> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-january-2024.md).

# Features Introduced in January 2024

Learn what’s new on Prisma® Cloud in January 2024.

* [Announcement](#announcement)
* [New Features](#new-features)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [Policy Updates - IAM](#policy-updates-iam)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)
* [Deprecation Notices](#deprecation-notices)

## Announcement

| **Feature**                     | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Prisma Cloud Darwin Release** | <p>The <strong>Prisma Cloud Darwin Release</strong> is now available for all Prisma Cloud environments except app.cn and app.gov. With the Code to Cloud™ intelligence capabilities in this release, your security and development teams can work together to reduce application risks and prevent breaches.</p><p>With this change, your tenant will be updated with the new intuitive user interface and <a href="https://live.paloaltonetworks.com/t5/prisma-cloud-customer-videos/prisma-cloud-evolution-amp-transformation/ta-p/556596">rich set of security capabilities</a>. When you are upgraded to the Darwin release, refer to the <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/">Enterprise Edition documentation</a>.</p><p>Contact your Prisma Cloud Customer Success team for more details.</p> |

## New Features

| **Feature**                                                                                                                                                                                                                                                                     | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Compliance Dashboard</strong></p><p><mark style="background-color:orange;"><strong>Secure the Infrastructure</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                         | <p>Prisma Cloud’s out of the box dashboards now include a <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/dashboards-compliance">Compliance</a> dashboard. Select <strong>Home > Dashboards > Compliance</strong> to view a snapshot of assets and their compliance status, compliance trends over time, and top compliance policies by failed status.</p><p><img src="/files/3iwsIPCspeIPXDca1WHp" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><mark style="background-color:orange;">Update</mark> <strong>Code to Cloud Dashboard</strong></p><p><mark style="background-color:orange;"><strong>Secure the Infrastructure</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p> | Prisma Cloud’s Latest Events tracker now provides redirections on the events from all phases of the Code Build Deploy Run (CBDR) cloud deployment lifecycle. Select any event from **Home > Dashboards > Code to Cloud > Latest Events** to immediately take action and investigate the risk or incident. Learn more about optimizing Prisma Cloud [Dashboards](https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/dashboards-code-to-cloud).                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><mark style="background-color:orange;">Update</mark> <strong>Code to Cloud Dashboard</strong></p><p><mark style="background-color:orange;"><strong>Secure the Infrastructure</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p> | <p>Prisma Cloud’s <strong>Dashboards > Add Dashboard > Widget Selector</strong> now includes two additional widgets to help you easily report on your organization’s efficiency in responding to alerts. Widgets are currently available to System Administrators and include:</p><ul><li>Alerts by MTTR - Displays alerts by severity and their mean time to resolution.</li><li>Alert by Resolution Reason - Displays the resolved alerts by their method of resolution.</li></ul><p>Learn more about leveraging these widgets to <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/create-and-manage-dashboards">create</a> your own custom dashboards.</p>                                                                                                                                                                            |
| <p><strong>Send Ad hoc Alert Notifications to Email and Slack</strong></p><p><mark style="background-color:orange;"><strong>Secure the Infrastructure</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                           | <p>In addition to sending ad hoc Alert notifications to your Jira integration, now you can also <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/alerts/view-respond-to-prisma-cloud-alerts">send a notification</a> to <strong>Email</strong> and <strong>Slack</strong> for any open alert. From <strong>Alerts > Overview</strong>, select an Alert ID link to view the details. From the <strong>Send To</strong> dropdown, select <strong>Email</strong> or <strong>Slack</strong> to send the notification.</p><p><img src="/files/1rGtBejChR6OxOoUrDtn" alt="" data-size="original"></p><p>Selecting <strong>View Alert</strong> from the Email received or the Slack channel will directly open the Alert Overview (for all Policies, except Attack Path) or the Evidence Graph (for Attack Path policies) in the Prisma Cloud console.</p> |
| <p><strong>Unique Counts on the Prioritized Funnel</strong></p><p><mark style="background-color:orange;"><strong>Secure the Runtime</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                             | In Vulnerability Management, the Prioritized Funnel widget now displays the unique CVE count instead of the total number of CVE occurrences.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>Dashboard Widgets</strong></p><p><mark style="background-color:orange;"><strong>Secure the Infrastructure</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                            | <p>Prisma Cloud’s <strong>Dashboards > Add Dashboard > Widget Selector</strong> now includes eight additional <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/get-started/adoption-advisor#id0356c4cc-e4f1-43e2-8848-3f6cd7e4cd60">widgets</a> to help you create <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/create-and-manage-dashboards">customized dashboards</a> to track your organization’s key metrics. Widgets include:</p><ul><li>Adoption Progress</li><li>Assets with Urgent Alerts</li><li>Anomalous Threats Detected</li><li>Top Custom Alerts Generated</li><li>Discovered vs. Secured Resources</li><li>Vulnerabilities Trend by Resource Type</li><li>Risks Burndown</li><li>Incidents Burndown</li></ul>                                                                           |
| <p><strong>Terraform Module Scanning</strong></p><p><mark style="background-color:orange;"><strong>Secure the Source</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                            | Prisma Cloud now supports rendering and scanning public, private, and locally cached Terraform modules. This capability enables you to analyze misconfigurations that may result from the module definition and the variables defined in the resource block. For more information, see [Terraform Module Scanning](https://docs.prismacloud.io/en/enterprise-edition/content-collections/application-security/risk-management/monitor-and-manage-code-build/terraform-module-scan).                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Agentless Scanning</strong></p><p><mark style="background-color:orange;"><strong>Secure the Runtime</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                                  | Added agentless scanning support of encrypted volumes in Azure for the hub account mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Agentless Scanning</strong></p><p><mark style="background-color:orange;"><strong>Secure the Runtime</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                                  | Added agentless scanning hub account mode for Azure.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Vulnerability Management</strong></p><p><mark style="background-color:orange;"><strong>Secure the Runtime</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                            | Added support for Debian Bullseye and Bookworm Security fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>Operating System Support</strong></p><p><mark style="background-color:orange;"><strong>Secure the Runtime</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                            | Added support for OpenShift 4.14.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Vulnerability Management</strong></p><p><mark style="background-color:orange;"><strong>Secure the Runtime</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                            | From 32.01, support is added to detect the Java version number when IBM Java is used during vulnerability management. This enhancement covers IBM Java version 1.8 and earlier. For IBM Java version 1.9 and later, support is partial and depends on the presence of the `jdk/release` file.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |

## API Ingestions

| **Service**                                                                                                                                                                        | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Azure Cache</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                                    | <p><strong>azure-cache-redis-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Cache/redis/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Google Cloud VMware Engine</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                     | <p><strong>gcloud-vmware-engine-private-cloud</strong></p><p>Additional permissions required:</p><ul><li><code>vmwareengine.locations.list</code></li><li><code>vmwareengine.privateClouds.list</code></li><li><code>vmwareengine.privateClouds.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Google Cloud VMware Engine</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                     | <p><strong>gcloud-vmware-engine-cluster</strong></p><p>Additional permissions required:</p><ul><li><code>vmwareengine.locations.list</code></li><li><code>vmwareengine.privateClouds.list</code></li><li><code>vmwareengine.clusters.list</code></li><li><code>vmwareengine.clusters.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Google Cloud VMware Engine</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                     | <p><strong>gcloud-vmware-engine-hcx-activation-key</strong></p><p>Additional permissions required:</p><ul><li><code>vmwareengine.locations.list</code></li><li><code>vmwareengine.privateClouds.list</code></li><li><code>vmwareengine.hcxActivationKeys.list</code></li><li><code>vmwareengine.hcxActivationKeys.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Google Cloud VMware Engine</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                     | <p><strong>gcloud-vmware-engine-subnet</strong></p><p>Additional permissions required:</p><ul><li><code>vmwareengine.locations.list</code></li><li><code>vmwareengine.privateClouds.list</code></li><li><code>vmwareengine.subnets.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                    | <p><strong>gcloud-vertex-ai-aiplatform-custom-job</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.customJobs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                    | <p><strong>gcloud-vertex-ai-aiplatform-endpoint</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.endpoints.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                    | <p><strong>gcloud-vertex-ai-aiplatform-training-pipeline</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.trainingPipelines.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                    | <p><strong>gcloud-vertex-ai-aiplatform-pipeline-job</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.pipelineJobs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Google Speech to text</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                          | <p><strong>gcloud-speech-projects-locations-phraseSets-list</strong></p><p>Additional permission required:</p><ul><li><code>speech.phraseSets.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Google Speech to text</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                          | <p><strong>gcloud-speech-projects-locations-customClasses-list</strong></p><p>Additional permission required:</p><ul><li><code>speech.customClasses.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>Google Cloud Composer</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                          | <p><strong>gcloud-composer-projects-locations-imageVersions-list</strong></p><p>Additional permission required:</p><ul><li><code>composer.imageversions.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Google Data Migration</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                          | <p><strong>gcloud-datamigration-projects-locations-privateConnections-list</strong></p><p>Additional permissions required:</p><ul><li><code>datamigration.privateconnections.list</code></li><li><code>datamigration.privateconnections.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>Google Data Migration</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                          | <p><strong>gcloud-datamigration-projects-locations-connectionProfiles-list</strong></p><p>Additional permissions required:</p><ul><li><code>datamigration.connectionprofiles.list</code></li><li><code>datamigration.connectionprofiles.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>Google Data Migration</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                          | <p><strong>gcloud-datamigration-projects-locations-conversionWorkspaces-list</strong></p><p>Additional permissions required:</p><ul><li><code>datamigration.conversionworkspaces.list</code></li><li><code>datamigration.conversionworkspaces.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>Google Data Migration</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                          | <p><strong>gcloud-datamigration-projects-locations-migrationJobs-list</strong></p><p>Additional permissions required:</p><ul><li><code>datamigration.migrationjobs.list</code></li><li><code>datamigration.migrationjobs.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| <p><mark style="background-color:orange;">Update</mark> <strong>Google Deployment Manager</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p> | <p><strong>gcloud-deployment-manager-deployment-manifest</strong></p><p>Prisma Cloud will update the <code>Resource Name</code> and <code>Asset ID</code> fields in the backend for <code>gcloud-deployment-manager-deployment-manifest</code> API. Due to this change, when you perform an RQL search query, you will be able to see a change in the <code>Resource Name</code> and <code>Asset ID</code> fields making it easier for you to identify the resources. Also, all the existing resources will be deleted, and then regenerated on the management console.</p><p>Existing alerts corresponding to this resource will be resolved as <code>Resource\_Deleted</code>, and new alerts will be generated against any policy violations.</p><p><strong>Impact—</strong> None. Once the resources for <code>gcloud-deployment-manager-deployment-manifest</code> resume ingesting data, you will notice the correct alert count in the console.</p> |
| <p><mark style="background-color:orange;">Update</mark> <strong>Google Cloud SQL</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>          | <p><strong>gcloud-sql-instances-list</strong></p><p>Prisma Cloud has updated the <code>gcloud-sql-instances-list</code> API to exclude the <code>settings.settingsVersion</code> field from the JSON response because it changes frequently and does not add much value to the response.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>OCI Service Catalog</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                            | <p><strong>oci-servicecatalog-catalog</strong></p><p>Additional permissions required:</p><ul><li><code>SERVICE\_CATALOG\_INSPECT</code></li><li><code>SERVICE\_CATALOG\_READ</code></li></ul><p>You must update the Terraform template to enable the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><mark style="background-color:orange;">Update</mark> <strong>OCI Data Safe</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>             | <p><strong>oci-data-safe-target-database</strong></p><p>The resource JSON for this API no longer includes the <code>timeUpdated</code> field.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><mark style="background-color:orange;">Update</mark> <strong>OCI Database</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>              | <p><strong>oci-database-autonomous-database</strong></p><p>The resource JSON for this API no longer includes the <code>actualUsedDataStorageSizeInTBs</code> field.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><mark style="background-color:orange;">Update</mark> <strong>OCI MySQL</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                 | <p><strong>oci-mysql-dbsystems</strong></p><p>The resource JSON for this API no longer includes the <code>timeUpdated</code> field.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><p><strong>Azure Cognitive Services account not configured with private endpoint</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p></td><td><p>Identifies Azure Cognitive Services accounts that are not configured with private endpoint. Private endpoints in Azure AI service resources allow clients on a virtual network to securely access data over Azure Private Link. Configuring a private endpoint enables access to traffic coming from only known networks and prevents access from malicious or unknown IP addresses which includes IP addresses within Azure. It is recommended to create private endpoint for secure communication for your Cognitive Services account.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-cognitive-services-account' AND json.rule = properties.provisioningState equal ignore case Succeeded and properties.privateEndpointConnections[*] is empty
</code></pre></td></tr><tr><td><p><strong>Azure Cognitive Services account is not configured with managed identity</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p></td><td><p>Identifies Azure Cognitive Services accounts that are not configured with managed identity. Managed identity can be used to authenticate to any service that supports Azure AD authentication, without having credentials in your code. Storing credentials in a code increases the threat surface in case of exploitation and also managed identities eliminate the need for developers to manage credentials. So as a security best practice, it is recommended to have the managed identity to your Cognitive Services account.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-cognitive-services-account' AND json.rule = properties.provisioningState equal ignore case Succeeded and (identity.type does not exist or identity.type equal ignore case None)
</code></pre></td></tr><tr><td><p><strong>Azure Cognitive Services account configured with public network access</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p></td><td><p>Identifies Azure Cognitive Services accounts configured with public network access. Overly permissive public network access allows access to resource through the internet using a public IP address. It is recommended to restrict IP ranges to allow access to your cognitive Services account and endpoint from specific public internet IP address ranges and is accessible only to restricted entities.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-cognitive-services-account' AND json.rule = properties.provisioningState equal ignore case Succeeded and properties.publicNetworkAccess equal ignore case Enabled and (properties.networkAcls.defaultAction does not exist or properties.networkAcls.defaultAction equal ignore case Allow)
</code></pre></td></tr><tr><td><strong>Attack Path Policies</strong></td><td>New Attack Path policies are available. Log in to the Prisma Cloud console and filter for the list of available policies.</td></tr><tr><td><p><strong>AWS S3 bucket encrypted using Customer Managed Key (CMK) with overly permissive policy</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p>Identifies Amazon S3 buckets that use Customer Managed Keys (CMKs) for encryption that have a key policy overly permissive. Amazon S3 bucket encryption key overly permissive can result in the exposure of sensitive data and potential compliance violations. As a security best practice, It is recommended to follow the principle of least privilege ensuring that the KMS key policy does not have all the permissions to be able to complete a malicious action.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name= 'aws-s3api-get-bucket-acl' AND json.rule = (sseAlgorithm contains "aws:kms" or sseAlgorithm contains "aws:kms:dsse") and kmsMasterKeyID exists as X; config from cloud.resource where api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.keyState equals Enabled and keyMetadata.keyManager equals CUSTOMER and policies.default.Statement[?any((Principal.AWS equals * or Principal equals *)and Condition does not exist)] exists as Y; filter '$.X.kmsMasterKeyID contains $.Y.key.keyArn' ; show X;
</code></pre></td></tr><tr><td><p><strong>AWS S3 bucket encrypted with Customer Managed Key (CMK) is not enabled for regular rotation</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p>Identifies Amazon S3 buckets that use Customer Managed Keys (CMKs) for encryption but are not enabled with key rotation. Amazon S3 bucket encryption key rotation failure can result in prolonged exposure of sensitive data and potential compliance violations. As a security best practice, it is important to rotate these keys periodically. This ensures that if the keys are compromised, the data in the underlying service remains secure with the new keys.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name= 'aws-s3api-get-bucket-acl' AND json.rule = (sseAlgorithm contains "aws:kms" or sseAlgorithm contains "aws:kms:dsse") and kmsMasterKeyID exists as X; config from cloud.resource where api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.keyState equals Enabled and keyMetadata.keyManager equal ignore case CUSTOMER and keyMetadata.origin equals AWS_KMS and (rotation_status.keyRotationEnabled is false or rotation_status.keyRotationEnabled equals "null")as Y; filter '$.X.kmsMasterKeyID contains $.Y.key.keyArn'; show X;
</code></pre></td></tr><tr><td><p><strong>AWS RDS database instance encrypted with Customer Managed Key (CMK) is not enabled for regular rotation</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p>Identifies Amazon RDS instances that use Customer Managed Keys (CMKs) for encryption but are not enabled with key rotation. Amazon RDS instance encryption key rotation failure can result in prolonged exposure of sensitive data and potential compliance violations. As a security best practice, it is important to periodically rotate these keys. This ensures that if the keys are compromised, the data in the underlying service remains secure with the new keys.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-rds-describe-db-instances' and json.rule = storageEncrypted is true as X; config from cloud.resource where api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.keyState equals Enabled and keyMetadata.keyManager equals CUSTOMER and keyMetadata.origin equals AWS_KMS and (rotation_status.keyRotationEnabled is false or rotation_status.keyRotationEnabled equals "null") as Y; filter '($.X.kmsKeyId equals $.Y.key.keyArn)'; show X;
</code></pre></td></tr><tr><td><p><strong>Azure Storage account encrypted by an encryption key configured access policy with privileged operations</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p>Identifies Azure Storage accounts which are encrypted by an encryption key configured access policy with privileged operations. Encryption keys should be kept confidential and only accessible to authorized entity with limited operation access. Allowing privileged access to an encryption key also allows to alter/delete the data that is encrypted by it, making the data more easily accessible. It is recommended to have restricted access policies to an encryption key so that only authorized entities can access it with limited operation access.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.encryption.keySource equal ignore case "Microsoft.Keyvault" as X; config from cloud.resource where api.name = 'azure-key-vault-list' and json.rule = properties.accessPolicies[*].permissions exists and (properties.accessPolicies[*].permissions.keys[*] intersects ('Decrypt', 'Encrypt', 'Release', 'Purge', 'all') or properties.accessPolicies[*].permissions.secrets[*] intersects ('Purge', 'all') or properties.accessPolicies[*].permissions.certificates[*] intersects ('Purge', 'all')) as Y; filter '$.Y.properties.vaultUri contains $.X.properties.encryption.keyvaultproperties.keyvaulturi'; show X;
</code></pre></td></tr><tr><td><p><strong>Azure Storage account encrypted by an encryption key that is not rotated regularly</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p>Identifies Azure Storage accounts which are encrypted by an encryption key that is not rotated regularly. As a security best practice, it is important to rotate the keys periodically so that if the keys are compromised, the data in the underlying service is still secure with the new keys.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.encryption.keySource equal ignore case "Microsoft.Keyvault" as X; config from cloud.resource where api.name = 'azure-key-vault-list' and json.rule = keys[?any(attributes.exp equals -1 and attributes.enabled contains true)] exists as Y; filter '$.Y.properties.vaultUri contains $.X.properties.encryption.keyvaultproperties.keyvaulturi'; show X;
</code></pre></td></tr><tr><td><p><strong>Azure AKS cluster configured with overly permissive API server access</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p>Identifies AKS clusters configured with overly permissive API server access. In Kubernetes, the API server receives requests to perform actions in the cluster such as to create resources or scale the number of nodes. To enhance cluster security and minimize attacks, the API server should only be accessible from a limited set of IP address ranges. These IP ranges allow defined IP address ranges to communicate with the API server. A request made to the API server from an IP address that is not part of these authorized IP ranges is blocked. It is recommended to configure AKS cluster with defined IP address ranges to communicate with the API server.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-kubernetes-cluster' AND json.rule = properties.powerState.code equal ignore case Running and properties.apiServerAccessProfile.enablePrivateCluster is false and (properties.apiServerAccessProfile.authorizedIPRanges does not exist or properties.apiServerAccessProfile.authorizedIPRanges is empty)
</code></pre></td></tr><tr><td><p><strong>Azure Machine learning workspace configured with overly permissive network access</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p>Identifies Machine learning workspaces configured with overly permissive network access. Overly permissive public network access allows access to resource through the internet using a public IP address. It is recommended to restrict IP ranges to allow access to your workspace and endpoint from specific public internet IP address ranges and is accessible only to restricted entities.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-machine-learning-workspace' AND json.rule = properties.provisioningState equal ignore case Succeeded and properties.publicNetworkAccess equal ignore case Enabled and (properties.ipAllowlist does not exist or properties.ipAllowlist is empty)
</code></pre></td></tr><tr><td><p><strong>New CI/CD Configuration Build Policies</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p>Added the following default CI/CD policies within the <strong>Build</strong> subtype of <strong>Configuration</strong> policies under <strong>Governance</strong> for enhanced continuous integration and deployment pipeline security.</p><p><strong>Azure Repo Policies</strong></p><ul><li>Potential dependency confusion in an Azure Repos repository due to package name or scope available in registry</li><li>Deprecated package used in NPM project of an Azure Repos repository</li><li>Missing ‘.npmrc’ file in Azure Repos repository</li><li>Possible Python typosquatting detected in an Azure Repos repository</li><li>Secret exposed in registry URL within ‘.npmrc’ file of an Azure Repos repository</li><li>Unencrypted channel used by ‘.npmrc’ file of an Azure Repos repository to download dependencies from proxy</li><li>Azure Pipelines uses an unpinned container image</li><li>Secret exposed in proxy URL within ‘.npmrc’ file of an Azure Repos repository</li><li>Deprecated package used in NPM project of a Bitbucket repository</li></ul><p><strong>Bitbucket Policies</strong></p><ul><li>Missing ‘.npmrc’ file in Bitbucket repository</li><li>Possible Python typosquatting detected in a Bitbucket repository</li><li>Potential dependency confusion in a Bitbucket repository due to package name or scope available in registry</li><li>Private Bitbucket repository made public</li><li>Secret exposed in proxy URL within ‘.npmrc’ file of a Bitbucket repository</li><li>Secret exposed in registry URL within ‘.npmrc’ file of a Bitbucket repository</li><li>Unencrypted channel used by ‘.npmrc’ file of a Bitbucket repository to download dependencies from proxy</li><li>Unencrypted channel used by ‘.npmrc’ file of a Bitbucket repository to download dependencies from registry</li></ul><p><strong>CircleCI Policies</strong></p><ul><li>CircleCI pipeline uses an unpinned container image</li></ul><p><strong>GitHub Policies</strong></p><ul><li>Deprecated package used in NPM project of a GitHub repository</li><li>Missing ‘.npmrc’ file in GitHub repository</li><li>Possible Python typosquatting detected in a GitHub repository</li><li>Potential dependency confusion in a GitHub repository due to package name or scope available in registry</li><li>Secret exposed in proxy URL within ‘.npmrc’ file of a GitHub repository</li><li>Secret exposed in registry URL within ‘.npmrc’ file of a GitHub repository</li><li>Unencrypted channel used by ‘.npmrc’ file of a GitHub repository to download dependencies from proxy</li><li>Unencrypted channel used by ‘.npmrc’ file of a GitHub repository to download dependencies from registry</li><li>Unrotated organization secrets in GitHub Actions</li><li>Unrotated repository secrets in GitHub Actions</li></ul><p><strong>GitLab Policies</strong></p><ul><li>Deprecated package used in NPM project of a GitLab repository</li><li>Missing ‘.npmrc’ file in GitLab repository</li><li>Possible Python typosquatting detected in a GitLab repository</li><li>Potential dependency confusion in a GitLab repository due to package name or scope available in registry</li><li>Secrets found in logs of a GitLab CI pipeline</li><li>Secret exposed in proxy URL within ‘.npmrc’ file of a GitLab repository</li><li>Secret exposed in registry URL within ‘.npmrc’ file of a GitLab repository</li><li>Unencrypted channel used by ‘.npmrc’ file of a GitLab repository to download dependencies from proxy</li><li>Unencrypted channel used by ‘.npmrc’ file of a GitLab repository to download dependencies from registry</li></ul></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><p><strong>Azure Function App authentication is off</strong></p><p><mark style="background-color:orange;">24.1.2</mark></p></td><td><p><strong>Changes—</strong> The policy RQL is updated to only report Function Apps for which authentication is disabled. Azure Function App Authentication prevents anonymous HTTP requests from reaching the API app or authenticates token-enabled requests before they reach the API app, but not the Logic app or Web App resources created in Azure.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case Running and kind contains functionapp and config.siteAuthEnabled is false
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case Running and kind contains functionapp and kind does not contain workflowapp and kind does not equal app and config.siteAuthEnabled is false
</code></pre><p><strong>Impact—</strong> Low. Existing alerts generated for Logic App and Web App will be resolved and new alerts will be generated.</p></td></tr><tr><td><p><strong>AWS Elasticsearch domain publicly accessible</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL is updated to check for <code>vpc-options</code> instead of <code>vpc.endpoints</code>.</p><p><strong>Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-es-describe-elasticsearch-domain' AND json.rule = processing is false and (endpoints does not exist or endpoints.vpc does not exist or endpoints.vpc is empty)
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-es-describe-elasticsearch-domain' AND json.rule = processing is false and vpcoptions.vpcid does not exist
</code></pre><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Azure Key Vault Firewall is not enabled</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL is updated to not trigger alerts when the public access is disabled.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-key-vault-list' AND json.rule = properties.networkAcls.ipRules[*].value does not exist
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-key-vault-list' AND json.rule = properties.networkAcls.ipRules[*].value does not exist and properties.publicNetworkAccess does not equal ignore case disabled
</code></pre><p><strong>Impact—</strong> Low. Existing alerts which were triggered when the public access was disabled will be resolved.</p></td></tr><tr><td><p><strong>Azure Storage account is not configured with private endpoint connection</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL has been updated to report azure storage account which allow all networks with <code>IPrule</code> and <code>VirtualNetworkRule</code> not being empty.</p><p><strong>Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equals Succeeded and networkRuleSet.defaultAction equal ignore case Allow and networkRuleSet.virtualNetworkRules is empty and networkRuleSet.ipRules[] is empty and properties.privateEndpointConnections[] is empty
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equals Succeeded and networkRuleSet.defaultAction equal ignore case Allow and properties.privateEndpointConnections[*] is empty
</code></pre><p><strong>Impact—</strong> Low. New alerts will be generated when the <code>IPrule</code> and <code>VirtualNetworkRule</code> are retained.</p></td></tr><tr><td><p><strong>AWS S3 bucket publicly readable</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy remediation steps and RQL will be updated to check for Authenticated User with read access.</p><p><strong>Policy Type—</strong> Config</p><p><strong>Severity—</strong> High</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-s3api-get-bucket-acl' AND json.rule = ((((publicAccessBlockConfiguration.ignorePublicAcls is false and accountLevelPublicAccessBlockConfiguration does not exist) or (publicAccessBlockConfiguration does not exist and accountLevelPublicAccessBlockConfiguration.ignorePublicAcls is false) or (publicAccessBlockConfiguration.ignorePublicAcls is false and accountLevelPublicAccessBlockConfiguration.ignorePublicAcls is false)) and acl.grantsAsList[?any(grantee equals AllUsers and permission is member of (ReadAcp,Read,FullControl))] exists) or ((policyStatus.isPublic is true and ((publicAccessBlockConfiguration.restrictPublicBuckets is false and accountLevelPublicAccessBlockConfiguration does not exist) or (publicAccessBlockConfiguration does not exist and accountLevelPublicAccessBlockConfiguration.restrictPublicBuckets is false) or (publicAccessBlockConfiguration.restrictPublicBuckets is false and accountLevelPublicAccessBlockConfiguration.restrictPublicBuckets is false))) and (policy.Statement[?any(Effect equals Allow and (Principal equals * or Principal.AWS equals *) and (Action contains s3:* or Action contains s3:Get or Action contains s3:List) and (Condition does not exist))] exists))) and websiteConfiguration does not exist
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-s3api-get-bucket-acl' AND json.rule = ((((publicAccessBlockConfiguration.ignorePublicAcls is false and accountLevelPublicAccessBlockConfiguration does not exist) or (publicAccessBlockConfiguration does not exist and accountLevelPublicAccessBlockConfiguration.ignorePublicAcls is false) or (publicAccessBlockConfiguration.ignorePublicAcls is false and accountLevelPublicAccessBlockConfiguration.ignorePublicAcls is false)) and (acl.grantsAsList[?any(grantee equals AllUsers and permission is member of (ReadAcp,Read,FullControl))] exists or acl.grantsAsList[?any(grantee equals AuthenticatedUsers and permission is member of (ReadAcp,Read,FullControl))] exists)) or ((policyStatus.isPublic is true and ((publicAccessBlockConfiguration.restrictPublicBuckets is false and accountLevelPublicAccessBlockConfiguration does not exist) or (publicAccessBlockConfiguration does not exist and accountLevelPublicAccessBlockConfiguration.restrictPublicBuckets is false) or (publicAccessBlockConfiguration.restrictPublicBuckets is false and accountLevelPublicAccessBlockConfiguration.restrictPublicBuckets is false))) and (policy.Statement[?any(Effect equals Allow and (Principal equals * or Principal.AWS equals *) and (Action contains s3:* or Action contains s3:Get or Action contains s3:List) and (Condition does not exist))] exists))) and websiteConfiguration does not exist
</code></pre><p><strong>Impact—</strong> Low. New alerts will be generated when Authenticated users have read permissions.</p></td></tr><tr><td><strong>Policy Updates—Metadata</strong></td><td></td></tr><tr><td><p><strong>GCP VM instance using a default service account with full access to all Cloud APIs</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy name, description and remediation details are updated.</p><p><strong>Current Policy Name—</strong> GCP VM instance using a default service account with full access to all Cloud APIs</p><p><strong>Updated Policy Name—</strong> GCP VM instance using a default service account with Cloud Platform access scope</p><p><strong>Current Policy Description—</strong> This policy identifies the GCP VM instances which are using a default service account with full access to all Cloud APIs. To compliant with the principle of least privileges and prevent potential privilege escalation it is recommended that instances are not assigned to default service account 'Compute Engine default service account' with scope 'Allow full access to all Cloud APIs'.</p><p><strong>Updated Policy Description—</strong> This policy identifies the GCP VM instances that are using a default service account with cloud-platform access scope. To compliant with the principle of least privileges and prevent potential privilege escalation it is recommended that instances are not assigned to default service account 'Compute Engine default service account' with scope 'cloud-platform'.</p><p><strong>Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><strong>Policy Deletion</strong></td><td></td></tr><tr><td><p><strong>Azure Policies Deletion</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p></td><td><p><strong>Changes—</strong> Azure has deprecated Azure Storage classic metrics. Due to this change the following associated policies have been deleted:</p><ul><li>Azure storage account logging (Classic Diagnostic Setting) for queues is disabled (fde9482f-3ac2-43f6-bda2-bf2013074acd)</li><li>Azure storage account logging (Classic Diagnostic Setting) for blobs is disabled (85a4a77f-0d46-4c3d-ae8c-37d945a0b44e)</li><li>Azure storage account logging (Classic Diagnostic Setting) for tables is disabled (f4784022-48f3-4f3b-bc16-2b7fef56aea3)</li></ul><p><strong>Impact—</strong> Low. Existing alerts are resolved as <code>Policy_Deleted</code>.</p></td></tr></tbody></table>

## Policy Updates - IAM

tt:\[**24.1.2**]

The following IAM policy has updated RQL.

<table data-header-hidden><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Name</strong></td><td><strong>Old RQL</strong></td><td><strong>New RQL</strong></td></tr><tr><td><strong>AWS cross-account resource access through IAM policies</strong></td><td><pre><code>config from iam where dest.cloud.type = 'AWS' and source.cloud.account != dest.cloud.account
</code></pre></td><td><pre><code>config from iam where dest.cloud.type = 'AWS' and source.cloud.account != dest.cloud.account AND dest.cloud.accountgroup != 'Default Account Group' AND dest.cloud.account != '*'
</code></pre></td></tr></tbody></table>

tt:\[**24.1.1**]

The following IAM policies has updated names and description.

| **Old Policy Name**                                                    | **Old Policy Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                      | **New Policy Name**                                                         | **New Policy Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ---------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS EC2 instance with IAM permissions management access level          | This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.AWS IAM permissions management access level that are risky for AWS EC2 instances. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of permissions management access to minimize security risks. | AWS EC2 Instance with IAM policy management permissions                     | This policy identifies IAM permissions that allow EC2 instances to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                                 |
| AWS EC2 instance with IAM write access level                           | This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                                   | AWS EC2 Instance with IAM write permissions                                 | This policy identifies IAM permissions that allow EC2 instances to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                                           |
| AWS EC2 instance with org write access level                           | This policy identifies org write access that is defined as risky permissions. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                                         | AWS EC2 Instance with AWS Organization management permissions               | This policy identifies IAM permissions that allow EC2 instances to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                  |
| AWS Lambda Function with IAM permissions management access level       | This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS Lambda Function instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                            | AWS Lambda Function with IAM policy management permissions                  | This policy identifies IAM permissions that allow Lambda functions to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                              |
| AWS Lambda Function with IAM write access level                        | This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS Lambda Function instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                       | AWS Lambda Function with IAM write permissions                              | This policy identifies IAM permissions that allow Lambda functions to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                                        |
| AWS Lambda Function with org write access level                        | This policy identifies org write access that is defined as risky permissions. Ensure that the AWS Lambda Function instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                             | AWS Lambda Function with AWS Organization management permissions            | This policy identifies IAM permissions that allow Lambda functions to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.               |
| Okta User with IAM permissions management access level                 | This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the Okta Users in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                                           | AWS Okta User with IAM policy management permissions                        | This policy identifies IAM permissions that allow Okta users to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                                    |
| Okta User with IAM write access level                                  | This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the Okta Users in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                                                      | AWS Okta User with IAM write permissions                                    | This policy identifies IAM permissions that allow Okta users to perform write operations for IAM, such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                                              |
| Okta User with org write access level                                  | This policy identifies org write access that is defined as risky permissions. Ensure that the Okta Users in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                                                            | AWS Okta User with AWS Organization management permissions                  | This policy identifies IAM permissions that allow Okta users to manage AWS Organizations, such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                    |
| ECS Task Definition with IAM permissions management access level       | This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS ECS Task Definition instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                        | AWS ECS Task Definition with IAM policy management permissions              | This policy identifies IAM permissions that allow ECS task definitions to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                          |
| ECS Task Definition with IAM write access level                        | This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS ECS Task Definition instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks                                                                                                                                                                                                                                    | AWS ECS Task Definition with IAM write permissions                          | This policy identifies IAM permissions that allow ECS task definitions to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                                    |
| ECS Task Definition with org write access level                        | This policy identifies org write access that is defined as risky permissions. Ensure that the AWS ECS Task Definition instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                         | AWS ECS Task Definition with AWS Organization management permissions        | This policy identifies IAM permissions that allow ECS task definitions to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.           |
| IAM User with IAM permissions management access level                  | This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the IAM Users in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                                            | AWS IAM User with IAM policy management permissions                         | This policy identifies IAM permissions that allow IAM users to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                                     |
| IAM User with IAM write access level                                   | This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the IAM Users in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                                                       | AWS IAM User with IAM write permissions                                     | This policy identifies IAM permissions that allow IAM users to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                                               |
| IAM User with org write access level                                   | This policy identifies org write access that is defined as risky permissions. Ensure that the IAM Users in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                                                             | AWS IAM User with AWS Organization management permissions                   | This policy identifies IAM permissions that allow IAM users to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                      |
| Elasticbeanstalk Platform with IAM permissions management access level | This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS Elasticbeanstalk Platform instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                  | AWS Elastic Beanstalk Platform with IAM policy management permissions       | This policy identifies IAM permissions that allows an Elastic Beanstalk Platform to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                |
| Elasticbeanstalk Platform with IAM write access level                  | This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS Elasticbeanstalk Platform instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                             | AWS Elastic Beanstalk Platform with IAM write permissions                   | This policy identifies IAM permissions that allows an Elastic Beanstalk Platform to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.                                          |
| Elasticbeanstalk Platform with org write access level                  | This policy identifies org write access that is defined as risky permissions. Ensure that the AWS Elasticbeanstalk Platform instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.                                                                                                                                                                                                                                   | AWS Elastic Beanstalk Platform with AWS Organization management permissions | This policy identifies IAM permissions that allows an Elastic Beanstalk Platform to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment. |

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                                                                                                                                  | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Support for RBI Compliance Standard</strong></p><p><mark style="background-color:orange;">24.1.2</mark></p>                                                    | <p>Prisma Cloud now supports the Reserve Bank of India (RBI) compliance standard. This comprehensive framework mandates a proactive stance on cybersecurity, ensuring secure networks and databases, constant protection of customer information, and immediate response plans for security incidents.</p><p>You can now view this built-in standard and the associated policies on <strong>Compliance > Standards</strong>. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p>                    |
| <p><strong>Support for SEBI Compliance Standard</strong></p><p><mark style="background-color:orange;">24.1.2</mark></p>                                                   | <p>Prisma Cloud now supports the Securities and Exchange Board of India (SEBI) compliance standard. This regulation lays down the listing obligations of companies that have listed their securities on stock exchanges in India. It also provides for the disclosure requirements that these companies must comply with.</p><p>You can now view this built-in standard and the associated policies on <strong>Compliance > Standards</strong>. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p> |
| <p><mark style="background-color:orange;">Update</mark> <strong>Policy Mappings for Azure CIS 2.0</strong></p><p><mark style="background-color:orange;">24.1.2</mark></p> | <p>The following compliance requirements in Azure CIS 2.0 Level 1 and Azure CIS 2.0 Level 2 are updated with new mappings:</p><ul><li>Azure CIS 2.0 Level 1</li><li>Database Services</li><li>Microsoft Defender</li><li>Storage Accounts</li><li>Azure CIS 2.0 Level 2</li><li>Database Services</li><li>Microsoft Defender</li></ul><p><strong>Impact—</strong> Compliance score can vary as new mappings are introduced.</p>                                                                                                                                                                 |

## REST API Updates

| **Change**                                                                                                                                                           | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><strong>New Alerts API</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                   | A new [Create On Demand Notification](https://pan.dev/prisma-cloud/api/cspm/create-ondemand-notification/) endpoint is now available. It allows you to configure and share alert notifications through Email, Jira, or Slack.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>New Widget APIs</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                                                  | <p>The following new APIs are added to get the data from some of the widgets used to create custom dashboards:</p><ul><li>Get Alerts Count by Resolution Reason - <a href="https://pan.dev/prisma-cloud/api/cspm/value-widgets-alert-metrics-resolution-reason/">POST api/v1/metrics/alert-count-by-resolution-reason</a></li><li>Get Mean Resolution Time - <a href="https://pan.dev/prisma-cloud/api/cspm/value-widgets-alert-metrics/">POST /api/v1/metrics/alert-mean-resolution-time</a></li></ul>                                                                                                                                                                                                            |
| <p><strong>Unified Vulnerability Explorer API</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p>                               | A new [Get Prioritized Vulnerabilities V2](https://pan.dev/prisma-cloud/api/cspm/prioritised-vulnerability-v-2/) API is now available. It allows to view the top priority vulnerabilities along with the number of assets in which they occur.                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| <p><mark style="background-color:orange;">Update</mark> <strong>Policy APIs</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p> | <p>The policy APIs now support the following types and subtypes:</p><ul><li><strong>Policy types</strong> - malware and grayware</li><li><strong>Policy subtypes</strong> - host and container\_image</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>IAM APIs</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                         | New versions of [IAM](https://pan.dev/prisma-cloud/api/cspm//iam/) endpoints are now available to get permissions, access details, and query suggestions. A few other new endpoints are also added to the [IAM](https://pan.dev/prisma-cloud/api/cspm//iam/) category to get the least privilege access details and remediation command.                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Widget APIs</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                      | <p>The following new APIs are added to get the data from some of the widgets used to create custom dashboards:</p><ul><li>Get Discovered and Secured Resources - <a href="https://pan.dev/prisma-cloud/api/cspm/value-widgets-get-discovered-vs-secured/">POST /adoptionadvisor/api/v2/compute/discovered-secured/trend</a></li><li>Get Vulnerabilities Trend - <a href="https://pan.dev/prisma-cloud/api/cspm/value-widgets-get-vulnerabilities-trend/">POST /adoptionadvisor/api/v2/compute/vulnerabilities/trend</a></li><li>Get Assets with Alerts - <a href="https://pan.dev/prisma-cloud/api/cspm/value-widgets-get-assets-with-alerts/">POST /adoptionadvisor/api/v2/cspm/riskyasset/trend</a></li></ul>    |
| <p><strong>Unified Vulnerability Explorer APIs</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                              | New APIs are available in the [Unified Vulnerability Explorer](https://pan.dev/prisma-cloud/api/cspm/unified-vulnerability-explorer/) category to get the list of vulnerabilities based on CVE, priority, stage, RQL, and so on. In addition, you have endpoints to get the remediation status and create a remediation request.                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>Background Job APIs</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                              | <p>The following new endpoints are available to get background job reports:</p><ul><li>Get Reports Metadata - <a href="https://pan.dev/prisma-cloud/api/cspm/list-reports/">GET /report-service/api/v1/report</a></li><li>Get Report Metadata by ID - <a href="https://pan.dev/prisma-cloud/api/cspm/get-report-metadata-by-id/">GET /report-service/api/v1/report/:reportId</a></li><li>Get Report Status - <a href="https://pan.dev/prisma-cloud/api/cspm/get-report-status-by-id/">GET /report-service/api/v1/report/:reportId/status</a></li><li>Download a Report - <a href="https://pan.dev/prisma-cloud/api/cspm/download-report-by-id/">GET /report-service/api/v1/report/:reportId/download</a></li></ul> |
| <p><strong>Add a New Collection</strong></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                             | Collections that were added using the [Add a New Collection](https://pan.dev/prisma-cloud/api/cwpp/post-collections/) did not display as expected in the Console. This issue has been resolved by making all request body fields, except `name`, optional. Any field that is not provided will default to the wildcard value '\*'.                                                                                                                                                                                                                                                                                                                                                                                 |

## Deprecation Notices

| **Change**                                                                                                                                                                                                                                                    | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>End of Life (EOL) for Prisma Cloud Microsegmentation in 24.1.2</strong></p><p><mark style="background-color:orange;"><strong>24.1.2</strong></mark></p><p><em>EOL was first announced in 23.9.2</em></p>                                           | <p>The Prisma Cloud Microsegmentation module was announced as End-of-Sale effective 31 August, 2022. As of the 24.1.2 release, the Microsegmentation solution is disconnected and any active agents will no longer work.</p><p>Make sure to uninstall all instances of the Enforcer (the Microsegmentation agent) deployed in your environment, as these agents will no longer enforce any security policies on traffic on or across your hosts.</p> |
| <p><strong>app.sg Stack Decommissioned for Prisma Cloud Data Security</strong></p><p><mark style="background-color:orange;"><strong>Secure the Infrastructure</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p> | You will no longer be able to use the **app.sg** stack for Data Security since it’s being decommissioned. If you want to use Data Security, contact your Prisma Cloud customer support representative.                                                                                                                                                                                                                                               |
| <p><strong>Support for BridgecrewCLI</strong></p><p><mark style="background-color:orange;"><strong>Secure the Source</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                          | BridgecrewCLI including GitHub Action, CircleCI Orb, and container have been deprecated. You can continue using Checkov and its compatible plugins without any disruptions.                                                                                                                                                                                                                                                                          |
| <p><strong>Alerts</strong></p><p><mark style="background-color:orange;"><strong>Secure the Runtime</strong></mark></p><p><mark style="background-color:orange;"><strong>24.1.1</strong></mark></p>                                                            | <p>Deprecated the <code>AccountID</code> and <code>Cluster</code> macros used in alerts. This removes the <code>AccountID</code> and <code>Cluster</code> fields in the following alerts using the macros.</p><ul><li>Webhook</li><li>AWS SQS</li><li>Prisma Cortex Alert</li><li>Splunk</li></ul>                                                                                                                                                   |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-january-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
