instance publicly exposed with critical/high exploitable vulnerabilities and cryptomining domain request activity**       | <p>Identifies AWS EC2 instances which are publicly exposed and have exploitable vulnerabilities that are connected with remote systems known for cryptomining domain request activities. Cryptomining domain request initiates suspicious DNS queries to domain names that are associated with known crypto-mining pools to generate new coins in cryptocurrencies such as Bitcoin and Monero. The network connectivity with remote systems known for cryptomining domain request on a publicly exposed and exploitable instance indicates that the instance could be under attack or already have been compromised.</p><p><strong>Policy Severity—</strong> Critical.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **AWS EC2 instance publicly exposed with critical/high exploitable vulnerabilities and DGA domain request activity**                | <p>Identifies AWS EC2 instances which are publicly exposed and have exploitable vulnerabilities that are connected with remote systems known for DGA domain request activities. Domain generation algorithms (DGAs) are used to generate pseudo-random domain names, typically in large numbers within the context of establishing a malicious command-and-control (C2) communications channel. The network connectivity with remote systems known for DGA domain request activity on a publicly exposed and exploitable instance indicates that the instance could be under attack or already have been compromised.</p><p><strong>Policy Severity—</strong> Critical.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

## Policy Updates

No Policy Updates for 23.4.2.

## Changes in Existing Behavior

| FEATURE                               | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Rate Limit Exception for GCP APIs** | <p>The API calls from Prisma Cloud now use quota from the onboarded GCP Projects instead of the GCP Project where the service account is created. This change enables Prisma Cloud to ingest resource metadata across multiple projects without exceeding the GCP API rate limits.</p><p>To ensure continuous insights into all of your GCP resources and to prevent rate limit exception errors, follow the steps listed in <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-gcp/prerequisites-to-onboard-gcp#_prerequisites_to_onboard_gcp_organizations_and_projects_rate-limit-exception-for-gcp-apis">prerequisites to onboard GCP</a> and make sure to complete them.</p><p>If you use the Terraform template provided by Prisma Cloud, the required permissions to the GCP service account are automatically enabled.</p><p><strong>Impact</strong>— Not completing the tasks may result in rate limit exception errors for Prisma Cloud’s authorized API calls to GCP.</p> |
| **Update for Google Compute APIs**    | <p>Prisma Cloud now provides global region support, as well as a backend update to the resource ID for <strong>gcloud-compute-internal-lb-backend-service</strong> API. As a result, all resources for these APIs will be deleted and then regenerated on the management console.</p><p>Existing alerts corresponding to these resources will be resolved as Resource\_Updated, and new alerts will be generated against policy violations if any.</p><p><strong>Impact</strong>—You may notice a reduced alert count. However, once the resources for <strong>gcloud-compute-internal-lb-backend-service</strong> resume ingesting data, the alert count will return to the original numbers.</p>                                                                                                                                                                                                                                                                                                                                                                      |

## REST API Updates

| CHANGE                                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Cloud Accounts Endpoints**                      | <p>The following new endpoints are now available for the Cloud Accounts API:</p><ul><li>Save Account Config With Given Attributes - <a href="https://pan.dev/prisma-cloud/api/cspm/save-account-config/">POST /config/v3/account</a></li><li>Fetch Aws Org Master Account Details - <a href="https://pan.dev/prisma-cloud/api/cspm/get-aws-org-cloud-config/">GET /config/v3/account/awsorg/:id</a></li><li>Performs a Permissions Check for the Given PCDS Account (AWS Org) - <a href="https://pan.dev/prisma-cloud/api/cspm/get-status-pcds-aws-org-account/">GET /config/v3/account/awsorg/:id/status</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Data Security Settings Endpoints**              | <p>The following new endpoints are now available for the Data Security Settings API:</p><ul><li>Clone Data Pattern - <a href="https://pan.dev/prisma-cloud/api/cspm/clone-dss-data-pattern/">POST /config/v3/dss-api/data-pattern/clone/dssTenantId/:dssTenantId</a></li><li>List Data Patterns - <a href="https://pan.dev/prisma-cloud/api/cspm/get-all-dss-data-patterns/">GET /config/v3/dss-api/data-pattern/dssTenantId/:dssTenantId</a></li><li>Add Data Pattern - <a href="https://pan.dev/prisma-cloud/api/cspm/add-dss-data-pattern/">POST /config/v3/dss-api/data-pattern/dssTenantId/:dssTenantId</a></li><li>Update Data Pattern - <a href="https://pan.dev/prisma-cloud/api/cspm/update-dss-data-pattern/">PUT /config/v3/dss-api/data-pattern/dssTenantId/:dssTenantId/pattern-id/:patternId</a></li><li>Delete Data Pattern - <a href="https://pan.dev/prisma-cloud/api/cspm/delete-dss-data-pattern/">DELETE /config/v3/dss-api/data-pattern/dssTenantId/:dssTenantId/pattern-id/:patternId</a></li><li>Get Data Pattern by Name - <a href="https://pan.dev/prisma-cloud/api/cspm/get-dss-data-pattern-name/">GET /config/v3/dss-api/data-pattern/name/dssTenantId/:dssTenantId</a></li><li>List Data Profiles - <a href="https://pan.dev/prisma-cloud/api/cspm/get-dss-data-profiles/">GET /config/v3/dss-api/data-profile/dssTenantId/:dssTenantId</a></li><li>Update Data Profile Status - <a href="https://pan.dev/prisma-cloud/api/cspm/enable-disable-dss-data-profiles/">PUT /config/v3/dss-api/data-profile/dssTenantId/:dssTenantId</a></li><li>Add Data Profile - <a href="https://pan.dev/prisma-cloud/api/cspm/add-dss-data-profile/">POST /config/v3/dss-api/data-profile/dssTenantId/:dssTenantId</a></li><li>Get Data Profile Details - <a href="https://pan.dev/prisma-cloud/api/cspm/get-dss-data-profile-details/">GET /config/v3/dss-api/data-profile/dssTenantId/:dssTenantId/id/:profileId</a></li><li>Update Data Profile - <a href="https://pan.dev/prisma-cloud/api/cspm/update-dss-data-profile/">PUT /config/v3/dss-api/data-profile/dssTenantId/:dssTenantId/id/:profileId</a></li><li>Clone Data Profile - <a href="https://pan.dev/prisma-cloud/api/cspm/clone-dss-data-profile/">POST /config/v3/dss-api/data-profile/dssTenantId/:dssTenantId/id/:profileId</a></li><li>Delete Data Profile - <a href="https://pan.dev/prisma-cloud/api/cspm/delete-dss-data-profile/">DELETE /config/v3/dss-api/data-profile/dssTenantId/:dssTenantId/id/:profileId</a></li><li>Get Snippet Configuration - <a href="https://pan.dev/prisma-cloud/api/cspm/get-dss-snippets-config/">GET /config/v3/dss-api/snippets/dssTenantId/:dssTenantId</a></li><li>Update Snippet Configuration - <a href="https://pan.dev/prisma-cloud/api/cspm/update-dss-snippets-config/">POST /config/v3/dss-api/snippets/dssTenantId/:dssTenantId</a></li><li>Perform a Credit Estimation - <a href="https://pan.dev/prisma-cloud/api/cspm/get-credit-estimation/">POST /config/v3/estimated-credits</a></li><li>Update the Resources Scan Config - <a href="https://pan.dev/prisma-cloud/api/cspm/configure-resources/">PUT /config/v3/resource/configure</a></li><li>Fetch All Resources for the PCDS Tenant - <a href="https://pan.dev/prisma-cloud/api/cspm/get-resources/">GET /config/v3/resources</a></li><li>Generate an Azure Terraform Script for all Azure accounts under a PCDS Tenant - <a href="https://pan.dev/prisma-cloud/api/cspm/generate-network-acl-script-by-tenant-id/">GET /config/v3/tenant/acl-script</a></li><li>Fetch the Tenant Config for a PCDS Tenant - <a href="https://pan.dev/prisma-cloud/api/cspm/get-resources/">GET /config/v3/tenant/config</a></li><li>Update the PCDS Tenant Resource Report Frequency - <a href="https://pan.dev/prisma-cloud/api/cspm/update-report-frequency/">PUT /config/v3/tenant/resource/sizing/configure</a></li></ul> |
| **New APIs for Onboarding GCP Cloud Accounts**    | <p>The following new endpoints are now available for the Cloud Accounts API.</p><ul><li>Add GCP Cloud Account- <a href="https://pan.dev/prisma-cloud/api/cspm/add-gcp-cloud-account/#add-gcp-cloud-account">POST /cas/v1/gcp\_account</a></li><li>Update GCP Cloud Account - <a href="https://pan.dev/prisma-cloud/api/cspm/update-gcp-cloud-account/#update-gcp-cloud-account">PUT /cas/v1/gcp\_account/:id</a></li><li>Get GCP Cloud Account Status- <a href="https://pan.dev/prisma-cloud/api/cspm/get-gcp-cloud-account-status/">POST /cas/v1/cloud\_account/status/gcp</a></li><li>Generate and Download the GCP Terraform Template- <a href="https://pan.dev/prisma-cloud/api/cspm/generate-template-link-gcp-gcp/#generate-and-download-the-gcp-terraform-template">POST /cas/v1/gcp\_template</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **New API to Get Cloud Account Deployment Types** | <p>The following new endpoint is added to get the deployment types of a cloud account. This endpoint is supported only for Alibaba account.</p><ul><li>Get Cloud Account Deployment Type - <a href="https://pan.dev/prisma-cloud/api/cspm/get-gcp-cloud-account-status/">GET /cas/v1/cloud/:cloudType/deployment-type</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **New Parameter Added for Alibaba Account**       | <p>A new parameter <code>deployment type</code> is added to the request or response body of the following endpoints. This parameter is supported only for Alibaba accounts.</p><ul><li>Add Cloud Account - <a href="https://pan.dev/prisma-cloud/api/cspm/add-cloud-account/#request-body-to-add-an-alibaba-account">POST /cloud/:cloud\_type</a></li><li>Update Cloud Account - <a href="https://pan.dev/prisma-cloud/api/cspm/update-cloud-account/#request-body-to-update-an-alibaba-account">PUT /cloud/:cloud\_type/:id</a></li><li>List Cloud Accounts - <a href="https://pan.dev/prisma-cloud/api/cspm/get-cloud-accounts/">GET /cloud</a></li><li>List Cloud Org Accounts - <a href="https://pan.dev/prisma-cloud/api/cspm/get-cloud-org-accounts/">GET /cloud/:cloud\_type/:id/project</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

## Deprecation Notice

| **FEATURE**                                                                              | **DESCRIPTION**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ---------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <mark style="background-color:orange;">End of Support for AWS Classic EC2 Service</mark> | The `aws-ec2-classic-instance` API is planned for deprecation at the end of April 2023. As AWS has announced the depreciation of the resource type, Prisma Cloud will no longer ingest the `aws-ec2-classic-instance` API. For more information, see [Retiring EC2-Classic Networking](https://aws.amazon.com/blogs/aws/ec2-classic-is-retiring-heres-how-to-prepare/).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <mark style="background-color:orange;">Prisma Cloud Data Security v1, v2 APIs</mark>     | <p>The following Prisma Cloud Data Security APIs (v1, v2) for AWS cloud account onboarding, data settings, data profiles, snippets, and data patterns are deprecated:</p><p><strong>Cloud Accounts Endpoints</strong></p><ul><li>Add Data Security Config (AWS Org) - <code>POST /dlp/api/config/v2</code></li><li>Update Data Security Config (AWS Org) - <code>PUT /dlp/api/config/v2</code></li><li>Check Data Security Preconditions (AWS Org) - <code>POST /dlp/api/v1/config/awsorg/status</code></li><li>Get Data Security Config (AWS Org) - <code>GET /dlp/api/config/v2/:accountId</code></li></ul><p><strong>Data Security Settings Endpoints</strong></p><ul><li>List Data Resources - <code>GET /dlp/api/v1/resource-inventory/resources</code></li><li>Update Data Scan Config - <code>PUT /dlp/api/config/v2/resource</code></li><li>List Data Patterns - <code>PUT /dlp/api/v1/dss-api/data-pattern</code></li><li>Add Data Pattern - <code>POST /dlp/api/v1/dss-api/data-pattern</code></li><li>Clone Data Pattern - <code>POST /dlp/api/v1/dss-api/data-pattern/clone</code></li><li>Get Data Pattern Details - <code>GET /dlp/api/v1/dss-api/data-pattern/id/:patternId</code></li><li>Get Data Pattern By Name - <code>GET /dlp/api/v1/dss-api/data-pattern/name</code></li><li>Update Data Pattern - <code>PUT /dlp/api/v1/dss-api/data-pattern/:patternId</code></li><li>Delete Data Pattern - <code>DELETE /dlp/api/v1/dss-api/data-pattern/:patternId</code></li><li>List Data Profiles - <code>GET /dlp/api/v1/dss-api/data-profile</code></li><li>Add Data Profile - <code>POST /dlp/api/v1/dss-api/data-profile</code></li><li>Update Data Profile Status - <code>PUT /dlp/api/v1/dss-api/data-profile</code></li><li>Get Data Profile Details - <code>GET /dlp/api/v1/dss-api/data-profile/id/:profileId</code></li><li>Update Data Profile - <code>PUT /dlp/api/v1/dss-api/data-profile/id/:profileId</code></li><li>Clone Data Profile - <code>POST /dlp/api/v1/dss-api/data-profile/id/:profileId</code></li><li>Delete Data Profile - <code>DELETE /dlp/api/v1/dss-api/data-profile/id/:profileId</code></li><li>Get Snippet Configuration - <code>GET /dlp/api/v1/dss-api/snippets</code></li><li>Update Snippet Configuration - <code>POST /dlp/api/v1/dss-api/snippets</code></li></ul> |

## New Features Introduced in 23.4.1

* [New Features](#new-features1)
* [API Ingestions](#api-ingestions1)
* [New Policies](#new-policies1)
* [Policy Updates](#policy-updates1)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates1)
* [Changes in Existing Behavior](#changes-in-existing-behavior1)
* [REST API Updates](#rest-api-updates1)

## New Features

| FEATURE                                                                                 | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| --------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Support for New Region on AWS**                                                       | <p>Prisma Cloud now ingests data for resources deployed in the Hyderabad cloud region on AWS.</p><p>To review a list of supported regions, select "Inventory > Assets", and choose <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/cloud-service-provider-regions-on-prisma-cloud#id091e5e1f-e6d4-42a8-b2ff-85840eb23396_id9c4f8473-140d-4e4a-94a1-523e00ebfbe4">Cloud Region</a> from the filter drop-down.</p><p><img src="/files/XB2bltSfej1DfySsa5B8" alt="" data-size="original"></p> |
| <mark style="background-color:orange;">Enhancement</mark> **OCI Terraform File Update** | Prisma Cloud now supports over 100 IAM policy statements without requiring a service limit increase from OCI. With this change, you must [update](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-oci-account/add-oci-tenant-to-prisma-cloud#:~:text=Update%20an%20Onboarded%20OCI%20Account) your existing Terraform file to enable read permissions for all the supported services necessary for an OCI tenant on Prisma Cloud.                                                      |

## API Ingestions

| SERVICE                                     | API DETAILS                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Azure Virtual WAN**                       | <p><strong>azure-vpn-server-configurations</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Network/vpnServerConfigurations/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                         |
| **Azure Virtual WAN**                       | <p><strong>azure-p2s-vpn-gateway</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Network/p2sVpnGateways/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                            |
| **Google Certificate Authority Service**    | <p><strong>gcloud-certificate-authority-certificate-template</strong></p><p>Additional permissions required:</p><ul><li><code>privateca.locations.list</code></li><li><code>privateca.certificateTemplates.list</code></li><li><code>privateca.certificateTemplates.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p> |
| **Google Traffic Director Network Service** | <p><strong>gcloud-traffic-director-network-service-gateway</strong></p><p>Additional permissions required:</p><ul><li><code>networkservices.locations.list</code></li><li><code>networkservices.gateways.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                    |
| **Google Traffic Director Network Service** | <p><strong>gcloud-traffic-director-network-service-mesh</strong></p><p>Additional permissions required:</p><ul><li><code>networkservices.locations.list</code></li><li><code>networkservices.meshes.list</code></li><li><code>networkservices.meshes.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                |

## New Policies

| NEW POLICIES                                                                                                  | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **AWS EC2 instance publicly exposed with critical/high exploitable vulnerabilities and malware activity**     | <p>Identifies AWS EC2 instances which are publicly exposed and have exploitable vulnerabilities that are connected with remote systems known for malware activities. Malware includes viruses, trojans, worms and other types of malware that affect the popular open-source operating system. The network connectivity with remote systems known for malware activity on a publicly exposed and exploitable instance indicates that the instance could be under attack or already have been compromised.</p><p><strong>Policy Severity—</strong> Critical.</p>                                            |
| **AWS EC2 instance publicly exposed with critical/high exploitable vulnerabilities and botnet activity**      | <p>Identifies AWS EC2 instances which are publicly exposed and have exploitable vulnerabilities that are connected with remote systems known for botnet activities. A Botnets can be used to perform distributed denial-of-service (DDoS) attacks, steal data, send spam, and allows the attacker to access the device and its connection. The network connectivity with remote systems known for botnet activity on a publicly exposed and exploitable instance indicates that the instance could be under attack or already have been compromised.</p><p><strong>Policy Severity—</strong> Critical.</p> |
| **AWS EC2 instance publicly exposed with critical/high exploitable vulnerabilities and cryptominer activity** | <p>Identifies AWS EC2 instances which are publicly exposed and have exploitable vulnerabilities that are connected with remote systems known for cryptominer activities. Cryptominer hides on computers or mobile devices to surreptitiously use the machine’s resources to mine cryptocurrencies. The network connectivity with remote systems known for cryptominer activity on a publicly exposed and exploitable instance indicates that the instance could be under attack or already have been compromised.</p><p><strong>Policy Severity—</strong> Critical.</p>                                    |
| **AWS EC2 instance publicly exposed with critical/high exploitable vulnerabilities and backdoor activity**    | <p>Identifies AWS EC2 instances which are publicly exposed and have exploitable vulnerabilities that are connected with remote systems known for backdoor activities. A backdoor allows unauthorized remote access to the instances where the malware is installed while bypassing the authentication mechanisms in place. The network connectivity with remote systems known for backdoor activity on a publicly exposed and exploitable instance indicates that the instance could be under attack or already have been compromised.</p><p><strong>Policy Severity—</strong> Critical.</p>               |

## Policy Updates

No Policy Updates for 23.4.1.

## New Compliance Benchmarks and Updates

| COMPLIANCE BENCHMARK               | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Support for ISO/IEC 27001:2022** | <p>Prisma Cloud now supports the ISO/IEC 27001:2022 compliance standard.</p><p>ISO/IEC 27001:2022 provides guidelines for organizational information security standards and information security management practices, including the selection, implementation, and management of controls while taking the organization’s information security risk environment into account.</p><p>With this support, you can now view this built-in standard and the related policies on Prisma Cloud’s <strong>Compliance > Standard</strong> page. Additionally, you can generate reports for immediate viewing or download, or you can schedule recurring reports to keep track of this compliance standard over time.</p> |

## Changes in Existing Behavior

| FEATURE                                                                                                      | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Changes to Policy Severity Level** <mark style="background-color:orange;">First announced in 23.2.1</mark> | <p>Prisma Cloud updated the system default policies to help you identify critical alerts and address them effectively. The policy severity levels for some system default policies are re-aligned to use the newly introduced <strong>Critical</strong> and <strong>Informational</strong> severities. Due to this change, the policies have five levels of severity; Critical, High, Medium, Low, and Informational. You can prioritize critical alerts first and then move on to the other levels.</p><p><strong>Impact—</strong></p><ul><li>Your existing open alerts associated with updated policies will have a change in their severity levels.</li><li>If you have Alert rules set up based on the <strong>Policy Severity</strong> filter, there may be a decrease or increase in the number of alerts.</li><li>The overall Compliance posture may change due to possible alert number changes.</li><li>If you have alert rules configured for external integrations such as ServiceNow, this shift in the number of alerts may result in sending notifications for the Resolved or Open alerts.</li><li>If you change a custom severity of a policy back to the default severity, the new severity update will apply.</li></ul><p>This update will not affect the severities of your custom policies or the system default policies for which you have manually changed the severities (custom severity). Also, if you have included a policy in at least one other alert rule \`(not based on severity filter)], there will be no change in the alert numbers.</p><p>If you have any questions, contact your Prisma Cloud Customer Success Representative.</p> |
| **Update for Google Compute APIs**                                                                           | <p>Prisma Cloud now provides global region support, as well as a backend update to the resource ID for <strong>gcloud-compute-url-maps</strong>, <strong>gcloud-compute-target-http-proxies</strong>, and <strong>gcloud-compute-target-https-proxies</strong> APIs. As a result, all resources for these APIs will be deleted and then regenerated on the management console.</p><p>Existing alerts corresponding to these resources will be resolved as Resource\_Updated, and new alerts will be generated against policy violations if any.</p><p><strong>Impact</strong>—You may notice a reduced alert count. However, once the resources for <strong>gcloud-compute-url-maps</strong>, <strong>gcloud-compute-target-http-proxies</strong>, and <strong>gcloud-compute-target-https-proxies</strong> resume ingesting data, the alert count will return to the original numbers.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |

## REST API Updates

| CHANGE                                           | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **New APIs for Onboarding Azure Cloud Accounts** | <p>The following new endpoints are now available for the Cloud Accounts API.</p><ul><li>Add Azure Cloud Account- <a href="https://pan.dev/prisma-cloud/api/cspm/add-azure-cloud-account/">POST /cas/v1/azure\_account</a></li><li>Update Azure Cloud Account- <a href="https://pan.dev/prisma-cloud/api/cspm/update-azure-cloud-account/">PUT /cas/v1/azure\_account/:account\_id</a></li><li>Generate and Download the Azure Terraform Template- <a href="https://pan.dev/prisma-cloud/api/cspm/generate-template-link/">POST /cas/v1/azure\_template</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **New APIs for Data Security Onboarding**        | <p>The following new endpoints are now available for the Data Security Onboarding API.</p><ul><li>Fetch Account Config By Storage UUID- <a href="https://pan.dev/prisma-cloud/api/cspm/get-account-config-by-storage-uuid/">GET /config/v3/account/storageUUID/:id</a></li><li>Fetch Account Config By PCDS Account ID- <a href="https://pan.dev/prisma-cloud/api/cspm/get-account-config-by-pcds-account-id/">GET /config/v3/account/:id</a></li><li>Update the account config for the specified PCDS Account ID- <a href="https://pan.dev/prisma-cloud/api/cspm/update-pcds-account-config/">PUT /config/v3/account/:id</a></li><li>Performs a Permissions Check for the Given PCDS Account- <a href="https://pan.dev/prisma-cloud/api/cspm/get-status-pcds-account/">GET /config/v3/account/:id/status</a></li><li>Generate an Azure Terraform Script- <a href="https://pan.dev/prisma-cloud/api/cspm/generate-network-acl-script-by-account-id/">GET /config/v3/account/:subscriptionId/acl-script</a></li><li>Generate an Azure Terraform Script- <a href="https://pan.dev/prisma-cloud/api/cspm/get-azure-terraform-script/">GET /config/v3/tenant/:tenantId/:subscriptionId/terraform-script</a></li></ul> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-cspm-release-information/features-introduced-in-april-2023.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
