> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-cspm-release-information/features-introduced-in-march-2023.md).

# Features Introduced in March 2023

Learn what’s new on Prisma® Cloud in March 2023.

* [New Features Introduced in 23.3.2](#new-features-mar-2)
* [New Features Introduced in 23.3.1](#new-features-mar-1)

## New Features Introduced in 23.3.2

* [New Features](#new-features2)
* [API Ingestions](#api-ingestions2)
* [New Policies](#new-policies2)
* [Policy Updates](#policy-updates2)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates2)
* [Changes in Existing Behavior](#changes-in-existing-behavior2)
* [REST API Updates](#rest-api-updates2)

## New Features

| FEATURE                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Support for New Regions on GCP** | <p>Prisma Cloud now ingests data for resources deployed in the Madrid, Milan, Paris, Tel Aviv, Toronto, Santiago, Columbus, and Dallas cloud regions on GCP.</p><p>To review a list of supported regions, select "Inventory > Assets", and choose <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/cloud-service-provider-regions-on-prisma-cloud#id091e5e1f-e6d4-42a8-b2ff-85840eb23396_idd6a79d35-57c0-4f25-8309-aceedae32b7a">Cloud Region</a> from the filter drop-down.</p><p><img src="/files/6wgDv6Pcfq76aR94EuHH" alt="" data-size="original"></p> |

## API Ingestions

| SERVICE                                                                                       | API DETAILS                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| --------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <mark style="background-color:orange;">Update</mark> **AWS Config**                           | <p><strong>aws-configservice-describe-configuration-recorders</strong></p><p>This API is updated with an additional field <code>region</code> in the resource JSON.</p>                                                                                                                                                                                                                                                                                                             |
| **AWS Network Firewall**                                                                      | <p><strong>aws-network-firewall-firewall-policy</strong></p><p>Additional permissions required:</p><ul><li><code>network-firewall:ListFirewallPolicies</code></li><li><code>network-firewall:DescribeFirewallPolicy</code></li><li><code>network-firewall:DescribeResourcePolicy</code></li></ul><p>You must manually add the permissions or update the CFT template to enable them.</p><p>Not supported in AWS China.</p>                                                          |
| **AWS Network Firewall**                                                                      | <p><strong>aws-network-firewall-firewall</strong></p><p>Additional permissions required:</p><ul><li><code>network-firewall:ListFirewalls</code></li><li><code>network-firewall:DescribeFirewall</code></li></ul><p>The Security Audit role only includes the <code>network-firewall:ListFirewalls</code> permission. You must manually add <code>network-firewall:DescribeFirewall</code> permission or update the CFT template to enable it.</p><p>Not supported in AWS China.</p> |
| **AWS Systems Manager**                                                                       | <p><strong>aws-ssm-resource-compliance-summary</strong></p><p>Additional permission required:</p><ul><li><code>ssm:ListResourceComplianceSummaries</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                          |
| **Google Cloud Firestore**                                                                    | <p><strong>gcloud-cloud-firestore-native-database</strong></p><p>Additional permission required:</p><ul><li><code>datastore.databases.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                          |
| **Google Anthos GKE Fleet Management**                                                        | <p><strong>gcloud-anthos-gke-fleet-membership</strong></p><p>Additional permissions required:</p><ul><li><code>gkehub.locations.list</code></li><li><code>gkehub.memberships.list</code></li><li><code>gkehub.memberships.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                             |
| **Google Anthos GKE Fleet Management**                                                        | <p><strong>gcloud-anthos-gke-fleet-feature</strong></p><p>Additional permissions required:</p><ul><li><code>gkehub.locations.list</code></li><li><code>gkehub.features.list</code></li><li><code>gkehub.features.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                      |
| <mark style="background-color:orange;">Update</mark> **Google Certificate Authority Service** | <p>Additional permission <code>privateca.locations.list</code> is required for the following APIs:</p><ul><li><strong>gcloud-certificate-authority-ca</strong></li><li><strong>gcloud-certificate-authority-certificate</strong></li><li><strong>gcloud-certificate-authority-pool</strong></li><li><strong>gcloud-certificate-authority-revocation-lists</strong></li></ul><p>The Viewer role includes the permission.</p>                                                         |
| <mark style="background-color:orange;">Update</mark> **Google Dataplex**                      | <p><strong>gcloud-dataplex-lake-zone-asset-action</strong></p><p>Additional permission required:</p><ul><li><code>dataplex.locations.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                           |
| <mark style="background-color:orange;">Update</mark> **API Gateway**                          | <p><strong>gcloud-apigateway-gateway</strong></p><p>Additional permission required:</p><ul><li><code>apigateway.locations.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                      |

## New Policies

No New Policies for 23.3.2.

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>POLICY UPDATES</td><td>DESCRIPTION</td></tr><tr><td><strong>Policy Updates-RQL</strong></td><td></td></tr><tr><td><strong>AWS Cloudfront Distribution with S3 have Origin Access set to disabled</strong></td><td><p><strong>Changes—</strong> The policy RQL is updated to include the new feature of AWS origin access control.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-cloudfront-list-distributions' AND json.rule = 'origins.items[*].s3OriginConfig exists and origins.items[*].s3OriginConfig.originAccessIdentity is empty'
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-cloudfront-list-distributions' AND json.rule = 'origins.items[*].s3OriginConfig exists and origins.items[*].s3OriginConfig.originAccessIdentity is empty and origins.items[*].originAccessControlId is empty'
</code></pre><p><strong>Impact—</strong> Medium. Existing open alerts related to AWS feature Origin Access Control will be resolved with resolution as <strong>Policy_Updated</strong>.</p></td></tr><tr><td><strong>AWS access keys not used for more than 90 days</strong></td><td><p><strong>Changes—</strong> The policy name, description, and RQL are updated to meet the compliance standard of 45 days.</p><p><strong>Updated Policy name—</strong> AWS Access key not used for more than 45 days</p><p><strong>Updated Description—</strong> This policy identifies IAM users for which access keys are not used for more than 45 days. Access keys allow users programmatic access to resources. However, if any access key has not been used in the past 45 days, then that access key needs to be deleted (even though the access key is inactive).</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type ='aws' and api.name = 'aws-iam-get-credential-report' AND json.rule = '(access_key_1_active is true and ((access_key_1_last_used_date != N/A and _DateTime.ageInDays(access_key_1_last_used_date) > 90) or (access_key_1_last_used_date == N/A and access_key_1_last_rotated != N/A and _DateTime.ageInDays(access_key_1_last_rotated) > 90))) or (access_key_2_active is true and ((access_key_2_last_used_date != N/A and _DateTime.ageInDays(access_key_2_last_used_date) > 90) or (access_key_2_last_used_date == N/A and access_key_2_last_rotated != N/A and _DateTime.ageInDays(access_key_2_last_rotated) > 90)))'
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type ='aws' and api.name = 'aws-iam-get-credential-report' AND json.rule = '(access_key_1_active is true and ((access_key_1_last_used_date != N/A and _DateTime.ageInDays(access_key_1_last_used_date) > 45) or (access_key_1_last_used_date == N/A and access_key_1_last_rotated != N/A and _DateTime.ageInDays(access_key_1_last_rotated) > 45))) or (access_key_2_active is true and ((access_key_2_last_used_date != N/A and _DateTime.ageInDays(access_key_2_last_used_date) > 45) or (access_key_2_last_used_date == N/A and access_key_2_last_rotated != N/A and _DateTime.ageInDays(access_key_2_last_rotated) > 45)))'
</code></pre><p><strong>Impact—</strong> High. The alert count will increase for access keys that have not been used in more than 45 days.</p></td></tr><tr><td><strong>GCP VM disks not encrypted with Customer-Supplied Encryption Keys (CSEK)</strong></td><td><p><strong>Changes—</strong> The policy RQL is updated to check the GCP compute disks that are not encrypted with CSEK.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcp-compute-disk-list' AND json.rule = diskEncryptionKey does not exist and name does not start with "gke-" and status equals READY
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcp-compute-disk-list' AND json.rule = status equals READY and name does not start with "gke-" and diskEncryptionKey.sha256 does not exist
</code></pre><p><strong>Impact—</strong> Low. New alerts may be generated when the VM disks are not encrypted with CSEK. No impact on existing alerts.</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| COMPLIANCE BENCHMARK               | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Support for ISO/IEC 27002:2022** | <p>Prisma Cloud now supports the ISO/IEC 27002:2022 compliance standard.</p><p>ISO/IEC 27002:2022 provides guidelines for organizational information security standards and information security management practices, including the selection, implementation, and management of controls while taking the organization’s information security risk environment into account.</p><p>With this support, you can now view this built-in standard and the related policies on Prisma Cloud’s <strong>Compliance > Standard</strong> page. Additionally, you can generate reports for immediate viewing or download, or you can schedule recurring reports to keep track of this compliance standard over time.</p> |

## Changes in Existing Behavior

| FEATURE                                                                                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Global Region Support for Target ssl proxy**                                                   | <p>Prisma Cloud now provides global region support for <strong>gcloud-compute-target-ssl-proxy</strong> API. Due to this, all the resources will be deleted and then regenerated on the management console.</p><p>Existing alerts corresponding to these resources are resolved as <strong>Resource\_Updated</strong>, and new alerts will be generated against the policy violations.</p><p><strong>Impact—</strong> You may notice a reduced count for the number of alerts. However, the alert count will return to the original numbers once the resources for <strong>gcloud-compute-target-ssl-proxy</strong> start ingesting data again.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <mark style="background-color:orange;">Update</mark> **Prisma Cloud Data Security IP Addresses** | <p>The list of <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/get-started-with-prisma-cloud/enable-access-prisma-cloud-console">source IP addresses</a> for data security in US and EU regions are updated. Make sure you review the list, add the new IP addresses in your allow lists, and remove the old ones.</p><p><strong>US New IPs (to add)</strong></p><ul><li>3.128.230.117</li><li>3.14.212.156</li><li>3.22.23.119</li><li>20.9.80.30</li><li>20.9.81.254</li><li>20.228.128.132</li><li>20.228.250.145</li><li>20.253.198.116</li><li>20.253.198.147</li></ul><p><strong>US Old IPs (to remove)</strong></p><ul><li>20.121.153.41</li><li>20.121.153.87</li><li>20.121.153.100</li><li>52.226.252.199</li><li>20.121.153.105</li><li>52.226.252.38</li><li>20.119.0.19</li><li>20.12.129.169</li><li>20.221.94.213</li><li>20.12.129.184</li><li>20.12.129.193</li><li>20.12.129.195</li><li>20.12.129.196</li><li>20.118.48.12</li><li>20.121.153.41</li><li>20.121.153.87</li><li>20.121.153.100</li><li>52.226.252.199</li><li>20.121.153.105</li><li>52.226.252.38</li><li>20.119.0.19</li><li>40.118.253.86</li><li>138.91.88.27</li><li>138.91.228.231</li><li>104.42.8.63</li><li>104.42.4.238</li><li>40.118.249.60</li><li>40.112.243.64</li></ul><p><strong>EU New IPs (to add)</strong></p><ul><li>3.64.66.135</li><li>18.198.52.216</li><li>3.127.191.112</li><li>20.223.237.240</li><li>20.238.97.44</li><li>20.26.194.122</li><li>51.142.252.210</li><li>51.124.198.75</li><li>51.124.199.134</li></ul><p><strong>EU Old IPs (to remove)</strong></p><ul><li>20.113.10.157</li><li>20.113.11.130</li><li>20.113.12.29</li><li>20.113.12.30</li><li>20.79.228.76</li><li>20.113.9.21</li><li>20.79.107.0</li><li>20.223.28.120</li><li>20.223.28.149</li><li>20.223.28.176</li><li>20.223.28.189</li><li>20.223.28.207</li><li>20.223.28.226</li><li>20.107.224.16</li><li>20.90.227.199</li><li>20.90.227.255</li><li>20.90.228.8</li><li>20.90.228.71</li><li>20.90.228.129</li><li>20.90.228.194</li><li>20.90.134.24</li><li>20.103.147.247</li><li>20.103.148.141</li><li>20.103.149.167</li><li>20.103.149.216</li><li>20.103.149.237</li><li>20.103.150.28</li><li>20.105.232.10</li></ul> |

## REST API Updates

No REST API Updates for 23.3.2.

## New Features Introduced in 23.3.1

* [New Features](#new-features1)
* [API Ingestions](#api-ingestions1)
* [New Policies](#new-policies1)
* [Policy Updates](#policy-updates1)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates1)
* [Changes in Existing Behavior](#changes-in-existing-behavior1)
* [REST API Updates](#rest-api-updates1)

## New Features

| FEATURE                                                                                                     | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ----------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **GRBAC now available for Data Security**                                                                   | <p>Granular Role Based Access Control (GRBAC) is now available for Data Security functionality in Prisma Cloud. You can now create <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/manage-prisma-cloud-administrators/create-custom-prisma-cloud-roles">Custom Roles</a> with the option to <strong>View</strong>, <strong>Create</strong>, <strong>Update</strong> or <strong>Delete</strong> Data Security functions. GRBAC allows you to enforce least privileged access, giving you the option to create roles with the minimum amount of access to Data Security required for a users job function. Custom Role creation is limited to users with a current System Administrator role.</p><p><img src="/files/YYsbkLrGyKOMOYIQqaZO" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                   |
| **Task Delegation on Adoption Advisor**                                                                     | <p>For operationalizing the security capabilities available on Prisma Cloud, you can now assign tasks to specific members on your team so that the right person is assigned and accountable for completing the task and making progress.</p><p>The Assignee receives an email with a link to the appropriate page on the administrative console where the Adoption Advisor side panel provides guidance on the high-level steps to complete the task and the documentation link for more details.</p><p><img src="/files/WHPNfmF2bZ7DUjU0L9j2" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **Vulnerabilities displayed in Command Center**                                                             | <p>The <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-dashboards/command-center-dashboard">Command Center</a> dashboard on the Prisma Cloud console now includes a snapshot view of Urgent Vulnerabilities, Top 5 Vulnerable Images, and Top 5 Vulnerable Hosts. Vulnerabilities triggering <strong>Critical</strong> and <strong>High</strong> alerts are grouped into these actionable views, giving you insight into the impacted resources in your environment and providing you with remediation options. You can view data for the past 30 days and also filter results by:</p><ul><li><strong>Time Range</strong> - Viewable for the last day, week, month, or a customized time frame</li><li><strong>Account Groups</strong></li><li><strong>Cloud Accounts</strong></li></ul><p>Currently, only System Administrators can view the Vulnerabilities widget. The Vulnerability dashboard is also currently not available for Government and China based deployments.</p><p><img src="/files/4srgBnmeFhV8VPC8qt3M" alt="" data-size="original"></p>                                    |
| **Prisma Cloud Chronicles**                                                                                 | <p>The Chronicles is a weekly email update to summarize your team’s usage of Prisma Cloud, suggest product adoption improvements and links to the Release Notes to show what’s new, and provide actionable opportunities to secure your cloud environment.</p><p><img src="/files/9XfSk7AaMsl6SrZDF49e" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Support for Finance Regions on Alibaba Cloud**                                                            | <p>Prisma Cloud now ingests data for resources deployed in Alibaba Finance Cloud for Hangzhou, Shanghai, and Shenzhen regions. To review a list of supported regions, select "Inventory > Assets", and choose <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/cloud-service-provider-regions-on-prisma-cloud#id091e5e1f-e6d4-42a8-b2ff-85840eb23396_id04f54d2e-f21e-4c1e-98c8-5d2e6ad89b5f">Cloud Region</a> from the filter drop-down.</p><p><img src="/files/BNvcRxf8fQBUJfSG7Fie" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <mark style="background-color:orange;">Enhancement</mark> **Separate Text Boxes for Key and Value Entries** | <p>If you are using tags, you no longer need to use a colon (:) to separate key and value entries in a single text box while assigning resource tags on <strong>Alert Overview</strong> and <strong>Asset Inventory</strong>. You can now enter <strong>Key</strong> and <strong>Value</strong> in separate text boxes.</p><p><img src="/files/1v7ZNS7WBidtpzPzryRx" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <mark style="background-color:orange;">Enhancement</mark> **Asset Inventory**                               | <p>The text strings displayed in <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-dashboards/asset-inventory">Asset Inventory</a> are improved for better readability and accuracy.</p><ul><li>The <strong>Asset Inventory</strong> displays "Data as of:" similar to that displayed in <strong>Asset Explorer</strong> to indicate the freshness of the snapshot of the data.</li><li>The <strong>Date</strong> filter in <strong>Asset Explorer</strong> now displays "Most recent" instead of the absolute date-time.</li><li>The <strong>Asset Detail View</strong> displays "You are viewing the most recent data about this asset" text to indicate that it is the most recent data for the asset regardless of the data roll-up time and it may be more up to date than the latest snapshot.</li><li>The <strong>Asset Detail View</strong> also displays "You are viewing data about a deleted asset" to indicate that you are viewing an asset which has been deleted from your cloud environment.</li></ul><p><img src="/files/IOIDAZeizfMyC88zuR32" alt="" data-size="original"></p> |

## API Ingestions

| SERVICE                      | API DETAILS                                                                                                                                                                                                                                                                                                                           |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Azure Defender for Cloud** | <p><strong>azure-defender-for-cloud-workspace-setting</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Security/workspaceSettings/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                       |
| **Azure Defender for Cloud** | <p><strong>azure-defender-for-cloud-setting</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Security/settings/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                          |
| **Azure Defender for Cloud** | <p><strong>azure-defender-for-cloud-security-contact</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Security/securityContacts/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                         |
| **Azure Defender for Cloud** | <p><strong>azure-defender-for-cloud-secure-score</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Security/secureScores/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                 |
| **Azure Batch Account**      | <p><strong>azure-batch-account-pool</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Batch/batchAccounts/read</code></li><li><code>Microsoft.Batch/batchAccounts/pools/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                |
| **Google Cloud Deploy**      | <p><strong>gcloud-cloud-deploy-configuration</strong></p><p>Additional permissions required:</p><ul><li><code>clouddeploy.config.get</code></li><li><code>clouddeploy.locations.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                 |
| **Google Cloud Deploy**      | <p><strong>gcloud-cloud-deploy-delivery-pipeline</strong></p><p>Additional permissions required:</p><ul><li><code>clouddeploy.locations.list</code></li><li><code>clouddeploy.deliveryPipelines.list</code></li><li><code>clouddeploy.deliveryPipelines.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p> |
| **Google Cloud Deploy**      | <p><strong>gcloud-cloud-deploy-target</strong></p><p>Additional permissions required:</p><ul><li><code>clouddeploy.locations.list</code></li><li><code>clouddeploy.targets.list</code></li><li><code>clouddeploy.targets.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                |

## New Policies

| NEW POLICIES               | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Attack Path Policies**   | <p>To help prioritize alerts and mitigate security issues, Prisma Cloud provides 5 new out-of-the-box <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/manage-prisma-cloud-policies">Attack Path policies</a> that are of critical severity and enabled by default.</p><p>The Attack Path policies are:</p><ul><li><strong>AWS EC2 instance with s3:GetObject permission is publicly exposed and not configured with Instance Metadata Service v2 (IMDSv2)</strong></li></ul><p>This policy identifies AWS EC2 instances with s3:GetObject permission which are publicly exposed and not configured with Instance Metadata Service v2 (IMDSv2). With IMDSv2, every request is protected by session authentication. IMDSv2 protects against misconfigured-open website application firewalls, misconfigured-open reverse proxies, unpatched SSRF vulnerabilities, and misconfigured-open layer-3 firewalls and network address translation. As a best practice, only use IMDSv2 for all your EC2 instances.</p><ul><li><strong>AWS EC2 instance with iam:PassRole and ec2:RunInstances permissions is publicly exposed</strong></li></ul><p>This policy identifies AWS EC2 instances with risky permissions and are publicly exposed. EC2 instances associated with 'iam:PassRole','ec2:RunInstances' permissions can be used to escalate privileges by passing an existing IAM role to a new EC2 instance and moving laterally. It is highly recommended that you remove the risky permissions from the IAM role attached to EC2 instances. Additionally, review and restrict the public exposure based on the business requirements.</p><ul><li><strong>AWS EC2 instance with ORG level WRITE permissions is publicly exposed</strong></li></ul><p>This policy identifies AWS EC2 instances which with risky ORG level WRITE permissions and are publicly exposed. EC2 instances having org level write permissions can be used to escalate privileges at the ORG level and move laterally between accounts. It is highly recommended to remove the risky permissions from the IAM role attached to EC2 instances. Additionally, review and restrict the public exposure based on the business requirements.</p><ul><li><strong>AWS EC2 instance with Critical/High exploitable vulnerability is publicly exposed</strong></li></ul><p>This policy identifies AWS EC2 instances which have known exploitable vulnerabilities and are publicly exposed. An attacker can exploit the vulnerability to compromise the confidentiality, integrity, or availability of the affected EC2 instance and perform malicious actions. As a best practice, remediate the Critical/High exploitable vulnerabilities reported for EC2 instances. Additionally, review and restrict the public exposure based on the business requirements.</p><ul><li><strong>AWS EC2 instance with iam:PassRole and lambda:InvokeFunction permissions is publicly exposed</strong></li></ul><p>This policy identifies AWS EC2 instances which are attached to an IAM role with risky permissions and are publicly exposed. EC2 instances having 'iam:PassRole','lambda:CreateFunction', 'lambda:InvokeFunction' permissions can be used to escalate privileges by passing an existing IAM role to a new Lambda function and moving laterally. As a best practice remove the risky permissions from the IAM role attached to EC2 instances. Additionally, review and restrict the public exposure based on the business requirements.</p><p>Attack Path policies are not available in China and Government regions.</p> |
| **Azure Anomaly Policies** | <p>Prisma Cloud provides the following new policies that detect anomalies using the information in audit logs for your Azure cloud accounts:</p><ul><li><strong>Azure Compute workload assigning roles to resources</strong>—Detects when an Azure Compute workload assigns a role to a resource, resource group, or subscription.</li><li><strong>Azure Compute workload modifying Key Vault configurations</strong>—Detects when an Azure Compute workload modifies the configuration of a key vault.</li><li><strong>Azure Compute workload deleting network security groups</strong>—Detects when an Azure Compute workload deletes network security groups.</li><li><strong>Azure Compute workload disabling Azure alerts</strong>—Detects when an Azure Compute workload deletes Azure Monitor alert rules.</li><li><strong>Azure Compute workload creating or modifying route tables</strong>—Detects when an Azure Compute workload creates or modifies Azure routing tables.</li><li><strong>Azure Compute workload disabling anti-malware extensions</strong>—Detects when an Azure Compute workload disables anti-malware extensions.</li><li><strong>Azure user reading database master keys</strong>—Detects when an Azure user reads master keys from a Cosmos DB.</li><li><strong>Azure user executing remote commands on virtual machines</strong>—Detects when an Azure user runs commands remotely on a virtual machine.</li></ul><p>These anomaly policies:</p><ul><li>Identify when an Azure compute workload uses potential Privilege Escalation or Defense Evasion tactics</li><li>Detect when an Azure user is using Credential Access or Lateral Movement Tactics Prisma Cloud triggers alerts for these anomaly policies after ingesting the audit logs from Azure cloud accounts and the anomaly policies are added to an alert rule.</li></ul><p>You also can specify a role in the anomaly trusted list to suppress the alerts. The specified anomaly policy will not generate alerts for the matching role names added to this trusted list.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>POLICY UPDATES</td><td>DESCRIPTION</td></tr><tr><td><strong>Changes to Network Anomaly Policies</strong></td><td><p>The names of the <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/anomaly-policies">network anomaly policies</a> are modified to be self explanatory and also make it easier to identify cloud resources involved in the alerts reported by these policies. Additionally, the <strong>Resource Name</strong> column in the alert details for external network anomaly policies (excluding Port Sweep activity) now displays the internal resource (cloud instance) targeted or generating traffic instead of the public <strong>IP address</strong> of the source host participating in the suspicious activity.</p><ul><li>The <strong>Port Sweep activity (External)</strong> network anomaly policy involves multiple internal resources and selecting only one can create confusion. In order to avoid confusion, <strong>Port Sweep activity (External)</strong> policy continues to display the public <strong>IP address</strong> in the <strong>Resource Name</strong>.</li><li>The severity of the <strong>Network data exfiltration activity</strong> anomaly policy is changed from high to medium.</li></ul><p>For more information, see the <a href="https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/prisma/prisma-cloud/prerelease/external-network-anomaly-policies-changes.pdf">list of policies</a> that are affected.</p><p><strong>Impact—</strong> Only applies to any new alert generated by an anomaly policy. No impact on existing alerts.</p></td></tr><tr><td><strong>Policy Updates-RQL</strong></td><td></td></tr><tr><td><strong>GCP HTTPS Load balancer is configured with SSL policy having TLS version 1.1 or lower</strong></td><td><p><strong>Changes—</strong> The policy RQL is updated to match changes introduced in the <strong>gcloud-compute-ssl-policies</strong> API.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-ssl-policies' as X; config from cloud.resource where api.name = 'gcloud-compute-target-https-proxies' as Y; filter "($.Y.sslPolicy exists and $.X.sslPolicies is not empty) and ($.X.sslPolicies[?((@.profile=='MODERN'||@.profile=='CUSTOM') &#x26;&#x26; @.minTlsVersion!='TLS_1_2')].selfLink contains $.Y.sslPolicy)"; show Y;
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-ssl-policies' AND json.rule = (profile equals MODERN or profile equals CUSTOM) and minTlsVersion does not equal "TLS_1_2" as X; config from cloud.resource where api.name = 'gcloud-compute-target-https-proxies' AND json.rule = sslPolicy exists as Y; filter "$.X.selfLink contains $.Y.sslPolicy"; show Y;
</code></pre><p><strong>Impact—</strong> High. Existing alerts will be resolved as <strong>Resource_Updated</strong>. New alerts will be generated against the policy violations.</p></td></tr><tr><td><strong>GCP Load Balancer SSL proxy permits SSL policies with weak cipher suites</strong></td><td><p><strong>Changes—</strong> The policy RQL is updated to match changes introduced in the <strong>gcloud-compute-ssl-policies</strong> API.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-target-ssl-proxy' as X; config from cloud.resource where api.name = 'gcloud-compute-ssl-policies' as Y; filter "$.X.sslPolicy does not exist or ($.Y.sslPolicies[?(@.profile=='COMPATIBLE')].selfLink contains $.X.sslPolicy) or ($.Y.sslPolicies[?((@.profile=='MODERN'||@.profile=='CUSTOM') &#x26;&#x26; (@.minTlsVersion!='TLS_1_2'))].selfLink contains $.X.sslPolicy or ($.Y.sslPolicies[?(@.profile=='CUSTOM' &#x26;&#x26; 'TLS_RSA_WITH_AES_128_GCM_SHA256' in @.enabledFeatures)].selfLink contains $.X.sslPolicy or $.Y.sslPolicies[?(@.profile=='CUSTOM' &#x26;&#x26; 'TLS_RSA_WITH_AES_256_GCM_SHA384' in @.enabledFeatures)].selfLink contains $.X.sslPolicy or $.Y.sslPolicies[?(@.profile=='CUSTOM' &#x26;&#x26; 'TLS_RSA_WITH_AES_128_CBC_SHA' in @.enabledFeatures)].selfLink contains $.X.sslPolicy or $.Y.sslPolicies[?(@.profile=='CUSTOM' &#x26;&#x26; 'TLS_RSA_WITH_AES_256_CBC_SHA' in @.enabledFeatures)].selfLink contains $.X.sslPolicy or $.Y.sslPolicies[?(@.profile=='CUSTOM' &#x26;&#x26; 'TLS_RSA_WITH_3DES_EDE_CBC_SHA' in @.enabledFeatures)].selfLink contains $.X.sslPolicy))"; show X;
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-target-ssl-proxy' as X; config from cloud.resource where api.name = 'gcloud-compute-ssl-policies' as Y; filter "$.X.sslPolicy does not exist or ($.Y.profile equals COMPATIBLE and $.Y.selfLink contains $.X.sslPolicy) or ( ($.Y.profile equals MODERN or $.Y.profile equals CUSTOM) and $.Y.minTlsVersion does not equal TLS_1_2 and $.Y.selfLink contains $.X.sslPolicy ) or ( $.Y.profile equals CUSTOM and ( $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_128_GCM_SHA256 or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_256_GCM_SHA384 or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_128_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_256_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_3DES_EDE_CBC_SHA ) and $.Y.selfLink contains $.X.sslPolicy ) "; show X;
</code></pre><p><strong>Impact—</strong> High. Existing alerts will be resolved as <strong>Resource_Updated</strong>. New alerts will be generated against the policy violations.</p></td></tr><tr><td><strong>GCP Load Balancer HTTPS proxy permits SSL policies with weak cipher suites</strong></td><td><p><strong>Changes—</strong> The policy RQL is updated to match changes introduced in the <strong>gcloud-compute-ssl-policies</strong> API.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-target-https-proxies' as X; config from cloud.resource where api.name = 'gcloud-compute-ssl-policies' as Y; filter "($.Y.sslPolicies[?(@.profile=='COMPATIBLE')].selfLink contains $.X.sslPolicy) or ($.Y.sslPolicies[?((@.profile=='MODERN'||@.profile=='CUSTOM') &#x26;&#x26; (@.minTlsVersion!='TLS_1_2'))].selfLink contains $.X.sslPolicy or ($.Y.sslPolicies[?(@.profile=='CUSTOM' &#x26;&#x26; 'TLS_RSA_WITH_AES_128_GCM_SHA256' in @.enabledFeatures)].selfLink contains $.X.sslPolicy or $.Y.sslPolicies[?(@.profile=='CUSTOM' &#x26;&#x26; 'TLS_RSA_WITH_AES_256_GCM_SHA384' in @.enabledFeatures)].selfLink contains $.X.sslPolicy or $.Y.sslPolicies[?(@.profile=='CUSTOM' &#x26;&#x26; 'TLS_RSA_WITH_AES_128_CBC_SHA' in @.enabledFeatures)].selfLink contains $.X.sslPolicy or $.Y.sslPolicies[?(@.profile=='CUSTOM' &#x26;&#x26; 'TLS_RSA_WITH_AES_256_CBC_SHA' in @.enabledFeatures)].selfLink contains $.X.sslPolicy or $.Y.sslPolicies[?(@.profile=='CUSTOM' &#x26;&#x26; 'TLS_RSA_WITH_3DES_EDE_CBC_SHA' in @.enabledFeatures)].selfLink contains $.X.sslPolicy))"; show X;
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-target-https-proxies' as X; config from cloud.resource where api.name = 'gcloud-compute-ssl-policies' as Y; filter " $.X.sslPolicy does not exist or ($.Y.profile equals COMPATIBLE and $.Y.selfLink contains $.X.sslPolicy) or ( ($.Y.profile equals MODERN or $.Y.profile equals CUSTOM) and $.Y.minTlsVersion does not equal TLS_1_2 and $.Y.selfLink contains $.X.sslPolicy ) or ( $.Y.profile equals CUSTOM and ( $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_128_GCM_SHA256 or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_256_GCM_SHA384 or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_128_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_256_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_3DES_EDE_CBC_SHA ) and $.Y.selfLink contains $.X.sslPolicy ) "; show X;
</code></pre><p><strong>Impact—</strong> High. Existing alerts will be resolved as <strong>Resource_Updated</strong>. New alerts will be generated against the policy violations.</p></td></tr><tr><td><strong>GCP HTTPS Load balancer SSL Policy not using restrictive profile</strong></td><td><p><strong>Changes—</strong> The policy RQL is updated to match changes introduced in the <strong>gcloud-compute-ssl-policies</strong> API.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-ssl-policies' as X; config from cloud.resource where api.name = 'gcloud-compute-target-https-proxies' as Y; filter "($.Y.sslPolicy exists and $.X.sslPolicies is not empty) and ($.X.sslPolicies[?(@.profile!='RESTRICTED' &#x26;&#x26; @.profile!='CUSTOM')].selfLink contains $.Y.sslPolicy)"; show Y;
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-ssl-policies' AND json.rule = profile does not equal RESTRICTED and profile does not equal CUSTOM as X; config from cloud.resource where api.name = 'gcloud-compute-target-https-proxies' AND json.rule = sslPolicy exists as Y; filter " $.X.selfLink contains $.Y.sslPolicy "; show Y;
</code></pre><p><strong>Impact—</strong> High. Existing alerts will be resolved as <strong>Resource_Updated</strong>. New alerts will be generated against the policy violations.</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| COMPLIANCE BENCHMARK                       | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **CSA Cloud Controls Matrix (CCM) v4.0.6** | <p>Prisma Cloud now supports the CSA Cloud Controls Matrix (CCM) v4.0.6 compliance standard.</p><p>The CSA Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing. It is a spreadsheet that contains a list of common frameworks and regulations that your organization must follow. Each control maps to a number of industry-accepted security standards, regulations, and frameworks, which means that completing the CCM controls also completes the accompanying standards and regulations. It reduces the need to use multiple frameworks and simplifies cloud security by displaying all common cloud standards in one place.</p><p>With this support, you can now view this built-in standard and the related policies on Prisma Cloud’s <strong>Compliance > Standard</strong> page. Additionally, you can generate reports for immediate viewing or download, or you can schedule recurring reports to keep track of this compliance standard over time.</p> |

## Changes in Existing Behavior

| FEATURE                                | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| -------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Google Compute SSL Policies Update** | <p>Prisma Cloud now includes a JSON update to increase the visibility and monitoring of <strong>gcloud-compute-ssl-policies</strong> API resources. Due to this, all the resources will be deleted and then regenerated on the management console.</p><p>Existing alerts corresponding to these resources will be resolved as Resource\_Updated, and new alerts will be generated against the policy violations.</p><p><strong>Impact—</strong> You may notice an increased count for the number of alerts for the following OOTB policies:</p><ul><li>GCP HTTPS Load balancer SSL Policy not using restrictive profile</li><li>GCP Load Balancer HTTPS proxy permits SSL policies with weak cipher suites</li><li>GCP Load Balancer SSL proxy permits SSL policies with weak cipher suites</li><li>GCP HTTPS Load balancer is configured with SSL policy having TLS version 1.1 or lower</li></ul><p>However, the alert count will return to the original numbers once the resources for <strong>gcloud-compute-ssl-policies</strong> start ingesting data again.</p> |

## REST API Updates

| CHANGE                                                                                                                                                                                                             | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Command Center APIs**                                                                                                                                                                                            | <p>The following new endpoints are available for the Command Center API:</p><ul><li>List Top Vulnerabilities - <a href="https://pan.dev/prisma-cloud/api/cspm/command-center-list-top-vulnerabilities/#list-top-vulnerabilities">POST /commandcenter/v1/top-vulnerabilities</a></li><li>List Total Vulnerable Images and Hosts - <a href="https://pan.dev/prisma-cloud/api/cspm/command-center-list-total-vulnerable-images-hosts/#list-total-vulnerable-images-and-hosts">POST /commandcenter/v1/vulnerabilities/summary</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>New APIs for Onboarding AWS Cloud ccounts</strong></p><p><mark style="background-color:orange;">This change was first announced in the Look Ahead that was published with the 22.4.1 release</mark></p> | <p>The following new endpoints are now available for the Cloud Accounts API. These endpoints include the updates to generate <strong>External ID</strong> in the <strong>IAM Role</strong> and to enable selection of <strong>Security Capabilities and Permissions</strong>.</p><ul><li>Add AWS Cloud Account - <a href="https://pan.dev/prisma-cloud/api/cspm/add-aws-cloud-account/#add-aws-cloud-account">POST /cas/v1/aws\_account</a></li><li>Update AWS Cloud Account - <a href="https://pan.dev/prisma-cloud/api/cspm/update-aws-cloud-account/#update-aws-cloud-account">PUT /cas/v1/aws\_account/:id</a></li><li>Get AWS Cloud Account Status - <a href="https://pan.dev/prisma-cloud/api/cspm/get-aws-cloud-account-status/#get-aws-cloud-account-status">POST /cas/v1/cloud\_account/status/aws</a></li><li>List Children of Parent (AWS) - <a href="https://pan.dev/prisma-cloud/api/cspm/get-list-of-children-under-parent-aws/#list-children-of-parent-aws">POST /cas/v1/aws\_account/:parent\_id/children</a></li><li>List Ancestors (AWS) - <a href="https://pan.dev/prisma-cloud/api/cspm/get-ancestors-for-given-members-ous/#list-ancestors-aws">POST /cas/v1/aws\_account/:account\_id/ancestors</a></li><li>Fetch Supported Features For Cloud Type - <a href="https://pan.dev/prisma-cloud/api/cspm/fetch-supported-features/#fetch-supported-features-for-cloud-type">POST /cas/v1/features/cloud/:cloud\_type</a></li><li>Generate and Download the AWS CFT Template - <a href="https://pan.dev/prisma-cloud/api/cspm/generate-cft-template-aws/#generate-and-download-the-aws-cft-template">POST /cas/v1/aws\_template</a></li><li>Generate the AWS CFT Template Link - <a href="https://pan.dev/prisma-cloud/api/cspm/generate-cft-template-link-aws/#generate-the-aws-cft-template-link">POST /cas/v1/aws\_template/presigned\_url</a></li></ul> |
| **Cloud Ingested Logs API**                                                                                                                                                                                        | <p>The following new endpoints are available for the Cloud Ingested Logs API:</p><ul><li>Get Eventbridge configuration details - <a href="https://pan.dev/prisma-cloud/api/cspm/get-eventbridge-configuration-details/#get-eventbridge-configuration-details">GET /audit\_logs/v2/tenant/:tenantId/aws\_accounts/:accountId/eventbridge\_config</a></li><li>Update Eventbridge configuration - <a href="https://pan.dev/prisma-cloud/api/cspm/save-or-update-eventbridge-config/#update-eventbridge-configuration">PUT /audit\_logs/v2/tenant/:tenantId/aws\_accounts/:accountId/eventbridge\_config</a></li><li>Get AWS eventbridge config status - <a href="https://pan.dev/prisma-cloud/api/cspm/get-eventbridge-configuration-status/#get-aws-eventbridge-config-status">GET /audit\_logs/v2/tenant/:tenantId/aws\_accounts/:accountId/eventbridge\_config/status</a></li><li>Generate Eventbridge CFT - <a href="https://pan.dev/prisma-cloud/api/cspm/generate-eventbridge-cft/#generate-eventbridge-cft">GET /audit\_logs/v2/tenant/:tenantId/aws\_accounts/:accountId/eventbridge\_config/cft\_download</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-cspm-release-information/features-introduced-in-march-2023.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
