> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2023/features-introduced-in-november-2023.md).

# Features Introduced in November 2023

Learn what’s new on Prisma® Cloud in November 2023.

## New Features Introduced in November 2023

* [Announcement](#announcement)
* [New Features](#new-features)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [REST API Updates](#rest-api-updates)

## Announcement

| FEATURE                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Prisma Cloud Darwin Release** | <p>The <strong>Prisma Cloud Darwin Release</strong> is here for Prisma Cloud environments on app.ind, app.ca, app.uk, and app.fr except app.gov. With the Code to Cloud™ intelligence capabilities in this release, your security and development teams can work together to reduce application risks and prevent breaches.</p><p>With this change, your tenant will be updated with the new intuitive user interface and <a href="https://live.paloaltonetworks.com/t5/prisma-cloud-customer-videos/prisma-cloud-evolution-amp-transformation/ta-p/556596">rich set of security capabilities</a>.</p><p>Connect with your Customer Success team for more details.</p><p>When you are upgraded to the Darwin release, refer to the <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/">Enterprise Edition documentation</a>.</p> |

## New Features

New Attack Path policies are available. Log in to the Prisma Cloud console and filter for the list of available policies.

## API Ingestions

| SERVICE                                                                                                                                                  | API DETAILS                                                                                                                                                                                                                                                                                                                                                                                                                             |
| -------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Amazon EC2</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                                           | <p><strong>aws-ec2-launch-template-data</strong></p><p>Additional permissions required:</p><ul><li><code>ec2:GetLaunchTemplateData</code></li><li><code>ec2:DescribeInstances</code></li></ul><p>The Security Audit role only includes the <code>ec2:DescribeInstances</code> permission. You must manually add the <code>ec2:GetLaunchTemplateData</code> permission to the CFT template to enable the permission.</p>                 |
| <p><strong>AWS Audit Manager</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                                    | <p><strong>aws-audit-manager-assessment</strong></p><p>Additional permissions required:</p><ul><li><code>auditmanager:ListAssessments</code></li><li><code>auditmanager:GetAssessment</code></li></ul><p>The Security Audit role only includes the <code>auditmanager:ListAssessments</code> permission. You must manually add the <code>auditmanager:GetAssessment</code> permission to the CFT template to enable the permission.</p> |
| <p><strong>AWS Audit Manager</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                                    | <p><strong>aws-audit-manager-control</strong></p><p>Additional permissions required:</p><ul><li><code>auditmanager:ListControls</code></li><li><code>auditmanager:GetControl</code></li></ul><p>The Security Audit role only includes the <code>auditmanager:ListControls</code> permission. You must manually add the <code>auditmanager:GetControl</code> permission to the CFT template to enable the permission.</p>                |
| <p><strong>AWS Application Migration Service</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                    | <p><strong>aws-mgn-launch-configuration-template</strong></p><p>Additional permission required:</p><ul><li><code>mgn:DescribeLaunchConfigurationTemplates</code></li></ul><p>You must manually add the <code>mgn:DescribeLaunchConfigurationTemplates</code> permission to the CFT template to enable the permission.</p>                                                                                                               |
| <p><mark style="background-color:orange;">Update</mark> <strong>Azure Key Vault</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p> | <p><strong>azure-key-vault-list</strong></p><p>This API has been updated to support Key rotation data. The resource JSON for this API has been updated to include the <code>keys\[\*].keyRotationPolicy</code> field.</p>                                                                                                                                                                                                               |
| <p><strong>Azure Synapse Analytics</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                              | <p><strong>azure-synapse-workspace-managed-sql-server-blob-auditing-policies</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Synapse/workspaces/read</code></li><li><code>Microsoft.Synapse/workspaces/auditingSettings/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                |
| <p><strong>Azure Synapse Analytics</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                              | <p><strong>azure-synapse-workspace-ip-firewall-rules</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Synapse/workspaces/read</code></li><li><code>Microsoft.Synapse/workspaces/firewallRules/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                           |
| <p><strong>Google AlloyDB for PostgreSQL</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                        | <p><strong>gcloud-alloydb-cluster</strong></p><p>Additional permissions required:</p><ul><li><code>alloydb.locations.list</code></li><li><code>alloydb.clusters.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                   |
| <p><strong>Google AlloyDB for PostgreSQL</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                        | <p><strong>gcloud-alloydb-cluster-user</strong></p><p>Additional permissions required:</p><ul><li><code>alloydb.locations.list</code></li><li><code>alloydb.clusters.list</code></li><li><code>alloydb.users.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                      |
| <p><strong>Google AlloyDB for PostgreSQL</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                        | <p><strong>gcloud-alloydb-cluster-instance</strong></p><p>Additional permissions required:</p><ul><li><code>alloydb.locations.list</code></li><li><code>alloydb.clusters.list</code></li><li><code>alloydb.instances.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                              |
| <p><strong>Google AlloyDB for PostgreSQL</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                        | <p><strong>gcloud-alloydb-backup</strong></p><p>Additional permissions required:</p><ul><li><code>alloydb.locations.list</code></li><li><code>alloydb.backups.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                     |
| <p><strong>OCI Cloud Guard</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>                                                      | <p><strong>oci-cloudguard-configuration</strong></p><p>Additional permissions required:</p><ul><li><code>CG\_CONFIG\_INSPECT</code></li><li><code>CG\_CONFIG\_READ</code></li></ul><p>You must update the Terraform template to enable the permissions.</p>                                                                                                                                                                             |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>NEW POLICIES</td><td>DESCRIPTION</td></tr><tr><td><p><strong>AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p></td><td><p>Identifies AWS EC2 instances that are internet reachable with unrestricted access (0.0.0.0/0) to HTTP/HTTPS ports (80 / 443). EC2 instances with unrestricted access to the internet for HTTP/HTTPS ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.</p><p><strong>Policy Type—</strong> Network Configuration</p><p><strong>Policy Severity—</strong> Informational</p><pre><code>config from network where source.network = '0.0.0.0/0' and address.match.criteria = 'full_match' and dest.resource.type = 'Instance' and dest.cloud.type = 'AWS' and protocol.ports in ( 'tcp/80' , 'tcp/443' )
</code></pre></td></tr><tr><td><p><strong>Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p></td><td><p>Identifies Azure Virtual Machines that are internet reachable with unrestricted access (0.0.0.0/0) to HTTP/HTTPS ports (80 / 443). Azure Virtual Machines with unrestricted access to the internet for HTTP/HTTPS ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.</p><p><strong>Policy Type—</strong> Network Configuration</p><p><strong>Policy Severity—</strong> Informational</p><pre><code>config from network where source.network = '0.0.0.0/0' and address.match.criteria = 'full_match' and dest.resource.type = 'Instance' and dest.cloud.type = 'AZURE' and protocol.ports in ( 'tcp/80' , 'tcp/443' )
</code></pre></td></tr><tr><td><p><strong>Azure Virtual Machine (Linux) does not authenticate using SSH keys</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p></td><td><p>Identifies Azure Virtual Machines that have basic authentication, not authenticating using SSH keys. Azure Virtual Machines with basic authentication could allow attackers to brute force and gain unauthorized access, which might lead to potential data leaks. It is recommended to use SSH keys for authentication to avoid brute force attacks on virtual machines.</p><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Severity—</strong> Low</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-vm-list' AND json.rule = powerState equal ignore case "PowerState/running" and (['properties.osProfile'].['linuxConfiguration'] exists and ['properties.osProfile'].['linuxConfiguration'].['disablePasswordAuthentication'] is false)
</code></pre></td></tr><tr><td><p><strong>GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p></td><td><p>Identifies GCP VM instances that are internet reachable with unrestricted access (0.0.0.0/0) to HTTP/HTTPS ports (80 / 443). GCP VM instances with unrestricted access to the internet for HTTP/HTTPS ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.</p><p><strong>Policy Type—</strong> Network Configuration</p><p><strong>Policy Severity—</strong> Informational</p><pre><code>config from network where source.network = '0.0.0.0/0' and address.match.criteria = 'full_match' and dest.resource.type = 'Instance' and dest.cloud.type = 'GCP' and protocol.ports in ( 'tcp/80' , 'tcp/443' )
</code></pre></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>POLICY UPDATES</td><td>DESCRIPTION</td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><p><strong>Azure Application Gateway is configured with SSL policy having TLS version 1.1 or lower</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p></td><td><p><strong>Changes—</strong> The RQL willl be updated to not report Application gateways with default policy created using API versions 2023-02-01 or higher as the minimum protocol version is set to 1.2.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-application-gateway' AND json.rule = ['properties.sslPolicy'] does not exist or (['properties.sslPolicy'].['policyType'] equal ignore case Predefined and (['properties.sslPolicy'].['policyName'] equal ignore case AppGwSslPolicy20150501 or ['properties.sslPolicy'].['policyName'] equal ignore case AppGwSslPolicy20170401)) or (['properties.sslPolicy'].['policyType'] equal ignore case Custom and (['properties.sslPolicy'].['minProtocolVersion'] equal ignore case TLSv1_0 or ['properties.sslPolicy'].['minProtocolVersion'] equal ignore case TLSv1_1))
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-application-gateway' AND json.rule = (['properties.sslPolicy'] does not exist and ['properties.defaultPredefinedSslPolicy'] does not equal ignore case AppGwSslPolicy20220101) or (['properties.sslPolicy'].['policyType'] equal ignore case Predefined and (['properties.sslPolicy'].['policyName'] equal ignore case AppGwSslPolicy20150501 or ['properties.sslPolicy'].['policyName'] equal ignore case AppGwSslPolicy20170401)) or (['properties.sslPolicy'].['policyType'] equal ignore case Custom and (['properties.sslPolicy'].['minProtocolVersion'] equal ignore case TLSv1_0 or ['properties.sslPolicy'].['minProtocolVersion'] equal ignore case TLSv1_1))
</code></pre><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> Low. Existing alerts where the application gateways were created with default policy using API versions 2023-02-01 or higher will be resolved as <strong>Policy_Updated</strong>.</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| COMPLIANCE BENCHMARK                                                                                                     | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Support for CMMC v2 Level 2 standard</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p> | <p>Prisma Cloud now supports the Cybersecurity Maturity Model Certification (CMMC) v2 Level 2 compliance standard. This framework includes cybersecurity practices, standards, and processes published by the Department of Defense (DoD) as part of the CMMC program, which aims to protect national security by standardizing how Defense contractors and subcontractors handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).</p><p>You can now view this built-in standard and the associated policies on the <strong>Compliance > Standards</strong> page with this support. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p> |

## Changes in Existing Behavior

| FEATURE                                                                                                                                                                       | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Checkov CLI upgrade</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;">23.11.1</mark></p> | <p>The Checkov CLI has been upgraded to Checkov 3.0. The upgrade impacts a few known changes:</p><ul><li><strong>Level Up</strong>: This capability has been removed. This change is non-disruptive and affects only Bridgecrew standalone sign ups.</li><li><strong>Multi-Signatures</strong>: Multi-signatures in Python checks are being removed. This will only impact custom Python policies using this method.</li><li><strong>Deprecating flags for Suppression and Fix</strong>: CLI command of <code>--skip-fixes</code> and <code>--skip-suppressions</code> are being deprecated. Instead <code>--skip-download</code> is a recommended command.</li><li><strong>API Key Restriction and Repo-ID Parameter</strong>: Scans with API keys will now require the --repo-id parameter for repository scans allowing for easier platform mapping.</li><li><strong>Enhanced Argument Handling</strong>: The way to specify frameworks and skip frameworks will align to other flags where multiple values can be listed (like --check). For example: <code>--framework terraform,arm</code>..</li><li><strong>Pyston Docker Build Deprecation</strong>: The Pyston Docker build has been depreciated due to increasing complexities in support. The regular Checkov image will still be available for use.</li></ul> |

## REST API Updates

| CHANGE                                                                                                    | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| --------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>New SSO APIs</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>          | <p>The following new endpoints are available for configuring SAML:</p><ul><li>Get SAML Configuration - <a href="https://pan.dev/prisma-cloud/api/cspm/get-saml-config/">GET /authn/v1/saml/config</a></li><li>Update SAML Configuration - <a href="https://pan.dev/prisma-cloud/api/cspm/update-saml-config/">PUT /authn/v1/saml/config</a></li><li>Create SAML Configuration - <a href="https://pan.dev/prisma-cloud/api/cspm/create-saml-config/">POST /authn/v1/saml/config</a></li></ul>          |
| <p><strong>New Cloud Account API</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p> | <p>The following new endpoint is available to enable or disable a feature for a set of members of an organization:</p><ul><li>Enable a Feature for Members - <a href="https://pan.dev/prisma-cloud/api/cspm/save-bulk-cloud-account-feature/">PUT /cas/api/v1/org/{id}/features</a></li></ul>                                                                                                                                                                                                         |
| <p><strong>New Alerts APIs</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p>       | <p>The following new endpoints are available for the Alerts API:</p><ul><li>Get Alert Count of Policies - <a href="https://pan.dev/prisma-cloud/api/cspm/alert-policy-list/">POST /alert/v1/policy</a></li><li>Get Alert Count by Policy Groups - <a href="https://pan.dev/prisma-cloud/api/cspm/alert-aggregation/">POST /alert/v1/aggregate</a></li><li>Get Alert Evidence Graph - <a href="https://pan.dev/prisma-cloud/api/cspm/get-alert-evidence-graph/">GET /alert/v1/{id}/graph</a></li></ul> |
| <p><strong>Updates to Alerts API</strong></p><p><mark style="background-color:orange;">23.11.1</mark></p> | The [List Alert Remediation Commands](https://pan.dev/prisma-cloud/api/cspm/get-alerts-remediation/) API and [Remediate Alert](https://pan.dev/prisma-cloud/api/cspm/perform-remediation-for-alert/) API will have an additional optional parameter, `findingId`. This parameter is used to remediate the findings of an attack path alert.                                                                                                                                                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2023/features-introduced-in-november-2023.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
