> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-february-2024.md).

# Features Introduced in February 2024

Learn what’s new on Prisma® Cloud in February 2024.

* [Announcement](#announcement)
* [New Features](#new-features)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [IPs for Runtime Security](#update-ips-for-runtime)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)

## Announcement

| **Feature**                     | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Prisma Cloud Darwin Release** | <p>The <strong>Prisma Cloud Darwin Release</strong> is now available for Prisma Cloud environments on app.gov. With the Code to Cloud™ intelligence capabilities in this release, your security and development teams can work together to reduce application risks and prevent breaches.</p><p>With this change, your tenant will be updated with the new intuitive user interface and <a href="https://live.paloaltonetworks.com/t5/prisma-cloud-customer-videos/prisma-cloud-evolution-amp-transformation/ta-p/556596">rich set of security capabilities</a>.</p><p>When you are upgraded to the Darwin release, refer to the <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/">Enterprise Edition documentation</a>.</p><p>Contact your Prisma Cloud Customer Success team for more details.</p> |

## New Features

| **Feature**                                                                                                                                                                                                                        | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>View Saved Filters as Saved Views</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.2.2</mark></p>                                 | <p>Saved Filters on Prisma Cloud are now available as <strong>Saved Views</strong> on the Alerts, Compliance, and Governance pages. Navigate to <strong>Home > Alerts/Compliance/Governance > Overview</strong> to find your filter combinations available as <strong>Saved Views</strong>. The following caveats apply:</p><ul><li>Views are no longer limited to a maximum of 20.</li><li>Saved Views are enabled by default for the persona (Cloud/Runtime/Application Security) you created them in. If you use the Prisma Cloud switcher to try another persona, the view is disabled but you have the option to re-enable it.</li><li>All users, except those who were added after the migration to Saved Views will have access to previously saved filter configurations.</li></ul><p>You can also create new <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/alerts/saved-views">Saved Views</a> to store select filter combinations and table configurations for a customizable look at your security posture.</p><p><img src="/files/OgR5HL9gSBcaHITb1yRc" alt="" data-size="original"></p> |
| <p><strong>OAuth 2.0 support for ServiceNow Integration</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.2.2</mark></p>                      | Prisma Cloud has enhanced its [ServiceNow integration](https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-servicenow) with OAuth 2.0 support, establishing a standardized and secure authentication framework for heightened security. This enhancement simplifies access token management, allowing Prisma Cloud to interact seamlessly with ServiceNow on your behalf, without exposing sensitive credentials. The result reduces the risk of unauthorized access while ensuring a more efficient and secure integration experience.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><mark style="background-color:orange;">Update</mark> <strong>Enhancements</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.2.2</mark></p> | <p>Prisma Cloud includes the following enhancements for <code>config from network</code> RQL searches and policies:</p><ul><li>Significant performance improvement on the Investigate page, with search results now delivered faster on an average.</li><li>Support for asset exclusion based on asset name, VPC ID, and tags.</li></ul><p>The following enhancements are specific to AWS:</p><ul><li>Support for NLB and ALB listener port analysis.</li><li>Network path analysis now considers security groups attached to NLB.</li><li>Better representation of network path for East-West traffic over a transit gateway.</li><li>Better representation of network path for East-West traffic within a single VPC.</li></ul><p>The following enhancement is specific to Azure:</p><ul><li>Support for NLB and ALB listener port analysis.</li></ul>                                                                                                                                                                                                                                                                              |
| <p><strong>Support Amazon Linux 2023</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">24.2.2</mark></p>                                                | Prisma Cloud now supports Amazon Linux 2023 OS scans and security feed integration for Amazon Linux 2023.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>Enhanced CSV Organization</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">24.2.2</mark></p>                                                | Segregating vulnerability and compliance findings based on Download Context.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Enhanced Compliance Report</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">24.2.2</mark></p>                                               | Added a new **Result** column to the compliance report CSV file. To get the report, go to **Monitor > Compliance > Compliance Explorer** and select **Containers**, **Images**, or **Hosts**. The new column shows either **pass** or **fail** for each resource and the corresponding compliance check ID.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Detect Go Stdlib Vulnerabilities at the Package Level</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">24.2.2</mark></p>                    | In O’Neal Update 3, Prisma Cloud has enhanced its capability to detect vulnerabilities in Go libraries. Previously, a broad approach was used for Go stdlib libraries, categorizing CVEs as "Go" vulnerabilities rather than associating them with specific vulnerable standard libraries. This update offers a more precise classification, allowing for the identification of specific vulnerable symbols within libraries. Moreover, the latest agents can now detect both stdlib with symbols they utilize and the installed Go runtime. This comprehensive approach enables Prisma Cloud to conduct more accurate vulnerability assessments, leading to a significant reduction in false positives. If you have utilized the Go detection capabilities previously, you are likely to experience a noticeable reduction in the number of reported vulnerabilities due to this improvement.                                                                                                                                                                                                                                        |
| <p><strong>Support for Just in Time (JIT) Auto-Provisioning</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.2.1</mark></p>                  | Prisma Cloud offers System Administrators the ability to auto-provision users using the Open ID Connect (OIDC) Single Sign-On (SSO) configuration. Configure [OIDC Just in Time (JIT)](https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/setup-sso-integration-on-prisma-cloud/get-started-with-oidc-sso/get-started-with-oidc-jit) provisioning to grant Prisma Cloud users limited real-time access when they log into their IdP with the appropriate credentials.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Support for New Region on GCP</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.2.1</mark></p>                                     | <p>Prisma Cloud now ingests data for resources deployed in the Johannesburg region on GCP.</p><p>To review a list of supported regions, select <strong>Inventory > Assets</strong>, and choose <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/connect/connect-cloud-accounts/cloud-service-provider-regions-on-prisma-cloud">Cloud Region</a> from the filter drop-down.</p><p><img src="/files/w1pGHZ1TJpNxGMGSYJ4E" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>Added non-default branch scanning</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;">24.2.1</mark></p>                                         | You can now scan branches other than the main or master, such as a feature branch or sprint branch, to obtain a comprehensive overview of the security issues in those branches before merging them into the main branch. For more information, under the Application Security documentation, select Get Started and navigate to [Non-Default Branch Scan](https://docs.prismacloud.io/en/enterprise-edition/content-collections/application-security/get-started/non-default-branch-scan).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |

## API Ingestions

| **Service**                                                                                                                                                                          | **API Details**                                                                                                                                                                                                                                                                                                                                                                                              |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><strong>AWS Batch</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p>                                                                        | <p><strong>aws-batch-job-definition</strong></p><p>Additional permission required:</p><ul><li><code>batch:DescribeJobDefinitions</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                     |
| <p><strong>AWS CodeBuild</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p>                                                                    | <p><strong>aws-code-build-source-credential</strong></p><p>Additional permission required:</p><ul><li><code>codebuild:ListSourceCredentials</code></li></ul><p>You must manually add the above permission to the CFT template to enable it.</p>                                                                                                                                                              |
| <p><strong>AWS CodeCommit</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p>                                                                   | <p><strong>aws-code-commit-repository</strong></p><p>Additional permissions required:</p><ul><li><code>codecommit:ListRepositories</code></li><li><code>codecommit:GetRepository</code></li></ul><p>The Security Audit Policy role includes the permissions.</p>                                                                                                                                             |
| <p><strong>AWS CodeCommit</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p>                                                                   | <p><strong>aws-code-commit-approval-rule-template</strong></p><p>Additional permissions required:</p><ul><li><code>codecommit:ListApprovalRuleTemplates</code></li><li><code>codecommit:GetApprovalRuleTemplate</code></li></ul><p>The Security Audit Policy role includes the permission for <code>codecommit:ListApprovalRuleTemplates</code>.</p>                                                         |
| <p><strong>Amazon CodePipeline</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p>                                                              | <p><strong>aws-code-pipeline-webhook</strong></p><p>Additional permission required:</p><ul><li><code>codepipeline:ListWebhooks</code></li></ul><p>You must manually add the <code>codepipeline:ListWebhooks</code> permission to the CFT template to enable it.</p>                                                                                                                                          |
| <p><strong>AWS Config</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p>                                                                       | <p><strong>aws-configservice-aggregator</strong></p><p>Additional permission required:</p><ul><li><code>config:DescribeConfigurationAggregators</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                      |
| <p><strong>AWS DataSync</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p>                                                                     | <p><strong>aws-datasync-agent</strong></p><p>Additional permissions required:</p><ul><li><code>datasync:ListAgents</code></li><li><code>datasync:DescribeAgent</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                      |
| <p><strong>Amazon EC2</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p>                                                                       | <p><strong>aws-ec2-vpc-endpoint-service</strong></p><p>Additional permission required:</p><ul><li><code>ec2:DescribeVpcEndpointServices</code></li></ul><p>The Security Audit Policy role includes the permission.</p>                                                                                                                                                                                       |
| <mark style="background-color:orange;">Update</mark> **Amazon Elastic Container Registry (ECR)**                                                                                     | <p><strong>aws-ecr-image</strong></p><p>Prisma Cloud updated the <code>aws-ecr-image</code> API to exclude the <code>lastRecordedPullTime</code> field from the JSON because it changes frequently causing too many resource snapshots.</p>                                                                                                                                                                  |
| <p><mark style="background-color:orange;">Update</mark> <strong>OCI APIs</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p>                    | <p>Prisma Cloud updated <code>oci-compute-instance</code>, <code>oci-cloudguard-security-zone</code>, and <code>oci-apimanagement-apigateway-deployment</code> APIs to prevent the ingestion of deleted resources from Oracle Cloud Service Provider.</p><p><code>oci-cloudguard-security-zone</code> will be enhanced to ingest resources from multiple compartments, extending beyond the home region.</p> |
| <p><strong>Amazon EC2 Image Builder</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                         | <p><strong>aws-imagebuilder-component</strong></p><p>Additional permissions required:</p><ul><li><code>imagebuilder:ListComponents</code></li><li><code>imagebuilder:GetComponent</code></li></ul><p>You must manually add the above permissions to the CFT template to enable them.</p>                                                                                                                     |
| <p><strong>Amazon EC2 Image Builder</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                         | <p><strong>aws-imagebuilder-image-recipe</strong></p><p>Additional permissions required:</p><ul><li><code>imagebuilder:ListImageRecipes</code></li><li><code>imagebuilder:GetImageRecipe</code></li></ul><p>You must manually add the above permissions to the CFT template to enable them.</p>                                                                                                              |
| <p><strong>Amazon EC2 Image Builder</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                         | <p><strong>aws-imagebuilder-image-pipeline</strong></p><p>Additional permissions required:</p><ul><li><code>imagebuilder:ListImagePipelines</code></li><li><code>imagebuilder:GetImagePipeline</code></li></ul><p>You must manually add the above permissions to the CFT template to enable them.</p>                                                                                                        |
| <p><strong>Amazon EC2 Image Builder</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                         | <p><strong>aws-imagebuilder-infrastructure-configuration</strong></p><p>Additional permissions required:</p><ul><li><code>imagebuilder:ListInfrastructureConfigurations</code></li><li><code>imagebuilder:GetInfrastructureConfiguration</code></li></ul><p>You must manually add the above permissions to the CFT template to enable them.</p>                                                              |
| <p><strong>AWS Elastic Disaster Recovery</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                    | <p><strong>aws-drs-job</strong></p><p>Additional permission required:</p><ul><li><code>drs:DescribeJobs</code></li></ul><p>You must manually add the above permission to the CFT template to enable it.</p>                                                                                                                                                                                                  |
| <p><strong>AWS Elastic Disaster Recovery</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                    | <p><strong>aws-drs-replication-configuration</strong></p><p>Additional permissions required:</p><ul><li><code>drs:DescribeSourceServers</code></li><li><code>drs:GetReplicationConfiguration</code></li></ul><p>You must manually add the above permissions to the CFT template to enable them.</p>                                                                                                          |
| <p><strong>AWS Elastic Disaster Recovery</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                    | <p><strong>aws-drs-source-server</strong></p><p>Additional permission required:</p><ul><li><code>drs:DescribeSourceServers</code></li></ul><p>You must manually add the above permission to the CFT template to enable it.</p>                                                                                                                                                                               |
| <p><strong>Google Cloud VMware Engine</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                       | <p><strong>gcloud-vmware-engine-network</strong></p><p>Additional permissions required:</p><ul><li><code>vmwareengine.locations.list</code></li><li><code>vmwareengine.vmwareEngineNetworks.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                            |
| <p><strong>Google Cloud VMware Engine</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                       | <p><strong>gcloud-vmware-engine-network-policy</strong></p><p>Additional permissions required:</p><ul><li><code>vmwareengine.locations.list</code></li><li><code>vmwareengine.networkPolicies.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                          |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                      | <p><strong>gcloud-vertex-ai-aiplatform-dataset</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.datasets.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                      |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                      | <p><strong>gcloud-vertex-ai-aiplatform-hyperparameter-tuning-job</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.hyperparameterTuningJobs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                    |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                      | <p><strong>gcloud-vertex-ai-aiplatform-index</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.indexes.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                         |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                      | <p><strong>gcloud-vertex-ai-aiplatform-feature-store-entity-type</strong></p><p>Additional permissions required:</p><ul><li><code>aiplatform.featurestores.list</code></li><li><code>aiplatform.entityTypes.list</code></li><li><code>aiplatform.entityTypes.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                   |
| <p><mark style="background-color:orange;">Update</mark> <strong>Google Cloud Firestore</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>      | <p><strong>gcloud-cloud-firestore-native-database</strong></p><p>Prisma Cloud updated the <code>gcloud-cloud-firestore-native-database</code> API to exclude the <code>earliestVersionTime</code> field from the resource configuration because it changes frequently causing too many resource snapshots.</p>                                                                                               |
| <p><mark style="background-color:orange;">Update</mark> <strong>Google Compute Engine (GCE)</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p> | <p><strong>gcloud-compute-autoscaler</strong></p><p>Prisma Cloud updated the <code>gcloud-compute-autoscaler</code> API to exclude the <code>recommendedSize</code> field from the resource configuration because it changes frequently causing too many resource snapshots.</p>                                                                                                                             |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><p><strong>Azure Batch Account configured with overly permissive network access</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p></td><td><p>This policy identifies Batch Accounts configured with overly permissive network access. By default, Batch accounts are accessible from the all networks. With an Account access IP firewall, you can restrict it further to only a set of IPv4 addresses or IPv4 address ranges. With Private access Virtual Networks, the network traffic path is secured on both ends. It is recommended to configure the Batch account with an IP firewall or by Virtual Network, so that the Batch account is accessible only to restricted entities.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-batch-account' AND json.rule = properties.provisioningState equal ignore case Succeeded and properties.networkProfile.accountAccess.defaultAction equal ignore case Allow and properties.publicNetworkAccess equal ignore case Enabled
</code></pre></td></tr><tr><td><p><strong>Azure Storage Account storing Machine Learning workspace high business impact data is publicly accessible</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p></td><td><p>This policy identifies Azure Storage Accounts storing Machine Learning workspace high business impact data that are publicly accessible. Azure Storage account stores machine learning artifacts such as job logs. By default, this storage account is used when you upload data to the workspace. The attacker could exploit publicly accessible storage account to get machine learning workspace high business impact data logs and could breach in to the system by leveraging data exposed. It is recommended to restrict storage account access to only to the machine learning services as per business requirement.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-machine-learning-workspace' AND json.rule = 'properties.provisioningState equal ignore case Succeeded and properties.hbiWorkspace is true and properties.storageAccount exists' as X; config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = 'totalPublicContainers > 0 and (properties.allowBlobPublicAccess is true or properties.allowBlobPublicAccess does not exist)' as Y; filter '$.X.properties.storageAccount contains $.Y.id'; show Y;
</code></pre></td></tr><tr><td><p><strong>AWS account security contact information is not set</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p></td><td><p>This policy identifies the AWS account which has not set security contact information. Providing dedicated contact information for security specific, AWS can directly communicate security advisories to the team responsible for handling security-related issues. Failure to specify security contact info in AWS risks missing critical advisories, leading to delayed incident response and increased vulnerability exposure. It is recommended to set security contact information to receive notifications.</p><p><strong>Policy Severity—</strong> Information</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-account-management-alternate-contact' group by account as X; filter ' AlternateContactType is not member of ("SECURITY") ' ;
</code></pre></td></tr><tr><td><p><strong>Azure Cognitive Services account configured with local authentication</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p></td><td><p>This policy identifies Azure Cognitive Services accounts that are configured with local authentication methods instead of AD identity. Local authentication allows users to access the service using a local account and password, rather than an Azure Active Directory (Azure AD) account. Disabling local authentication methods improves security by ensuring that Cognitive Services accounts require Active Directory identities exclusively for authentication. It is recommended to disable local authentication methods on your Cognitive Services account, instead use Azure Active Directory identities.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-cognitive-services-account' AND json.rule = properties.provisioningState equal ignore case Succeeded and (properties.disableLocalAuth does not exist or properties.disableLocalAuth is false)
</code></pre></td></tr><tr><td><p><strong>Azure Machine learning workspace is not configured with private endpoint</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p></td><td><p>This policy identifies Azure Machine learning workspaces that are not configured with private endpoint. Private endpoints in workspace resources allow clients on a virtual network to securely access data over Azure Private Link. Configuring a private endpoint enables access to traffic coming from only known networks and prevents access from malicious or unknown IP addresses which includes IP addresses within Azure. It is recommended to create private endpoint for secure communication for your Machine learning workspaces.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-machine-learning-workspace' AND json.rule = properties.provisioningState equal ignore case Succeeded and (properties.privateEndpointConnections[*] does not exist or properties.privateEndpointConnections[*] is empty or (properties.privateEndpointConnections[*] exists and properties.privateEndpointConnections[*].properties.privateLinkServiceConnectionState.status does not equal ignore case Approved))
</code></pre></td></tr><tr><td><p><strong>AWS Systems Manager EC2 instance having NON_COMPLIANT patch compliance status</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p></td><td><p>This policy identifies if the AWS Systems Manager patch compliance status is "NON_COMPLIANT" with critical or high severity for managed instances. Instances labeled non-compliant might lack essential patches for security, stability, or meeting standards. Non-compliant instances pose security risks because attackers often target unpatched systems to exploit known weaknesses. As a security best practice, it’s recommended to apply any missing patches to the affected instances.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-ssm-resource-compliance-summary' AND json.rule = Status equals "NON_COMPLIANT" and ComplianceType contains "Patch" and ResourceType contains "ManagedInstance" and (NonCompliantSummary.SeveritySummary.CriticalCount greater than 0 or NonCompliantSummary.SeveritySummary.HighCount greater than 0)
</code></pre></td></tr><tr><td><p><strong>Azure Microsoft Defender for Cloud set to Off for Databases</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p></td><td><p>This policy identifies Azure Microsoft Defender for Cloud which has defender setting for Databases set to Off. Enabling Azure Defender for Cloud provides advanced security capabilities like threat intelligence, anomaly detection, and behaviour analytics. Defender for Databases in Microsoft Defender for Cloud allows you to protect your entire database estate with attack detection and threat response for the most popular database types in Azure. It is highly recommended to enable Azure Defender for Databases.</p><p><strong>Policy Severity—</strong> Information</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = pricings[?any((name equals SqlServers and properties.pricingTier does not equal Standard) or (name equals CosmosDbs and properties.pricingTier does not equal Standard) or (name equals OpenSourceRelationalDatabases and properties.pricingTier does not equal Standard) or (name equals SqlServerVirtualMachines and properties.pricingTier does not equal Standard))] exists
</code></pre></td></tr><tr><td><p><strong>Azure Microsoft Defender for Cloud set to Off for Open-Source Relational Databases</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p></td><td><p>This policy identifies Azure Microsoft Defender for Cloud which has defender setting for Open-Source Relational Databases set to Off. Enabling Azure Defender for cloud provides advanced security capabilities like threat intelligence, anomaly detection, and behaviour analytics. Microsoft Defender for Cloud detects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases. It is highly recommended to enable Azure Defender for Open-Source Relational Databases.</p><p><strong>Policy Severity—</strong> Information</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = pricings[?any(name equals OpenSourceRelationalDatabases and properties.pricingTier does not equal Standard)] exists
</code></pre></td></tr><tr><td><p><strong>Azure Microsoft Defender for Cloud set to Off for Cosmos DB</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p></td><td><p>This policy identifies Azure Microsoft Defender for Cloud which has defender setting for Cosmos DB set to Off. Enabling Azure Defender for the cloud provides advanced security capabilities like threat intelligence, anomaly detection, and behaviour analytics. Microsoft Defender for Azure Cosmos DB detects potential SQL injections, known bad actors based on Microsoft Threat Intelligence, suspicious access patterns, and potential exploitation of your database through compromised identities, or malicious insiders. It is highly recommended to enable Azure Defender for Cosmos DB.</p><p><strong>Policy Severity—</strong> Information</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = pricings[?any(name equals CosmosDbs and properties.pricingTier does not equal Standard)] exists
</code></pre></td></tr><tr><td><p><strong>New to Configuration Build Policies</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p></td><td><p>Starting with 23.12.1 196 new <strong>Config</strong> policies of subtype <strong>Build</strong> are added in GA on Prisma Cloud platform. See <a href="https://docs.prismacloud.io/en/enterprise-edition/policy-reference">Application Security Policy Reference Guide</a> for more details.</p><p>Here are the list of policies:</p><p><strong>Open API Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>Operation object uses 'password' flow in OAuth2 authentication</li><li>Security definitions uses basic auth</li><li>Operation Objects Uses Basic Auth</li><li>Global schemes use 'httpa' protocol instead of 'https'</li><li>API keys transmitted over cleartext</li><li>The path scheme is supports unencrypted HTTP connections</li><li>API spec includes a 'password' flow in OAuth2 authentication</li><li>Operation object uses 'password' flow in OAuth2 authentication</li></ul><p>The list of policies with <strong>Medium</strong> policy severity:</p><ul><li>Security definition uses the deprecated implicit flow on OAuth2</li><li>Operation Objects Uses 'Implicit' Flow</li><li>Operation objects for PUT, POST, and PATCH operations do not have a 'consumes' field defined</li><li>The global security scope is not defined in the securityDefinitions</li><li>Array does not have a maximum number of items</li><li>Security scopes of operations are not defined in securityDefinition</li></ul><p>The list of policies with <strong>Low</strong> policy severity:</p><ul><li>Operation objects do not have the 'produces' field defined for GET operations</li></ul><p><strong>AWS General Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>Comprehend Entity Recognizer’s model is not encrypted by KMS using a customer managed Key (CMK)</li><li>Comprehend Entity Recognizer’s volume is not encrypted by KMS using a customer managed Key (CMK)</li><li>The Connect Instance S3 Storage Configuration utilizes Customer Managed Key</li><li>DynamoDB table replica does not use CMK KMS encryption</li><li>AWS Lambda function is not configured to validate code-signing</li><li>MemoryDB snapshot is not encrypted by KMS using a customer managed Key (CMK)</li><li>Neptune snapshot is not securely encrypted</li><li>Neptune snapshot is encrypted by KMS using a customer managed Key (CMK)</li><li>RedShift snapshot copy is not encrypted by KMS using a customer managed Key (CMK)</li><li>Redshift Serverless namespace is not encrypted by KMS using a customer managed key (CMK)</li><li>DocDB Global Cluster is not encrypted at rest</li><li>DataSync Location Object Storage exposes secrets</li><li>DMS endpoint is not using a Customer Managed Key (CMK)</li><li>EventBridge Scheduler Schedule is not using a Customer Managed Key (CMK)</li><li>The DMS S3 does not use a Customer Managed Key (CMK)</li><li>Secrets Manager secrets are not rotated within 90 days</li><li>API Gateway method setting is not set to encrypted caching</li><li>CodeBuild S3 logs are not encrypted</li><li>Elastic Beanstalk environments do not have enhanced health reporting enabled</li><li>EFS Access Points are not enforcing a root directory</li><li>ECS containers are not limited to read-only access to root filesystems</li><li>SSM parameters are not utilizing KMS CMK</li><li>Elastic Beanstalk managed platform updates are not enabled</li><li>Amazon Redshift clusters do not have automatic snapshots enabled</li><li>Network firewalls do not have deletion protection enabled</li><li>Network firewall encryption does not use a CMK</li><li>Network Firewall Policy does not define an encryption configuration that uses a CMK</li><li>Neptune is not encrypted with KMS using a customer managed Key (CMK)</li><li>Security configuration of the EMR Cluster does not ensure the encryption of EBS disks</li><li>RDS Performance Insights are not encrypted using KMS CMKs</li><li>Transfer server does not force secure protocols.</li></ul><p>The list of policies with <strong>Medium</strong> policy severity:</p><ul><li>Connect Instance Kinesis Video Stream Storage Config is not using CMK for encryption</li><li>AWS database instances do not have deletion protection enabled</li><li>S3 lifecycle configuration does not set a period for aborting failed uploads</li><li>AWS RDS snapshots are accessible to public</li><li>AWS SSM documents are public</li><li>AWS CloudFront distributions does not have a default root object configured</li><li>CloudFront distributions do not have origin failover configured</li><li>EC2 Auto Scaling groups are not utilizing EC2 launch templates</li><li>AWS CodeBuild project environment privileged mode is enabled</li><li>Elasticsearch domains are not configured with a minimum of three dedicated master nodes</li><li>CloudWatch alarm actions are not enabled</li><li>Redshift clusters are not using the default database name</li><li>Redshift clusters are not using enhanced VPC routing</li><li>ElastiCache for Redis cache clusters do not have auto minor version upgrades enabled</li><li>RDS Aurora Clusters do not have backtracking enabled</li><li>User identity should be enforced by EFS access points</li><li>ECS Fargate services are not ensured to run on the latest Fargate platform version</li><li>AWS ECS task definition elevated privileges enabled</li><li>ECS task definitions have their own unique process namespace or share the host’s process namespace</li><li>AWS Auto Scaling group launch configuration configured with Instance Metadata Service hop count greater than 1</li><li>Backup retention period for DocDB is inadequate</li><li>Neptune DB cluster does not have automated backups enabled with adequate retention</li><li>Runtime of Lambda is deprecated</li></ul><p>The list of policies with <strong>Low</strong> policy severity:</p><ul><li>AWS API Gateway endpoints without client certificate authentication</li><li>AWS API gateway request parameter is not validated</li><li>AWS Secret Manager Automatic Key Rotation is not enabled</li><li>AWS Elasticsearch domain has Dedicated master set to disabled</li><li>AWS Lambda Function resource-based policy is overly permissive</li><li>RDS cluster is not configured to copy tags to snapshots</li><li>AWS Transit Gateway auto accept vpc attachment is enabled</li><li>WAF rule does not have any actions</li><li>AWS EMR cluster is not enabled with local disk encryption</li><li>AWS EMR cluster is not enabled with data encryption in transit</li><li>Clusters of Neptune DB do not replicate tags to snapshots</li></ul><p>The list of policies with <strong>Informational</strong> policy severity:</p><ul><li>AWS EMR cluster is not configured with security configuration</li><li>AWS Neptune cluster deletion protection is disabled</li><li>AWS RDS instance with copy tags to snapshots disabled</li><li>AWS CloudTrail logs are not encrypted using Customer Master Keys (CMKs)</li><li>AWS SageMaker notebook instance with root access enabled</li><li>AWS RDS DB cluster is encrypted using default KMS key instead of CMK</li></ul><p><strong>AWS IAM Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>The AWS Managed IAMFullAccess IAM policy should not be used</li><li>AWS AdministratorAccess policy is used by IAM roles, users, or groups</li><li>IAM policy uses the AWS AdministratorAccess policy</li><li>IAM Policy Document Allows All or Any AWS Principal Permissions to Resources</li><li>IAM policies allow privilege escalation</li><li>IAM policies allow exposure of credentials</li><li>IAM policies allow data exfiltration</li><li>IAM policies allow permissions management or resource exposure without constraints</li><li>IAM policies allow write access without constraints</li><li>AWS Access key enabled on root account</li><li>IAM policy document allows "*" as a resource for any action that can be restricted</li><li>Permissions delegated to AWS services for AWS Lambda functions are not limited by SourceArn or SourceAccount</li></ul><p>The list of policies with <strong>Medium</strong> policy severity:</p><ul><li>AWS IAM policy allows full administrative privileges</li><li>A Policy is not Defined for KMS Key</li><li>Authorization type for API GatewayV2 routes is not specified</li><li>AWS IAM policy allows full administrative privileges</li></ul><p>The list of policies with <strong>Low</strong> policy severity:</p><ul><li>AWS OpenSearch Fine-grained access control is disabled</li><li>Access is not controlled through Single Sign-On (SSO)</li><li>AWS Neptune Cluster not configured with IAM authentication</li></ul><p><strong>AWS Kubernetes Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>EKS clusters are not running on a supported Kubernetes version</li></ul><p><strong>AWS Logging Policies</strong></p><p>The list of policies with <strong>Medium</strong> policy severity:</p><ul><li>An S3 bucket must have a lifecycle configuration</li><li>Execution history logging is not enabled on the State Machine</li><li>Elasticsearch Domain Audit Logging is disabled</li><li>RDS Cluster log capture is disabled</li><li>CloudWatch log groups must retain logs for a minimum duration of one year</li></ul><p>The list of policies with <strong>Low</strong> policy severity:</p><ul><li>Domain Name System (DNS) query logging is not enabled for Amazon Route 53 hosted zones</li><li>S3 buckets do not have event notifications enabled</li><li>Network Firewall Logging Configuration is not Defined</li><li>Data Trace is not enabled in the API Gateway Method Settings</li><li>State machine does not have X-ray tracing enabled</li><li>CodeBuild project environments do not have a logging configuration</li><li>RDS Cluster audit logging for MySQL engine is disabled</li><li>AWS ECS services have automatic public IP address assignment enabled</li><li>RDS instances have performance insights disabled</li></ul><p><strong>AWS Networking Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>Domain Name System Security Extensions (DNSSEC) signing is not enabled for Amazon Route 53 public hosted zones</li><li>MSK nodes are not private</li><li>ALB is not configured with the defensive or strictest desync mitigation mode</li><li>NACL ingress allows all ports</li></ul><p>The list of policies with <strong>Medium</strong> policy severity:</p><ul><li>AWS CloudFront distribution is using insecure SSL protocols for HTTPS communication</li></ul><p>The list of policies with <strong>Low</strong> policy severity:</p><ul><li>ElastiCache cluster is using the default subnet group</li></ul><p>The list of policies with <strong>Informational</strong> policy severity:</p><ul><li>AWS SageMaker notebook instance is not placed in VPC</li></ul><p><strong>Azure General Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>Backend of the API management system does not utilize HTTPS</li><li>Event Hub Namespace not using TLS 1.2 or greater</li></ul><p>The list of policies with <strong>Medium</strong> policy severity:</p><ul><li>Azure Automation account configured with overly permissive network access</li><li>Azure PostgreSQL database flexible server configured with overly permissive network access</li><li>Azure ACR HTTPS not enabled for webhook</li><li>Azure Storage account is not configured with private endpoint connection</li><li>Azure Application gateways listener that allow connection requests over HTTP</li></ul><p>The list of policies with <strong>Low</strong> policy severity:</p><ul><li>Azure SQL database Transparent Data Encryption (TDE) encryption disabled</li><li>Azure Virtual Network subnet is not configured with a Network Security Group</li><li>Azure Key vault Private endpoint connection is not configured</li><li>Azure MariaDB database server not using latest TLS version</li><li>Azure Storage account soft delete is disabled</li><li>Azure Application Gateway is configured with SSL policy having TLS version 1.1 or lower</li></ul><p>The list of policies with <strong>Informational</strong> policy severity:</p><ul><li>Azure AKS cluster Azure CNI networking not enabled</li><li>Azure Container Instance not configured with the managed identity</li></ul><p><strong>Azure IAM Policies</strong></p><ul><li>Azure Storage account configured with Shared Key authorization</li><li>Azure Storage account not configured with SAS expiration policy</li></ul><p>The list of policies with <strong>Informational</strong> policy severity:</p><ul><li>Azure Recovery Services vault is not configured with managed identity</li><li>Azure Automation account is not configured with managed identity</li></ul><p><strong>Azure Kubernets Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>AKS cluster not encrypting temp disks, caches, and data flows</li><li>Non-Critical System Pods Run on System Nodes</li></ul><p>The policy with <strong>Medium</strong> policy severity:</p><ul><li>Operating system disks are not ephemeral disks</li></ul><p><strong>Azure Logging Policies</strong></p><p>The policy with <strong>Medium</strong> policy severity:</p><ul><li>Ledger feature is disabled on the database</li></ul><p><strong>Azure Networking Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>DenyIntelMode for Azure Firewalls is not set to Deny</li><li>Firewall policy does not have IDPS mode set to deny</li></ul><p>The list of policies with <strong>Medium</strong> policy severity:</p><ul><li>Azure Spring Cloud service is not configured with virtual network</li><li>Azure Firewall does not define a firewall policy</li></ul><p>The policy with <strong>Low</strong> policy severity:</p><ul><li>Azure Virtual machine configured with public IP and serial console access</li></ul><p>The list of policies with <strong>Informational</strong> policy severity:</p><ul><li>Azure SQL Server allow access to any Azure internal resources</li></ul><p><strong>Azure Storage Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>Azure SQL Database Namespace is not zone redundant</li><li>Standard Replication is not enabled</li></ul><p>The list of policies with <strong>Medium</strong> policy severity:</p><ul><li>App Service Plan is not zone redundant</li><li>Azure Event Hub Namespace is not zone redundant</li><li>App Service Environment is not zone redundant</li></ul><p><strong>Docker Policies</strong></p><p>The policy with <strong>Medium</strong> policy severity:</p><ul><li>'chpasswd' is used to set or remove passwords</li></ul><p><strong>Google Cloud General Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>Spanner Database does not have drop protection enabled</li><li>GCP Storage buckets has public access to all authenticated users</li></ul><p>The list of policies with <strong>Medium</strong> policy severity:</p><ul><li>GCP Cloud Function is publicly accessible</li><li>Deletion protection for Spanner Database is disabled</li><li>BigQuery tables do not have deletion protection enabled</li><li>Big Table Instances do not have deletion protection enabled</li></ul><p><strong>Google Cloud IAM Policies</strong></p><p>The list of policies with <strong>High</strong> policy severity:</p><ul><li>KMS policy allows public access</li><li>IAM policy defines public access</li><li>Basic roles utilized at the organization level</li><li>Project level utilization of basic roles</li><li>IAM workload identity pool provider is not restricted</li></ul><p>The policy with <strong>Medium</strong> policy severity:</p><ul><li>Basic roles used at the folder level</li></ul><p><strong>Google Cloud Kubernetes Policies</strong></p><p>The policy with <strong>Informational</strong> policy severity:</p><ul><li>GCP Kubernetes Engine Clusters have Alpha cluster feature enabled</li></ul><p><strong>Google Cloud Networking Policies</strong></p><p>The policy with <strong>Medium</strong> policy severity:</p><ul><li>Google Cloud Platform network is not ensured to define a firewall</li></ul><p><strong>Google Cloud Storage GCS Policies</strong></p><p>The policy with <strong>Low</strong> policy severity:</p><ul><li>Ensure MySQL DB instance has point-in-time recovery backup configured</li></ul><p><strong>Logging Policies</strong></p><p>The policy with <strong>Medium</strong> policy severity:</p><ul><li>SQL statements of GCP PostgreSQL are not logged</li></ul><p>The list of policies with <strong>Low</strong> policy severity:</p><ul><li>PostgreSQL database flag 'log_duration' is not set to 'on'</li><li>PostgreSQL database flag 'log_executor_stats' is not set to 'off'</li><li>PostgreSQL database flag 'log_parser_stats' is not set to 'off'</li><li>PostgreSQL database flag 'log_planner_stats' is not set to 'off'</li><li>PostgreSQL database flag 'log_statement_stats' is not set to 'off'</li><li>Log levels of the GCP PostgreSQL database are not set to ERROR or lower</li><li>pgAudit is disabled for your GCP PostgreSQL database</li></ul><p>The policy with <strong>Informational</strong> policy severity:</p><ul><li>GCP PostgreSQL instance database flag log_hostname is not set to off</li></ul><p><strong>OCI General Policies</strong></p><p>The policy with <strong>Medium</strong> policy severity:</p><ul><li>OCI File Storage File System access is not restricted to root users</li></ul><p>The list of policies with <strong>Low</strong> policy severity:</p><ul><li>OCI Kubernetes Engine Cluster boot volume is not configured with in-transit data encryption</li><li>OCI Kubernetes Engine Cluster pod security policy not enforced</li></ul><p><strong>OCI IAM Policies</strong></p><p>The policy with <strong>Medium</strong> policy severity:</p><ul><li>OCI tenancy administrator users are associated with API keys</li></ul><p><strong>OCI Networking Policies</strong></p><p>The list of policies with <strong>Informational</strong> policy severity:</p><ul><li>OCI Network Security Group allows all traffic on RDP port (3389)</li><li>OCI Kubernetes Engine Cluster endpoint is not configured with Network Security Groups</li></ul><p><strong>Impact-</strong> You will view policy violations for these policies on Prisma Cloud switcher <strong>Application Security > Projects</strong> in <strong>IaC Misconfigurations</strong> code category. Enforcement levels for IaC Misconfigurations will now be applied to pipelines with these findings. You may enable additional subscriptions on <strong>Application Security > Settings</strong> to view violations and alerts for these policies.</p></td></tr><tr><td><p><strong>AWS Log metric filter and alarm does not exist for AWS Organization changes</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p></td><td><p>Identifies the AWS regions that do not have a log metric filter and alarm for AWS Organizations changes. Monitoring changes to AWS Organizations will help to ensure any unwanted, accidental, or intentional modifications that may lead to unauthorized access or other security breaches within the AWS account. It is recommended that a metric filter and alarm be established for detecting changes to AWS Organization’s configurations.</p><p>This policy will trigger an alert if you have at least one Cloudtrail with the multi trial enabled, Logs all management events in your account, and is not set with a specific log metric filter and alarm.</p><p><strong>Policy Severity—</strong> Information</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-logs-describe-metric-filters' as X; config from cloud.resource where api.name = 'aws-cloudwatch-describe-alarms' as Y; config from cloud.resource where api.name = 'aws-cloudtrail-describe-trails' as Z; filter '(($.Z.cloudWatchLogsLogGroupArn is not empty and $.Z.cloudWatchLogsLogGroupArn contains $.X.logGroupName and $.Z.isMultiRegionTrail is true and $.Z.includeGlobalServiceEvents is true) and (($.X.filterPattern contains "eventName=" or $.X.filterPattern contains "eventName =") and ($.X.filterPattern does not contain "eventName!=" and $.X.filterPattern does not contain "eventName !=") and ($.X.filterPattern contains "eventSource=" or $.X.filterPattern contains "eventSource =") and ($.X.filterPattern does not contain "eventSource!=" and $.X.filterPattern does not contain "eventSource !=") and $.X.filterPattern contains organizations.amazonaws.com and $.X.filterPattern contains AcceptHandshake and $.X.filterPattern contains AttachPolicy and $.X.filterPattern contains CreateAccount and $.X.filterPattern contains CreateOrganizationalUnit and $.X.filterPattern contains CreatePolicy and $.X.filterPattern contains DeclineHandshake and $.X.filterPattern contains DeleteOrganization and $.X.filterPattern contains DeleteOrganizationalUnit and $.X.filterPattern contains DeletePolicy and $.X.filterPattern contains DetachPolicy and $.X.filterPattern contains DisablePolicyType and $.X.filterPattern contains EnablePolicyType and $.X.filterPattern contains InviteAccountToOrganization and $.X.filterPattern contains LeaveOrganization and $.X.filterPattern contains MoveAccount and $.X.filterPattern contains RemoveAccountFromOrganization and $.X.filterPattern contains UpdatePolicy and $.X.filterPattern contains UpdateOrganizationalUnit) and ($.X.metricTransformations[*] contains $.Y.metricName))'; show X; count(X) less than 1
</code></pre></td></tr><tr><td><p><strong>AWS Log metric filter and alarm does not exist for usage of root account</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p></td><td><p>identifies the AWS regions that do not have a log metric filter and alarm for usage of a root account. Monitoring for root account logins will provide visibility into the use of a fully privileged account and an opportunity to reduce its use it. Failure to monitor root account logins may result in a lack of visibility into unauthorized use or attempts to access the root account, posing potential security risks to your AWS environment. It is recommended that a metric filter and alarm be established for detecting changes to CloudTrail’s configurations.</p><p>This policy will trigger alert if you have at least one Cloudtrail with the multi trial is enabled, Logs all management events in your account and is not set with specific log metric filter and alarm.</p><p><strong>Policy Severity—</strong> Information</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-logs-describe-metric-filters' as X; config from cloud.resource where api.name = 'aws-cloudwatch-describe-alarms' as Y; config from cloud.resource where api.name = 'aws-cloudtrail-describe-trails' as Z; filter '(($.Z.cloudWatchLogsLogGroupArn is not empty and $.Z.cloudWatchLogsLogGroupArn contains $.X.logGroupName and $.Z.isMultiRegionTrail is true and $.Z.includeGlobalServiceEvents is true) and ($.X.filterPattern does not contain "userIdentity.type!=" or $.X.filterPattern does not contain "userIdentity.type !=") and ($.X.filterPattern contains "userIdentity.type =" or $.X.filterPattern contains "userIdentity.type=") and ($.X.filterPattern contains "userIdentity.invokedBy NOT EXISTS") and ($.X.filterPattern contains "eventType!=" or $.X.filterPattern contains "eventType !=") and ($.X.filterPattern contains root or $.X.filterPattern contains Root) and ($.X.filterPattern contains AwsServiceEvent) and ($.X.metricTransformations[*] contains $.Y.metricName))'; show X; count(X) less than 1
</code></pre></td></tr><tr><td><p><strong>AWS IAM AWSCloudShellFullAccess policy is attached to IAM roles, users, or IAM groups</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p></td><td><p>Identifies the AWSCloudShellFullAccess policy attached to IAM roles, users, or IAM groups. AWS CloudShell is a convenient way of running CLI commands against AWS services. The 'AWSCloudShellFullAccess' IAM policy, providing unrestricted CloudShell access, poses a risk of data exfiltration, allowing malicious admins to exploit file upload/download capabilities for unauthorized data transfer. As a security best practice, it is recommended to grant least privilege access like granting only the permissions required to perform a task, instead of providing excessive permissions.</p><p><strong>Policy Severity—</strong> Information</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-iam-get-policy-version' AND json.rule = isAttached is true and policyName contains AWSCloudShellFullAccess and (entities.policyRoles[*].roleName exists or entities.policyUsers[*].userName exists or entities.policyGroups[*].groupName exists)
</code></pre></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>GCP Cloud Armor policy not configured with cve-canary rule</strong></td><td><p><strong>Changes—</strong> The policy RQL will be updated to exclude checking edge security type of policy as pre-built rules (such as cve-canary) cannot be applied to edge security policy.</p><p><strong>Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-armor-security-policy' AND json.rule = rules[*].match.expr.expression does not contain cve-canary or rules[?any(match.expr.expression contains cve-canary and action equals allow)] exists
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-armor-security-policy' AND json.rule = type does not equal ignore case CLOUD_ARMOR_EDGE and (rules[*].match.expr.expression does not contain cve-canary or rules[?any(match.expr.expression contains cve-canary and action equals allow)] exists)
</code></pre><p><strong>Impact—</strong> Low. Existing alerts will be resolved as <code>CLOUD_ARMOR_EDGE</code> type policies are excluded from the policy RQL.</p></td></tr><tr><td><strong>MWAA environment is publicly accessible</strong></td><td><p><strong>Changes—</strong> The policy is deleted from the Prisma Cloud platform.</p><p><strong>Severity—</strong> High</p><p><strong>Policy Type—</strong> Config Build</p><p><strong>Impact—</strong> You will no longer receive alerts.</p></td></tr></tbody></table>

## IPs for Runtime Security

tt:\[Update] **IP Addresses for Runtime Security**

tt:\[The change to add IPs was first announced in the 23.11.1 look ahead notice is no longer needed.]

Prisma Cloud has determined that since the Runtime Security console will not be migrating to AWS, there is no need to include the following IP addresses in your allowlist. You can now safely remove any related IP addresses you have previously added to your allowlist.

| **Prisma Cloud UI**                                   | **Ingress IPs**                                | **Egress IPs**                                |
| ----------------------------------------------------- | ---------------------------------------------- | --------------------------------------------- |
| app.prismacloud.io us-east-1 (N.Virginia)             | 3.232.212.150, 52.206.194.243, 54.205.93.245   | 34.232.99.40, 18.211.176.92, 54.243,170.105   |
| app2.prismacloud.io us-east-2 (Ohio)                  | 3.132.133.211, 3.134.159.143, 3.132.102.175    | 3.20.245.229, 18.117.2.10, 3.12.88.219        |
| app3.prismacloud.io us-west-2 (Oregon)                | 54.71.138.233, 44.225.112.87, 100.22.20.223    | 34.212.152.80, 35.81.57.244, 35.164.11.119    |
| app4.prismacloud.io us-west-1 (N.California)          | 52.8.150.142, 13.57.149.63, 52.53.102.128      | 52.8.254.103, 52.8.144.90, 52.52.105.247      |
| app.anz.prismacloud.io ap-southeast-2 (Sydney)        | 54.66.57.155, 3.24.19.111, 3.105.89.234        | 13.54.220.198, 52.65.26.161, 3.106.34.89      |
| app.ca.prismacloud.io ca-central-1 (Canada - Central) | 35.182.172.138, 35.183.159.40, 15.157.80.131   | 15.156.171.28, 3.98.195.69, 52.60.214.101     |
| app.ind.prismacloud.io ( ap-south-1 )                 | 13.127.110.199, 35.154.181.205, 15.206.220.174 | 65.0.38.58, 43.205.12.179, 13.200.1.224       |
| app.sg.prismacloud.io ap-southeast-1 (Singapore)      | 13.250.243.220, 54.251.192.140, 13.214.62.192  | 52.220.86.241, 18.139.216.124, 13.215.145.83  |
| app.jp.prismacloud.io ap-northeast-1 (Tokyo)          | 52.192.243.41, 57.180.105.24, 52.195.58.106    | 54.178.53.44, 57.180.197.75, 35.79.153.213    |
| app.eu.prismacloud.io eu-central-1 (Frankfurt)        | 3.68.165.169, 18.153.181.13, 3.126.32.183      | 18.192.34.49, 3.66.3.228, 18.153.176.170      |
| app2.eu.prismacloud.io eu-west-1 (Ireland)            | 52.49.29.166, 52.18.47.237, 52.212.198.8       | 54.220.240.134, 34.247.157.43, 34.255.175.135 |
| app.uk.prismacloud.io eu-west2 (London)               | 13.42.228.98, 18.135.233.1, 13.43.203.118      | 18.133.199.52, 3.10.115.247, 18.168.167.81    |
| app.fr.prismacloud.io eu-west-3 (Paris)               | 13.36.213.67, 13.36.106.162, 13.39.97.70       | 15.237.224.167, 13.36.133.84, 13.36.226.57    |

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                                                                                                                           | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>New policy mappings for Azure CIS</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p>                              | <p>The following compliance requirements in Azure CIS 1.5 Level 1, Azure CIS 1.5 Level 2 and Azure CIS v2.0.0 Level 2 are updated with new mappings.</p><ul><li>Azure CIS 1.5 Level 1 - Database Services, Microsoft Defender, Storage Accounts</li><li>Azure CIS 1.5 Level 2 - Database Services, Microsoft Defender</li><li>Azure CIS 2.0 Level 2 - Microsoft Defender, Storage Accounts</li></ul><p><strong>Impact-</strong> As new mappings are introduced, compliance scoring might vary.</p> |
| <p><strong>Risk Management in Technology includes mappings to support GCP</strong></p><p><mark style="background-color:orange;"><strong>24.2.2</strong></mark></p> | <p>Google Cloud Platform support is added for the Risk Management in Technology(RMiT) compliance standard.</p><p><strong>Impact-</strong> As new mappings are introduced, compliance scoring might vary.</p>                                                                                                                                                                                                                                                                                       |

## REST API Updates

| **Change**                                                                                                                                                                                                   | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>New incident policies based on traffic observation</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">24.2.2</mark></p> | <p>This update adds two new policies that alert you to traffic that includes:</p><ul><li>Sensitive data sent through an API endpoint that is exposed to the internet without authentication.</li><li>Sensitive data sent through an API endpoint that is exposed to the internet without encryption.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Split Vulnerability and Compliance CSV</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">24.2.2</mark></p>             | <p>The following APIs include a new parameter, <code>issueType</code>:</p><ul><li><a href="https://pan.dev/compute/api/get-hosts-download/">Download Host Scan Results</a></li><li><a href="https://pan.dev/compute/api/get-images-download/">Download Image Scan Results</a></li><li><a href="https://pan.dev/compute/api/get-registry-download/">Download Registry Scan Results</a></li><li><a href="https://pan.dev/compute/api/get-scans-download/">Download CI Image Scan Results</a></li><li><a href="https://pan.dev/compute/api/get-vms-download/">Download VM Image Scan Results</a></li><li><a href="https://pan.dev/compute/api/get-serverless-download/">Download Serverless Function Scan Results</a></li></ul><p>The <code>issueType</code> parameter can be set to <code>vulnerabilities</code> or <code>compliance</code> for downloading vulnerability or compliance issues respectively. If either value is not provided, both vulnerability and compliance issues are downloaded.</p> |
| <p><strong>Just-In-Time (JIT) Support</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                                               | <p>The following Single Sign-On (SSO) endpoints now support Just-In-Time (JIT) user provisioning:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-oauth-2-config/">Get OIDC Configuration</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/update-oauth-2-config/">Update OIDC Configuration</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/create-oauth-2-config/">Create an OIDC Configuration</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/patch-oauth-2-config/">Update OIDC Configuration Partially</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Enterprise Settings APIs</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                                                 | <p>The following APIs have a new boolean field <code>autoEnableAttackPathAndModulePolicies</code> with <code>false</code> as default.</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-enterprise-settings/">GET Enterprise Settings</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/update-enterprise-settings/">POST Enterprise settings</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Unified Vulnerability Explorer</strong></p><p><mark style="background-color:orange;"><strong>24.2.1</strong></mark></p>                                                                           | <p>The following new endpoints are now available to get details from the vulnerabilities dashboard:</p><ul><li><code>Get Vulnerability Overview V2</code> - <a href="https://pan.dev/prisma-cloud/api/cspm/vulnerability-dashboard-overview-v-2/">GET uve/api/v2/dashboard/vulnerabilities/overview</a></li><li><code>Get Vulnerabilities Burndown</code> - <a href="https://pan.dev/prisma-cloud/api/cspm/get-burndown/">GET uve/api/v2/dashboard/vulnerabilities/burndown</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-february-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
