> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-april-2024.md).

# Features Introduced in April 2024

Learn what’s new on Prisma® Cloud in April 2024.

* [New Features](#new-features)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [IAM Policies](#iam-policies)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)
* [Changes in Existing Behavior](#changes-in-existing-behavior)

## New Features

| **Feature**                                                                                                                                                                                                                                        | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Integration Support for Cortex XSOAR Version 8.0</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.4.2</mark></p>                                  | <p>The <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-cortex-xsoar">Cortex XSOAR integration</a> is enhanced to support both XSOAR versions 6.0 and 8.0. As a result, you will now see the <strong>Versions Available</strong> option on the Prisma Cloud Console. This option allows you to select between XSOAR versions 6.0 or 8.0 when you create or update the integration on Prisma Cloud.</p><p><img src="/files/crdD2vKIPmsJuTzJxG7m" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                |
| <p><strong>Share Views with Ease</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.4.2</mark></p>                                                             | <p>Accelerate team collaboration and communication with Prisma Cloud®'s shareable <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/create-and-manage-dashboards#sharedashboards">Dashboards</a> and <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/create-and-manage-saved-views">Saved Views</a>. Enhancements to Prisma Cloud provide a seamless way to share custom dashboards and saved views with other users in your tenant and/or organization. You can now configure the access level of any dashboard or saved view that you have created to make it Public and viewable by any user within your tenant. Review and/or change the access level or visibility status of any Dashboard/Saved View at any time, from the Manage Dashboards/Saved Views page.</p><p><img src="/files/JQmzezLexCBAsKs5TDjF" alt="" data-size="original"></p> |
| <p><strong>Prisma Cloud Service in Indonesia</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.4.2</mark></p>                                                 | Prisma Cloud tenant [(app.id.prismacloud.io)](http://app.id.prismacloud.io/) is now available for the [Jakarta](https://docs.prismacloud.io/en/enterprise-edition/content-collections/get-started/console-prerequisites) region.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Identity Access RQL Attributes Added</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.4.2</mark></p>                                              | Enhancements to the [Permission Query](https://docs.prismacloud.io/en/enterprise-edition/content-collections/search-and-investigate/permissions-queries/permissions-query-attributes) RQL allow you to easily and comprehensively understand the access provided to identities in your cloud environment, without the need for investigating individual actions. Use the `action.access.level` and `action.access.isAdministrative` RQL query attributes to track over privileged access in your AWS, Azure, and GCP environments.                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>Alerts by Status Widget</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.4.1</mark></p>                                                           | The **Dashboards** page now includes the **Alerts by Status** widget. Leverage this [widget](https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/create-and-manage-dashboards#managewidgets) to enhance your alerts investigations by filtering on alert status (Resolved, Open or Dismissed) and time range.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><mark style="background-color:orange;">Update</mark> <strong>Compliance Trend Widget</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.4.1</mark></p>      | <p>The <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/create-and-manage-dashboards">Compliance Trend</a> widget now supports filtering data by the following time durations:</p><ul><li>24 hours</li><li>1 week</li><li>1 month</li><li>3 months</li><li>6 months</li><li>1 year</li><li>Year to Date</li><li>Custom</li></ul><p>Note: When you select the <strong>Custom</strong> option under <strong>Time Range</strong>, the widget only uses the <strong>Start Date</strong> and disregards the hourly timestamp. The <strong>End Date</strong> is always set to the current date, regardless of your selection.</p>                                                                                                                                                                                                                                                                     |
| <p><mark style="background-color:orange;">Update</mark> <strong>IAM Permission Query Results</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.4.1</mark></p> | <p>Enhancements to IAM permission queries in Prisma Cloud now allow you to obtain <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/search-and-investigate/permissions-queries/permissions-query-results">narrowly focused results</a> by refining your search. Choose the fields relevant to your investigation to customize and define your permission query results.</p><p><img src="/files/D46luYn4NZs4rwZWUmCU" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>Azure IAM Identity Inventory</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.4.1</mark></p>                                                      | Gain greater visibility into Azure roles, groups, service principals and managed identities with [Azure IAM Identity Inventory](https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-iam-security/azure-cloud-identity-inventory). Enforce least privileged access best practices by routinely removing unused privileges and permissions within your Azure roles and entitlements. Select **Suggest Least Privilege Access** to modify existing permissions and generate a new policy in JSON, and Terraform format, that includes only the permissions required based on actual usage.                                                                                                                                                                                                                                                                                                       |

## API Ingestions

| **Service**                                                                                                                                                                           | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><mark style="background-color:orange;">Update</mark> <strong>AWS Application Auto Scaling</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p> | <p><strong>aws-application-autoscaling-scaling-policy</strong></p><p>The AWS Application Auto Scaling API now includes an additional field called <code>ResourceName</code>.</p>                                                                                                                                                                                                                                                                           |
| <p><mark style="background-color:orange;">Update</mark> <strong>Amazon API Gateway</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>           | <p><strong>aws-apigateway-method</strong></p><p>The aws-apigateway-method API has been updated to exclude to exclude the <code>methodIntegration.cacheNamespace</code> field from the JSON because it changes frequently causing too many resource snapshots.</p>                                                                                                                                                                                          |
| <p><strong>Amazon Detective</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                                  | <p><strong>aws-detective-datasource-package</strong></p><p>Additional permissions required:</p><ul><li><code>detective:ListGraphs</code></li><li><code>detective:ListDatasourcePackages</code></li></ul><p>The Security Audit role includes the <code>detective:ListGraphs</code> permission. You must manually add the <code>detective:ListDatasourcePackages</code> permission to the CFT template to enable it.</p>                                     |
| <p><strong>Amazon Polly</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                                      | <p><strong>aws-polly-speech-synthesis-task</strong></p><p>Additional permission required:</p><ul><li><code>polly:ListSpeechSynthesisTasks</code></li></ul><p>You must manually add the permission to the CFT template to enable it.</p>                                                                                                                                                                                                                    |
| <p><strong>Amazon SES</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                                        | <p><strong>aws-ses-configuration-set</strong></p><p>Additional permissions required:</p><ul><li><code>ses:ListConfigurationSets</code></li><li><code>ses:DescribeConfigurationSet</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                 |
| <p><strong>AWS Batch</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                                         | <p><strong>aws-batch-job-queue</strong></p><p>Additional permission required:</p><ul><li><code>batch:DescribeJobQueues</code></li></ul><p>You must manually add the permission to the CFT template to enable it.</p>                                                                                                                                                                                                                                       |
| <p><strong>Azure CDN</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                                         | <p><strong>azure-frontdoor-standardpremium-routes</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Cdn/profiles/read</code></li><li><code>Microsoft.Cdn/profiles/afdendpoints/read</code></li><li><code>Microsoft.Cdn/profiles/afdendpoints/routes/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                         |
| <p><strong>Azure CDN</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                                         | <p><strong>azure-frontdoor-standardpremium-afd-custom-domains</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Cdn/profiles/read</code></li><li><code>Microsoft.Cdn/profiles/customdomains/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                 |
| <p><strong>Azure SQL Database</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                                | <p><strong>azure-sql-managed-instance-vulnerability-assessments</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Sql/managedInstances/read</code></li><li><code>Microsoft.Sql/managedInstances/vulnerabilityAssessments/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                    |
| <p><strong>Azure SQL Database</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                                | <p><strong>azure-sql-managed-instance-encryption-protectors</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Sql/managedInstances/read</code></li><li><code>Microsoft.Sql/managedInstances/encryptionProtector/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                             |
| <p><strong>Azure Synapse Analytics</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                           | <p><strong>azure-synapse-workspace-sql-pools</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Synapse/workspaces/read</code></li><li><code>Microsoft.Synapse/workspaces/sqlPools/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                           |
| <p><strong>Google Traffic Director</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                           | <p><strong>gcloud-traffic-director-secure-web-proxy-url-list</strong></p><p>Additional permission required:</p><ul><li><code>networksecurity.urlLists.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                 |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                       | <p><strong>gcloud-vertex-ai-aiplatform-notebook-runtime-template</strong></p><p>Additional permissions required:</p><ul><li><code>aiplatform.notebookRuntimeTemplates.list</code></li><li><code>aiplatform.notebookRuntimeTemplates.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                          |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                       | <p><strong>gcloud-vertex-ai-aiplatform-notebook-runtime</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.notebookRuntimes.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                   |
| <p><strong>Google Traffic Director</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                           | <p><strong>gcloud-traffic-director-gateway-security-policy</strong></p><p>Additional permission required:</p><ul><li><code>networksecurity.gatewaySecurityPolicies.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                    |
| <p><strong>Google Traffic Director</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>                                                           | <p><strong>gcloud-traffic-director-gateway-security-policy-rule</strong></p><p>Additional permissions required:</p><ul><li><code>networksecurity.gatewaySecurityPolicies.list</code></li><li><code>networksecurity.gatewaySecurityPolicyRules.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                        |
| <p><strong>Amazon Cognito</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                    | <p><strong>aws-cognito-sync-pool-usage</strong></p><p>Additional permission required:</p><ul><li><code>cognito-sync:ListIdentityPoolUsage</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                          |
| <p><strong>Amazon Comprehend</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                 | <p><strong>aws-comprehend-entities-detection-jobs</strong></p><p>Additional permission required:</p><ul><li><code>comprehend:ListEntitiesDetectionJobs</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                             |
| <p><strong>Amazon Comprehend</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                 | <p><strong>aws-comprehend-document-classifier-summary</strong></p><p>Additional permission required:</p><ul><li><code>comprehend:ListDocumentClassifierSummaries</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                   |
| <p><strong>Amazon Comprehend</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                 | <p><strong>aws-comprehend-document-classifier</strong></p><p>Additional permission required:</p><ul><li><code>comprehend:ListDocumentClassifiers</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                   |
| <p><strong>Amazon Device Farm Projects</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                       | <p><strong>aws-device-farm-projects</strong></p><p>Additional permission required:</p><ul><li><code>devicefarm:ListProjects</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                        |
| <p><mark style="background-color:orange;">Update</mark> <strong>Amazon DynamoDB</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>              | <p><strong>aws-dynamodb-describe-table</strong></p><p>Additional permission required:</p><ul><li><code>dynamodb:DescribeContinuousBackups</code></li></ul><p>The Security Audit role includes the permission.</p><p>The <code>aws-dynamodb-describe-table</code> API is also updated to include <code>ContinuousBackupsDescription</code> field in the resource JSON.</p>                                                                                  |
| <p><strong>Amazon Elastic Transcoder Pipelines</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                               | <p><strong>aws-elastic-transcoder-pipelines</strong></p><p>Additional permission required:</p><ul><li><code>elastictranscoder:ListPipelines</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                        |
| <p><strong>Amazon ElasticBeanstalk Applications</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                              | <p><strong>aws-elasticbeanstalk-applications</strong></p><p>Additional permission required:</p><ul><li><code>elasticbeanstalk:DescribeApplications</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                 |
| <p><strong>Amazon GuardDuty</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                  | <p><strong>aws-guardduty-organization-configuration</strong></p><p>Additional permissions required:</p><ul><li><code>guardduty:ListDetectors</code></li><li><code>guardduty:DescribeOrganizationConfiguration</code></li></ul><p>The Security Audit role includes the <code>guardduty:ListDetectors</code> permission. You must manually add the <code>guardduty:DescribeOrganizationConfiguration</code> permission to the CFT template to enable it.</p> |
| <p><strong>Amazon IoT Analytics Datastores</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                   | <p><strong>aws-iot-analytics-datastores</strong></p><p>Additional permission required:</p><ul><li><code>iotanalytics:ListDatastores</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                |
| <p><strong>Amazon IoT Events Inputs</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                          | <p><strong>aws-iot-events-inputs</strong></p><p>Additional permission required:</p><ul><li><code>iotevents:ListInputs</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                              |
| <p><strong>Amazon Lookout for Vision Projects</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                | <p><strong>aws-lookoutvision-projects</strong></p><p>Additional permission required:</p><ul><li><code>lookoutvision:ListProjects</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                   |
| <p><strong>Amazon LookoutEquipment Datasets</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                  | <p><strong>aws-lookoutequipment-datasets</strong></p><p>Additional permission required:</p><ul><li><code>lookoutequipment:ListDatasets</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                             |
| <p><strong>Amazon Servicecatalog Portfolios</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                  | <p><strong>aws-servicecatalog-portfolios</strong></p><p>Additional permission required:</p><ul><li><code>servicecatalog:ListPortfolios</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                             |
| <p><strong>Amazon SWF Domains</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                | <p><strong>aws-swf-domains</strong></p><p>Additional permission required:</p><ul><li><code>swf:ListDomains</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                         |
| <p><strong>AWS ComprehendMedical Entities Detection V2 Jobs</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                  | <p><strong>aws-comprehendmedical-entities-detection-v2-jobs</strong></p><p>Additional permission required:</p><ul><li><code>comprehendmedical:ListEntitiesDetectionV2Jobs</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                          |
| <p><strong>AWS Greengrass Core Definitions</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                   | <p><strong>aws-greengrass-core-definitions</strong></p><p>Additional permission required:</p><ul><li><code>greengrass:ListCoreDefinitions</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                          |
| <p><strong>AWS Greengrass Groups</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                             | <p><strong>aws-greengrass-groups</strong></p><p>Additional permission required:</p><ul><li><code>greengrass:ListGroups</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                             |
| <p><strong>AWS IoTFleetWise Signal Catalogs</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                  | <p><strong>aws-iotfleetwise-signal-catalogs</strong></p><p>Additional permission required:</p><ul><li><code>iotfleetwise:ListSignalCatalogs</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                        |
| <p><strong>AWS LookoutMetrics Anomaly Detectors</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                              | <p><strong>aws-lookoutmetrics-anomaly-detectors</strong></p><p>Additional permission required:</p><ul><li><code>lookoutmetrics:ListAnomalyDetectors</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                |
| <p><strong>AWS Managed Blockchain Networks List</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                              | <p><strong>aws-managed-blockchain-networks</strong></p><p>Additional permission required:</p><ul><li><code>managedblockchain:ListNetworks</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                          |
| <p><strong>AWS OpsWorks Describe User Profiles</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                               | <p><strong>aws-opsworks-user-profiles</strong></p><p>Additional permission required:</p><ul><li><code>opsworks:DescribeUserProfiles</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                |
| <p><strong>AWS Polly Voices</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                  | <p><strong>aws-polly-voices</strong></p><p>Additional permission required:</p><ul><li><code>polly:DescribeVoices</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                   |
| <p><strong>AWS Resilience Hub</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                | <p><strong>aws-resiliencehub-apps</strong></p><p>Additional permission required:</p><ul><li><code>resiliencehub:ListApps</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                           |
| <p><strong>AWS SecurityHub Describe Standards</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                | <p><strong>aws-securityhub-standards</strong></p><p>Additional permission required:</p><ul><li><code>securityhub:DescribeStandards</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                 |
| <p><strong>AWS Service Discovery Namespaces</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                  | <p><strong>aws-servicediscovery-namespaces</strong></p><p>Additional permission required:</p><ul><li><code>servicediscovery:ListNamespaces</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                         |
| <p><strong>Azure Active Directory</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                            | <p><strong>azure-active-directory-directoryrole-definition</strong></p><p>Additional permissions required:</p><ul><li><code>EntitlementManagement.Read.All</code></li><li><code>RoleManagement.Read.All</code></li></ul><p>The Global Reader role includes the permissions.</p>                                                                                                                                                                            |
| <p><strong>Azure Active Directory</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                            | <p><strong>azure-active-directory-directoryrole-assignment</strong></p><p>Additional permissions required:</p><ul><li><code>EntitlementManagement.Read.All</code></li><li><code>RoleManagement.Read.All</code></li></ul><p>The Global Reader role includes the permissions.</p>                                                                                                                                                                            |
| <p><strong>Azure App Service</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                 | <p><strong>azure-app-service-web-apps-configurations</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Web/sites/Read</code></li><li><code>Microsoft.Web/sites/config/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                       |
| <p><strong>Azure Data Factory</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                | <p><strong>azure-data-factory-v2-linked-services</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.DataFactory/factories/read</code></li><li><code>Microsoft.DataFactory/factories/linkedservices/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                           |
| <p><strong>Azure Data Factory</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                                | <p><strong>azure-data-factory-v2-integration-runtimes</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.DataFactory/factories/read</code></li><li><code>Microsoft.DataFactory/factories/integrationruntimes/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                 |
| <p><mark style="background-color:orange;">Update</mark> <strong>Azure Cosmos DB</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>              | The `azure-cosmos-db` API is updated to include `minimalTlsVersion` field in the resource JSON.                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                       | <p><strong>gcloud-vertex-ai-aiplatform-deployment-resource-pool</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.deploymentResourcePools.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                    |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                       | <p><strong>gcloud-vertex-ai-aiplatform-nas-job</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.nasJobs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                     |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                       | <p><strong>gcloud-vertex-ai-aiplatform-batch-prediction-job</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.batchPredictionJobs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                            |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                       | <p><strong>gcloud-vertex-ai-aiplatform-model</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.models.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                        |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>                                                       | <p><strong>gcloud-vertex-ai-aiplatform-specialist-pool</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.specialistPools.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                     |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><p><strong>GCP Service account is publicly accessible</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p></td><td><p>This policy identifies GCP Service accounts that are publicly accessible.</p><p>GCP Service accounts are intended to be used by an application or compute workload, rather than a person. It can be granted permission to perform actions in the GCP project as any other GCP user. Allowing access to 'allUsers' or 'allAuthenticatedUsers' over a service account would allow unwanted access to the public and could lead to a security breach.</p><p>As a security best practice, follow the principle of Least Privilege and grant permissions to entities only on an as needed basis. It is recommended to avoid granting permission to 'allUsers' or 'allAuthenticatedUsers'.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-iam-service-accounts-list' AND json.rule = ( iamPolicy.bindings[].members contains "allUsers" or iamPolicy.bindings[].members contains "allAuthenticatedUsers" ) and ( disabled does not exist or disabled is false )
</code></pre></td></tr><tr><td><p><strong>AWS DynamoDB table does not have (PITR) point-in-time recovery enabled</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p></td><td><p>This policy identifies AWS DynamoDB tables that do not have point-in-time recovery (backup) enabled.</p><p>AWS DynamoDB enables you to back up your table data continuously by using point-in-time recovery (PITR) with per-second granularity. This helps in protecting your data against accidental write or delete operations.</p><p>It is recommended to enable point-in-time recovery functionality on the DynamoDB table to protect data.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-dynamodb-describe-table' AND json.rule = tableStatus equal ignore case ACTIVE AND continuousBackupsDescription.pointInTimeRecoveryDescription.pointInTimeRecoveryStatus does not equal ENABLED
</code></pre></td></tr><tr><td><p><strong>AWS Cognito identity pool allows unauthenticated guest access</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p></td><td><p>This policy identifies AWS Cognito identity pools that allow unauthenticated guest access.</p><p>AWS Cognito identity pools unauthenticated guest access and allows unauthenticated users to assume a role in your AWS account. These unauthenticated users will be granted permissions of the assumed role which may have more privileges than that are intended. This could lead to unauthorized access or data leakage.</p><p>It is recommended to disable unauthenticated guest access for the Cognito identity pools.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-cognito-identity-pool' AND json.rule = allowUnauthenticatedIdentities is true
</code></pre></td></tr><tr><td><p><strong>AWS GuardDuty detector is not enabled</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p></td><td><p>This policy identifies the AWS GuardDuty detector that is not enabled in specific regions. GuardDuty identifies potential security threats in the AWS environment by analyzing data collected from various sources.</p><p>The GuardDuty detector is the entity within the GuardDuty service that does this analysis. Failure to enable GuardDuty increases the risk of undetected threats and vulnerabilities which could lead to compromises in the AWS environment.</p><p>It is recommended to enable GuardDuty detectors in all regions to reduce the risk of security breaches.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-guardduty-detector' AND json.rule = status does not equal ENABLED
</code></pre></td></tr><tr><td><p><strong>AWS Glue Job not encrypted by Customer Managed Key (CMK)</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p></td><td><p>This policy identifies AWS Glue jobs that are encrypted using the default KMS key instead of CMK (Customer Managed Key) or using the CMK that is disabled.</p><p>AWS Glue allows you to specify whether the data processed by the job should be encrypted when stored in data storage locations such as Amazon S3. To protect sensitive data from unauthorized access, users can specify CMK to get enhanced security, and control over the encryption key and also comply with any regulatory requirements.</p><p>It is recommended to use a CMK to encrypt the AWS Glue job data as it provides complete control over the encrypted data.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-glue-job' as X; config from cloud.resource where api.name = 'aws-glue-security-configuration' as Y; config from cloud.resource where api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.keyManager does not equal CUSTOMER or (keyMetadata.keyManager equals CUSTOMER and keyMetadata.keyState equals Disabled) as Z; filter '$.X.SecurityConfiguration does not exist or ( $.X.SecurityConfiguration equals $.Y.name and ($.Y.encryptionConfiguration.s3Encryption[*].s3EncryptionMode does not equal "SSE-KMS" or ($.Y.encryptionConfiguration.s3Encryption[*].kmsKeyArn exists and $.Y.encryptionConfiguration.s3Encryption[*].kmsKeyArn equals $.Z.keyMetadata.arn)))' ; show X;
</code></pre></td></tr><tr><td><p><strong>AWS EC2 Auto Scaling Launch Configuration is not using encrypted EBS volumes</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p>This policy identifies AWS EC2 Auto Scaling Launch Configurations that are not using encrypted EBS volumes.</p><p>A launch configuration defines an instance configuration template that an Auto Scaling group uses to launch EC2 instances. Amazon Elastic Block Store (EBS) volumes allow you to create encrypted launch configurations when creating EC2 instances and auto scaling groups. When the entire EBS volume is encrypted, data stored at rest, in-transit, and snapshots are encrypted. This protects the data from unauthorized access.</p><p>As a security best practice for data protection, enable encryption for all EBS volumes at auto scaling launch configuration.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-ec2-autoscaling-launch-configuration' AND json.rule = blockDeviceMappings[*].ebs exists AND blockDeviceMappings[?any(ebs.encrypted is false)] exists
</code></pre></td></tr><tr><td><p><strong>AWS RDS cluster encryption in transit is not configured</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p>This policy identifies AWS RDS database clusters that are not configured with encryption in transit. This covers MySQL, PostgreSQL, and Aurora clusters.</p><p>Enabling encryption is crucial to protect data as it moves through the network and enhances the security between clients and storage servers. Without encryption, sensitive data transmitted between your application and the database is vulnerable to interception by malicious actors. This could lead to unauthorized access, data breaches, and potential compromises of confidential information.</p><p>It is recommended that data be encrypted while in transit to ensure its security and reduce the risk of unauthorized access or data breaches.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-rds-db-cluster' as X; config from cloud.resource where api.name = 'aws-rds-db-cluster-parameter-group' AND json.rule = (((DBParameterGroupFamily starts with "postgres" or DBParameterGroupFamily starts with "aurora-postgresql") and (['parameters'].['rds.force_ssl'].['ParameterValue'] does not equal 1 or ['parameters'].['rds.force_ssl'].['ParameterValue'] does not exist)) or ((DBParameterGroupFamily starts with "aurora-mysql" or DBParameterGroupFamily starts with "mysql") and (parameters.require_secure_transport.ParameterValue is not member of ("ON", "1") or parameters.require_secure_transport.ParameterValue does not exist))) as Y; filter '$.X.dBclusterParameterGroupArn equals $.Y.DBClusterParameterGroupArn' ; show X;
</code></pre></td></tr><tr><td><p><strong>AWS Secrets Manager secret not encrypted by Customer Managed Key (CMK)</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p>This policy identifies AWS Secrets Manager secrets that are encrypted using the default KMS key instead of CMK (Customer Managed Key) or using a CMK that is disabled.</p><p>AWS Secrets Manager secrets are a secure storage solution for sensitive information like passwords, API keys, and tokens in the AWS cloud. Secrets Manager secrets are encrypted by default by AWS managed key but users can specify CMK to get enhanced security, control over the encryption key, and also comply with any regulatory requirements.</p><p>As a security best practice, using CMK to encrypt your Secrets Manager secrets is advisable as it gives you full control over the encrypted data.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-secretsmanager-describe-secret' as X; config from cloud.resource where api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.keyManager does not equal CUSTOMER or (keyMetadata.keyManager equals CUSTOMER and keyMetadata.keyState equals Disabled) as Y; filter '($.X.kmsKeyId does not exist ) or ($.X.kmsKeyId exists and $.X.kmsKeyId equals $.Y.keyMetadata.arn)'; show X;
</code></pre></td></tr><tr><td><p><strong>AWS SageMaker endpoint data encryption at rest not configured</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p>This policy identifies AWS SageMaker Endpoints not configured with data encryption at rest.</p><p>AWS SageMaker Endpoint configuration defines the resources and settings for deploying machine learning models to SageMaker endpoints. By default, SageMaker Endpoints are not encrypted at rest. Enabling the encryption helps protect the integrity and confidentiality of the data on the storage volume attached to the ML compute instance that hosts the endpoint.</p><p>It is recommended to set encryption at rest to mitigate the risk of unauthorized access and potential data breaches.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' and api.name = 'aws-sagemaker-endpoint-config' as X; config from cloud.resource where api.name = 'aws-kms-get-key-rotation-status' as Y; config from cloud.resource where api.name = 'aws-sagemaker-endpoint' AND json.rule = endpointStatus does not equal "Failed" as Z; filter '($.X.KmsKeyId does not exist or (($.X.KmsKeyId exists and $.Y.keyMetadata.keyState equals Disabled) and $.X.KmsKeyId equals $.Y.keyMetadata.arn)) and ($.X.EndpointConfigName equals $.Z.endpointConfigName)' ; show X;
</code></pre></td></tr><tr><td><p><strong>AWS DMS replication instance is publicly accessible</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p>This policy identifies AWS DMS (Database Migration Service) replication instances with public accessibility enabled.</p><p>A DMS replication instance is used to connect to your source data store, read the source data, and format the data for consumption by the target data store. When AWS DMS replication instances are publicly accessible and have public IP addresses, any machine outside the VPC can create a connection to these instances, increasing the attack surface and the possibility of malicious activity.</p><p>So it is recommended to disable public accessibility of DMS replication instances to decrease the attack surface.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-dms-replication-instance' AND json.rule = replicationInstanceStatus is not member of ('creating','deleted','deleting') and publiclyAccessible is true
</code></pre></td></tr><tr><td><p><strong>AWS Athena Workgroup not configured with data encryption at rest</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p>This policy identifies AWS Athena workgroups not configured with data encryption at rest.</p><p>AWS Athena workgroup enables you to isolate queries for you or your group of users from other queries in the same account, to set the query results location and the encryption configuration. By default, Athena workgroup query run results are not encrypted at rest and client side settings can override the workgroup settings. Encrypting workgroups and preventing overrides from the client side helps in protecting the integrity and confidentiality of the data stored on Athena.</p><p>It is recommended to set encryption at rest and enable 'override client-side settings' to mitigate the risk of unauthorized access and potential data breaches.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-athena-workgroup' AND json.rule = WorkGroup.State equal ignore case enabled and (WorkGroup.Configuration.ResultConfiguration.EncryptionConfiguration does not exist or (WorkGroup.Configuration.EngineVersion.EffectiveEngineVersion contains Athena and WorkGroup.Configuration.EnforceWorkGroupConfiguration is false))
</code></pre></td></tr><tr><td><p><strong>AWS root account activity detected in last 14 days</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p>This policy identifies if AWS root account activity was detected within the last 14 days.</p><p>The AWS root account user is the primary administrative identity associated with an AWS account, providing complete access to all AWS services and resources. Since the root user has complete access to the account, adopting the principle of least privilege is important to lower the risk of unintentional disclosure of highly privileged credentials and inadvertent alterations. It’s also advised to remove the root user access keys and restrict the use of the root user, refraining from using them for routine or administrative duties.</p><p>It is recommended to restrict the use of the AWS root account.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-iam-get-credential-report' AND json.rule = 'user equals "&#x3C;root_account>" and ( _DateTime.ageInDays(access_key_1_last_used_date) &#x3C; 14 or _DateTime.ageInDays(access_key_2_last_used_date) &#x3C; 14 or _DateTime.ageInDays(password_last_used) &#x3C; 14 )'
</code></pre></td></tr><tr><td><p><strong>Azure Storage Sync Service configured with overly permissive network access</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p>This policy identifies Storage Sync Services configured with overly permissive network access.</p><p>A Storage Sync Service is a management construct that represents registered servers and sync groups. Allowing all traffic to the Sync Service may allow a bad actor to brute force their way into the system and potentially get access to the entire network. With a private endpoint, the network traffic path is secured on both ends and access is restricted to only defined authorized entities.</p><p>It is recommended to configure the Storage Sync Service with private endpoints to minimize the access vector.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-storage-sync-service' AND json.rule = properties.provisioningState equals Succeeded and properties.incomingTrafficPolicy equals AllowAllTraffic
</code></pre></td></tr><tr><td><p><strong>GCP Storage Bucket encryption not configured with Customer-Managed Encryption Key (CMEK)</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p>This policy identifies GCP Storage Buckets that are not configured with a Customer-Managed Encryption key.</p><p>GCP Storage Buckets might contain sensitive information. Google Cloud Storage service encrypts all data within the buckets using Google-managed encryption keys by default but users can specify Customer-Managed Keys (CMKs) to get enhanced security, control over the encryption key, and also comply with any regulatory requirements.</p><p>As a security best practice, the use of CMK to encrypt your Storage bucket is advisable as it gives you full control over the encrypted data.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-storage-buckets-list' AND json.rule = encryption.defaultKmsKeyName does not exist
</code></pre></td></tr><tr><td><p><strong>New Configuration Build Policies</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p>Added the following default policies within the <strong>Build</strong> subtype of <strong>Configuration</strong> policies under <strong>Governance</strong> for enhanced continuous integration and deployment pipeline security.</p><p><strong>AWS Networking Policies</strong></p><ul><li>TLS not enforced in SES configuration set</li></ul><p><strong>Azure General Policies</strong></p><ul><li>Azure SQL Database server not configured with private endpoint</li><li>Azure Database for MySQL server not configured with private endpoint</li><li>Azure Database for MariaDB not configured with private endpoint</li><li>Azure PostgreSQL servers not configured with private endpoint</li><li>Azure Container Registry (ACR) not zone redundant</li><li>Azure Container Instance environment variable with regular value type</li><li>Azure Synapse Workspace vulnerability assessment is disabled</li><li>Azure Microsoft Defender for Cloud set to Off for Resource Manager</li></ul><p><strong>Azure IAM Policies</strong></p><ul><li>Anonymous blob access configured in Azure storage account</li></ul><p><strong>Google Cloud General Policies</strong></p><ul><li>Vertex AI instance disks not encrypted with a Customer Managed Key (CMK)</li><li>Vertex AI tensorboard does not use a Customer Managed Key (CMK)</li><li>Vertex AI workbench instance disks not encrypted with a Customer Managed Key (CMK)</li><li>Vertex AI workbench instances are not private</li><li>Vertex AI endpoint is not using a Customer Managed Key (CMK)</li><li>Vertex AI featurestore is not configured to use a Customer Managed Key (CMK)</li><li>Document AI Processors not encrypted with a Customer Managed Key (CMK)</li><li>Document AI Warehouse Location is not configured to use a Customer Managed Key (CMK)</li><li>Vertex AI runtime is not encrypted with a Customer Managed Key (CMK)</li></ul><p><strong>Google Cloud Networking Policies</strong></p><ul><li>Vertex AI runtime is public</li><li>TPU v2 VM is public</li><li>Vertex AI endpoint is public</li><li>Vertex AI index endpoint is public</li></ul><p><strong>Google Cloud Logging Policies</strong></p><ul><li>Logging for Dialogflow CX agents is disabled</li><li>Logging for Dialogflow CX webhooks is disabled</li><li>Logging is disabled for Dialogflow agents</li></ul><p><strong>Impact-</strong> You will view policy violations for these policies on Prisma Cloud switcher <strong>Application Security > Projects</strong>. Enforcement levels for IaC Misconfigurations will now be applied to pipelines with these findings. You are required to enable the additional modules on <strong>Application Security > Settings</strong> to view violations and alerts for these policies.</p></td></tr></tbody></table>

## IAM Policies

The following OOTB IAM policies are newly added in 24.4.2 release.

<table data-header-hidden><thead><tr><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Name</strong></td><td><strong>Description</strong></td><td><strong>RQL</strong></td><td><strong>Cloud</strong></td><td><strong>Policy Severity</strong></td></tr><tr><td><strong>User account with excessive admin privileges</strong></td><td>Identifies users in Azure, AWS, and GCP which have administrative permissions that have not been used in the last 90 days.</td><td><pre><code>config from iam where source.cloud.resource.type = 'user' AND action.access.isAdministrative = true AND action.lastaccess.days > 90
</code></pre></td><td>All</td><td>Medium</td></tr><tr><td><strong>Cloud service account with excessive admin privileges</strong></td><td>Identifies cloud service accounts in Azure, AWS and GCP which have administrative permissions that have not been used in the last 90 days.</td><td><pre><code>config from iam where grantedby.cloud.entity.type IN ('service principal', 'system assigned', 'user assigned', 'serviceaccount', 'role') AND action.access.isAdministrative = true AND action.lastaccess.days > 90
</code></pre></td><td>All</td><td>Medium</td></tr><tr><td><strong>Roles with high privileges can be assumed by a service in an external account</strong></td><td>Identifies roles which have administrative permissions and can be assumed by an identity in an external account.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND grantedby.cloud.entity.type = 'role' AND action.access.isAdministrative = true AND source.cloud.accountgroup != 'Default Account Group'
</code></pre></td><td>AWS</td><td>High</td></tr><tr><td><strong>AWS Lateral Movement to Data Services Through Redshift Cluster Creation</strong></td><td>With access to the iam:PassRole, redshift:CreateCluster permissions, an adversary can create a Redshift cluster with a more privileged existing role, allowing access to more datasources.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name CONTAINS ALL ('iam:PassRole', 'redshift:CreateCluster') and grantedby.cloud.entity.type = 'role' AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>AWS</td><td>High</td></tr><tr><td><strong>Azure Lateral Movement via VM Command Execution Leveraging Managed Identity</strong></td><td>Using this role allows running commands on any virtual machine in the subscription. With 'Microsoft.Compute/virtualMachines/runCommand/action', an adversary can steal credentials connected to the VM and perform lateral movements.</td><td><pre><code>config from iam where dest.cloud.type = 'AZURE' AND action.name = 'Microsoft.Compute/virtualMachines/runCommand/action' AND grantedby.level.type = 'Azure Subscription'
</code></pre></td><td>Azure</td><td>Medium</td></tr><tr><td><strong>Azure Lateral Movement Through SSH Key Replacement and Managed Identity Exploitation on VM</strong></td><td>Using this role allows creating and changing virtual machines in the subscription. With 'Microsoft.ClassicCompute/virtualMachines/write' and 'Microsoft.ClassicCompute/virtualMachines/extensions/write', an adversary can update SSH keys for a VM.</td><td><pre><code>config from iam where dest.cloud.type = 'AZURE' AND action.name CONTAINS ALL ('Microsoft.ClassicCompute/virtualMachines/write', 'Microsoft.ClassicCompute/virtualMachines/extensions/write') AND grantedby.cloud.entity.type IN ('user assigned', 'system assigned', 'service principal', 'user') AND grantedby.level.type = 'Azure Subscription'
</code></pre></td><td>Azure</td><td>Medium</td></tr><tr><td><strong>GCP Cloud Run with basic role</strong></td><td>Identifies Cloud Run instances granted broad access due to highly permissive basic roles attached ('Viewer', 'Editor', 'Owner').</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND grantedby.cloud.policy.name IN ('Viewer', 'Editor', 'Owner')
</code></pre></td><td>GCP</td><td>Medium</td></tr><tr><td><strong>GCP Cloud Run with administrative permissions</strong></td><td>Identifies Cloud Run instances granted administrative permissions, increasing the blast radius in case of a potential compromise.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND action.access.isAdministrative = true
</code></pre></td><td>GCP</td><td>Medium</td></tr><tr><td><strong>GCP Cloud Run Job Public Execution via Default Compute SA Modification</strong></td><td>An entity can update Cloud Run job code and public execution permissions, potentially with high permissions.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND action.name = 'run.jobs.setIamPolicy' AND grantedby.level.type = 'GCP Project'
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Lateral Access Expansion by Making Cloud Run Publicly Executable</strong></td><td>An entity can update Cloud Run instance code and public execution permissions, potentially with high permissions.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND action.name = 'run.services.setIamPolicy' AND grantedby.level.type = 'GCP Project'
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Project-Wide Lateral Movement via SSH Key Modification for VMs</strong></td><td>An entity can update VM instance metadata for all project VMs and modify SSH keys for virtual machines inside the project, allowing a lateral movement and hijacking of VMs.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND action.name = 'compute.projects.setCommonInstanceMetadata'
</code></pre></td><td>GCP</td><td>High</td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><p><strong>AWS EBS volume region with encryption is disabled</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p><strong>Changes—</strong> The RQL is updated to check for Function app configured with default network configuration</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Updated Recommendation Steps</strong>:</p><p>Follow the steps outlined <a href="https://docs.aws.amazon.com/ebs/latest/userguide/work-with-ebs-encr.html#encryption-by-default">here</a> to enable encryption at the region level by default.</p><p><strong>Additional Information</strong>:</p><ul><li>To detect existing EBS volumes that are not encrypted ; refer Saved Search: AWS EBS volumes are not encrypted_RL</li><li>To detect existing EBS volumes that are not encrypted with CMK, refer Saved Search: AWS EBS volume not encrypted using Customer Managed Key_RL.</li></ul><p><strong>Impact—</strong> No impact</p></td></tr><tr><td><p><strong>Azure Function app configured with public network access</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p><strong>Changes—</strong> The RQL will be updated to check for Function app configured with default network configuration</p><p><strong>Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = 'kind starts with functionapp and properties.state equal ignore case running and properties.publicNetworkAccess exists and properties.publicNetworkAccess equal ignore case Enabled and config.ipSecurityRestrictions[?any(action equals Allow and ipAddress equals Any)] exists'
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = 'kind starts with functionapp and properties.state equal ignore case running and ((properties.publicNetworkAccess exists and properties.publicNetworkAccess equal ignore case Enabled) or (properties.publicNetworkAccess does not exist)) and config.ipSecurityRestrictions[?any(action equals Allow and ipAddress equals Any)] exists'
</code></pre><p><strong>Impact—</strong> Medium. New Alerts will be generated when the <code>publicNetworkAccess</code> for function app is set with default networking configuration.</p></td></tr><tr><td><p><strong>AWS MFA is not enabled on Root account</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL is updated to be inline with standard conventions followed by Prisma Cloud.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND cloud.service = 'IAM' AND api.name  = 'aws-iam-get-credential-report' AND json.rule = 'user equals "&#x3C;root_account>" and mfa_active is false and arn does not contain gov:'
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name  = 'aws-iam-get-credential-report' AND json.rule = 'user equals "&#x3C;root_account>" and mfa_active is false and arn does not contain gov:'
</code></pre><p><strong>Impact—</strong> None.</p></td></tr><tr><td><strong>Policy Updates—Metadata</strong></td><td></td></tr><tr><td><p><strong>AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy name is updated to show admin ports information in the policy names for better readability.</p><p><strong>Current Policy Name—</strong> AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports</p><p><strong>Updated Policy Name—</strong> AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389</p><p><strong>Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> None.</p></td></tr><tr><td><p><strong>Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy name is updated to show admin ports information in the policy names for better readability.</p><p><strong>Current Policy Name—</strong> Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports</p><p><strong>Updated Policy Name—</strong> Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389</p><p><strong>Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> None.</p></td></tr><tr><td><p><strong>GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy name is updated to show admin ports information in the policy names for better readability.</p><p><strong>Current Policy Name—</strong> GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports</p><p><strong>Updated Policy Name—</strong> GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389</p><p><strong>Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> None.</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                                                                                         | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Support for CRI Profile v2.0</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p> | <p>Prisma Cloud supports the CRI Profile v2.0 compliance standard. This framework is designed to offer an effective method for managing technology and cybersecurity risks, addressing dynamic threats while providing sufficient assurance to government regulators. The compliance standard encompasses all requirements and controls outlined by the Cyber Risk Institute (CRI), and is meticulously aligned with Prisma Cloud policies.</p><p>You can now view this built-in standard and the associated policies on the <strong>Compliance > Standards</strong> page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p> |

## REST API Updates

| **Change**                                                                                                                                                                       | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><mark style="background-color:orange;">Update</mark> <strong>Integration APIs</strong></p><p><mark style="background-color:orange;"><strong>24.4.2</strong></mark></p>        | The [Integration APIs](https://pan.dev/prisma-cloud/api/cspm/api-integration-config/#cortex-xsoar) now support Cortex XSOAR 8.0. All Integration APIs have an additional `demistoVersion` parameter to recognize the Cortex XSOAR version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><mark style="background-color:orange;">Update</mark> <strong>Alerts API Responses</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>    | <p>The following <strong>Alert API</strong> responses include a new <code>investigateOptions</code> field:</p><ul><li><p><strong>List Alerts</strong></p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-alerts/">GET /alert</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-alerts/">POST /alert</a></li></ul></li><li><p><strong>List Alerts V2</strong></p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-alerts-v-2/">GET v2/alert</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-alerts-v-2/">POST v2/alert</a></li></ul></li><li><p><strong>Alert Info</strong></p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-alert/">GET alert/:id</a></li></ul></li></ul> |
| <p><mark style="background-color:orange;">Update</mark> <strong>GET CVE Overview API</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>    | <p>The response of the <a href="https://pan.dev/prisma-cloud/api/cspm/cve-overview/">GET CVE Overview</a> endpoint includes the following changes:</p><ul><li><p>The following new parameters are added to <strong>impactedDistrosList</strong>:</p><ul><li>highestCVSS</li><li>highestSeverity</li><li>firstPublishedDate</li><li>lastModifiedDate</li></ul></li><li><p>The following new parameters are added to <strong>impactedDistrosList.distroDetailsList</strong>:</p><ul><li>publishedDate</li><li>modifiedDate</li></ul></li><li>The data type of <strong>impactedDistrosList.distroDetailsList.severity</strong> is changed from integer to string.</li></ul>                                                                  |
| <p><mark style="background-color:orange;">Update</mark> <strong>Compliance Posture APIs</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p> | The [Get Compliance Trend V2 - POST](https://pan.dev/prisma-cloud/api/cspm/post-compliance-posture-trend-v-2/) API now supports the `timeRange` parameter. For more information on Time Ranges , see [CSPM Time Range Model](https://pan.dev/prisma-cloud/api/cspm/api-time-range-model).                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><mark style="background-color:orange;">Update</mark> <strong>Search APIs</strong></p><p><mark style="background-color:orange;"><strong>24.4.1</strong></mark></p>             | <p>New version of <strong>Config Search</strong> APIs include a new <code>Time Range</code> model and various enhancements to response values.</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/search-config-by-search-id-v-2">Perform Config Search by Search Id V2 - POST</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/search-config-v2">Perform Config Search V2 - POST</a></li></ul>                                                                                                                                                                                                                                                                                                                          |

## Changes in Existing Behavior

| **Feature**                                                                                                                                                                                                  | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>S3 Flow Logs with Hourly Partition</strong></p><p><mark style="background-color:orange;">This change was first announced in the look ahead that was published with the 23.1.1 release.</mark></p> | <p>If you currently ingest AWS flow logs using S3 with the 24-hour partition, you need to change it to the hourly partition.</p><p>To make this change, <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-aws/configure-flow-logs">Configure Flow Logs</a> to use the hourly partition and enable the required additional fields.</p><p><strong>Impact</strong>— VPC Flow logs with partitions set to <strong>Every 24 hours (default)</strong> was disabled on February 29th, 2024. As a result, you will no longer be able to monitor or receive alerts for these logs. If you have any questions, contact your Prisma Cloud Customer Success Representative immediately.</p> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-april-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
