Features Introduced in January 2024
Learn what’s new on Prisma® Cloud in January 2024.
Announcement
Feature
Description
Prisma Cloud Darwin Release
The Prisma Cloud Darwin Release is now available for all Prisma Cloud environments except app.cn and app.gov. With the Code to Cloud™ intelligence capabilities in this release, your security and development teams can work together to reduce application risks and prevent breaches.
With this change, your tenant will be updated with the new intuitive user interface and rich set of security capabilities. When you are upgraded to the Darwin release, refer to the Enterprise Edition documentation.
Contact your Prisma Cloud Customer Success team for more details.
New Features
Feature
Description
Compliance Dashboard
Secure the Infrastructure
24.1.2
Prisma Cloud’s out of the box dashboards now include a Compliance dashboard. Select Home > Dashboards > Compliance to view a snapshot of assets and their compliance status, compliance trends over time, and top compliance policies by failed status.

Update Code to Cloud Dashboard
Secure the Infrastructure
24.1.2
Prisma Cloud’s Latest Events tracker now provides redirections on the events from all phases of the Code Build Deploy Run (CBDR) cloud deployment lifecycle. Select any event from Home > Dashboards > Code to Cloud > Latest Events to immediately take action and investigate the risk or incident. Learn more about optimizing Prisma Cloud Dashboards.
Update Code to Cloud Dashboard
Secure the Infrastructure
24.1.2
Prisma Cloud’s Dashboards > Add Dashboard > Widget Selector now includes two additional widgets to help you easily report on your organization’s efficiency in responding to alerts. Widgets are currently available to System Administrators and include:
Alerts by MTTR - Displays alerts by severity and their mean time to resolution.
Alert by Resolution Reason - Displays the resolved alerts by their method of resolution.
Learn more about leveraging these widgets to create your own custom dashboards.
Send Ad hoc Alert Notifications to Email and Slack
Secure the Infrastructure
24.1.2
In addition to sending ad hoc Alert notifications to your Jira integration, now you can also send a notification to Email and Slack for any open alert. From Alerts > Overview, select an Alert ID link to view the details. From the Send To dropdown, select Email or Slack to send the notification.

Selecting View Alert from the Email received or the Slack channel will directly open the Alert Overview (for all Policies, except Attack Path) or the Evidence Graph (for Attack Path policies) in the Prisma Cloud console.
Unique Counts on the Prioritized Funnel
Secure the Runtime
24.1.2
In Vulnerability Management, the Prioritized Funnel widget now displays the unique CVE count instead of the total number of CVE occurrences.
Dashboard Widgets
Secure the Infrastructure
24.1.1
Prisma Cloud’s Dashboards > Add Dashboard > Widget Selector now includes eight additional widgets to help you create customized dashboards to track your organization’s key metrics. Widgets include:
Adoption Progress
Assets with Urgent Alerts
Anomalous Threats Detected
Top Custom Alerts Generated
Discovered vs. Secured Resources
Vulnerabilities Trend by Resource Type
Risks Burndown
Incidents Burndown
Terraform Module Scanning
Secure the Source
24.1.1
Prisma Cloud now supports rendering and scanning public, private, and locally cached Terraform modules. This capability enables you to analyze misconfigurations that may result from the module definition and the variables defined in the resource block. For more information, see Terraform Module Scanning.
Agentless Scanning
Secure the Runtime
24.1.1
Added agentless scanning support of encrypted volumes in Azure for the hub account mode.
Agentless Scanning
Secure the Runtime
24.1.1
Added agentless scanning hub account mode for Azure.
Vulnerability Management
Secure the Runtime
24.1.1
Added support for Debian Bullseye and Bookworm Security fixes.
Operating System Support
Secure the Runtime
24.1.1
Added support for OpenShift 4.14.
Vulnerability Management
Secure the Runtime
24.1.1
From 32.01, support is added to detect the Java version number when IBM Java is used during vulnerability management. This enhancement covers IBM Java version 1.8 and earlier. For IBM Java version 1.9 and later, support is partial and depends on the presence of the jdk/release file.
API Ingestions
Service
API Details
Azure Cache
24.1.2
azure-cache-redis-diagnostic-settings
Additional permissions required:
Microsoft.Cache/redis/readMicrosoft.Insights/DiagnosticSettings/Read
The Reader role includes the permissions.
Google Cloud VMware Engine
24.1.2
gcloud-vmware-engine-private-cloud
Additional permissions required:
vmwareengine.locations.listvmwareengine.privateClouds.listvmwareengine.privateClouds.getIamPolicy
The Viewer role includes the permissions.
Google Cloud VMware Engine
24.1.2
gcloud-vmware-engine-cluster
Additional permissions required:
vmwareengine.locations.listvmwareengine.privateClouds.listvmwareengine.clusters.listvmwareengine.clusters.getIamPolicy
The Viewer role includes the permissions.
Google Cloud VMware Engine
24.1.2
gcloud-vmware-engine-hcx-activation-key
Additional permissions required:
vmwareengine.locations.listvmwareengine.privateClouds.listvmwareengine.hcxActivationKeys.listvmwareengine.hcxActivationKeys.getIamPolicy
The Viewer role includes the permissions.
Google Cloud VMware Engine
24.1.2
gcloud-vmware-engine-subnet
Additional permissions required:
vmwareengine.locations.listvmwareengine.privateClouds.listvmwareengine.subnets.list
The Viewer role includes the permissions.
Google Vertex AI AIPlatform
24.1.2
gcloud-vertex-ai-aiplatform-custom-job
Additional permission required:
aiplatform.customJobs.list
The Viewer role includes the permission.
Google Vertex AI AIPlatform
24.1.2
gcloud-vertex-ai-aiplatform-endpoint
Additional permission required:
aiplatform.endpoints.list
The Viewer role includes the permission.
Google Vertex AI AIPlatform
24.1.2
gcloud-vertex-ai-aiplatform-training-pipeline
Additional permission required:
aiplatform.trainingPipelines.list
The Viewer role includes the permission.
Google Vertex AI AIPlatform
24.1.2
gcloud-vertex-ai-aiplatform-pipeline-job
Additional permission required:
aiplatform.pipelineJobs.list
The Viewer role includes the permission.
Google Speech to text
24.1.2
gcloud-speech-projects-locations-phraseSets-list
Additional permission required:
speech.phraseSets.list
The Viewer role includes the permission.
Google Speech to text
24.1.2
gcloud-speech-projects-locations-customClasses-list
Additional permission required:
speech.customClasses.list
The Viewer role includes the permission.
Google Cloud Composer
24.1.2
gcloud-composer-projects-locations-imageVersions-list
Additional permission required:
composer.imageversions.list
The Viewer role includes the permission.
Google Data Migration
24.1.2
gcloud-datamigration-projects-locations-privateConnections-list
Additional permissions required:
datamigration.privateconnections.listdatamigration.privateconnections.getIamPolicy
The Viewer role includes the permissions.
Google Data Migration
24.1.2
gcloud-datamigration-projects-locations-connectionProfiles-list
Additional permissions required:
datamigration.connectionprofiles.listdatamigration.connectionprofiles.getIamPolicy
The Viewer role includes the permissions.
Google Data Migration
24.1.2
gcloud-datamigration-projects-locations-conversionWorkspaces-list
Additional permissions required:
datamigration.conversionworkspaces.listdatamigration.conversionworkspaces.getIamPolicy
The Viewer role includes the permissions.
Google Data Migration
24.1.2
gcloud-datamigration-projects-locations-migrationJobs-list
Additional permissions required:
datamigration.migrationjobs.listdatamigration.migrationjobs.getIamPolicy
The Viewer role includes the permissions.
Update Google Deployment Manager
24.1.2
gcloud-deployment-manager-deployment-manifest
Prisma Cloud will update the Resource Name and Asset ID fields in the backend for gcloud-deployment-manager-deployment-manifest API. Due to this change, when you perform an RQL search query, you will be able to see a change in the Resource Name and Asset ID fields making it easier for you to identify the resources. Also, all the existing resources will be deleted, and then regenerated on the management console.
Existing alerts corresponding to this resource will be resolved as Resource_Deleted, and new alerts will be generated against any policy violations.
Impact— None. Once the resources for gcloud-deployment-manager-deployment-manifest resume ingesting data, you will notice the correct alert count in the console.
Update Google Cloud SQL
24.1.2
gcloud-sql-instances-list
Prisma Cloud has updated the gcloud-sql-instances-list API to exclude the settings.settingsVersion field from the JSON response because it changes frequently and does not add much value to the response.
OCI Service Catalog
24.1.1
oci-servicecatalog-catalog
Additional permissions required:
SERVICE_CATALOG_INSPECTSERVICE_CATALOG_READ
You must update the Terraform template to enable the permissions.
Update OCI Data Safe
24.1.1
oci-data-safe-target-database
The resource JSON for this API no longer includes the timeUpdated field.
Update OCI Database
24.1.1
oci-database-autonomous-database
The resource JSON for this API no longer includes the actualUsedDataStorageSizeInTBs field.
Update OCI MySQL
24.1.1
oci-mysql-dbsystems
The resource JSON for this API no longer includes the timeUpdated field.
New Policies
Policies
Description
Azure Cognitive Services account not configured with private endpoint
24.1.2
Identifies Azure Cognitive Services accounts that are not configured with private endpoint. Private endpoints in Azure AI service resources allow clients on a virtual network to securely access data over Azure Private Link. Configuring a private endpoint enables access to traffic coming from only known networks and prevents access from malicious or unknown IP addresses which includes IP addresses within Azure. It is recommended to create private endpoint for secure communication for your Cognitive Services account.
Policy Severity— Medium
Policy Type— Config
Azure Cognitive Services account is not configured with managed identity
24.1.2
Identifies Azure Cognitive Services accounts that are not configured with managed identity. Managed identity can be used to authenticate to any service that supports Azure AD authentication, without having credentials in your code. Storing credentials in a code increases the threat surface in case of exploitation and also managed identities eliminate the need for developers to manage credentials. So as a security best practice, it is recommended to have the managed identity to your Cognitive Services account.
Policy Severity— Informational
Policy Type— Config
Azure Cognitive Services account configured with public network access
24.1.2
Identifies Azure Cognitive Services accounts configured with public network access. Overly permissive public network access allows access to resource through the internet using a public IP address. It is recommended to restrict IP ranges to allow access to your cognitive Services account and endpoint from specific public internet IP address ranges and is accessible only to restricted entities.
Policy Severity— High
Policy Type— Config
Attack Path Policies
New Attack Path policies are available. Log in to the Prisma Cloud console and filter for the list of available policies.
AWS S3 bucket encrypted using Customer Managed Key (CMK) with overly permissive policy
24.1.1
Identifies Amazon S3 buckets that use Customer Managed Keys (CMKs) for encryption that have a key policy overly permissive. Amazon S3 bucket encryption key overly permissive can result in the exposure of sensitive data and potential compliance violations. As a security best practice, It is recommended to follow the principle of least privilege ensuring that the KMS key policy does not have all the permissions to be able to complete a malicious action.
Policy Severity— Medium
Policy Type— Config
AWS S3 bucket encrypted with Customer Managed Key (CMK) is not enabled for regular rotation
24.1.1
Identifies Amazon S3 buckets that use Customer Managed Keys (CMKs) for encryption but are not enabled with key rotation. Amazon S3 bucket encryption key rotation failure can result in prolonged exposure of sensitive data and potential compliance violations. As a security best practice, it is important to rotate these keys periodically. This ensures that if the keys are compromised, the data in the underlying service remains secure with the new keys.
Policy Severity— Informational
Policy Type— Config
AWS RDS database instance encrypted with Customer Managed Key (CMK) is not enabled for regular rotation
24.1.1
Identifies Amazon RDS instances that use Customer Managed Keys (CMKs) for encryption but are not enabled with key rotation. Amazon RDS instance encryption key rotation failure can result in prolonged exposure of sensitive data and potential compliance violations. As a security best practice, it is important to periodically rotate these keys. This ensures that if the keys are compromised, the data in the underlying service remains secure with the new keys.
Policy Severity— Informational
Policy Type— Config
Azure Storage account encrypted by an encryption key configured access policy with privileged operations
24.1.1
Identifies Azure Storage accounts which are encrypted by an encryption key configured access policy with privileged operations. Encryption keys should be kept confidential and only accessible to authorized entity with limited operation access. Allowing privileged access to an encryption key also allows to alter/delete the data that is encrypted by it, making the data more easily accessible. It is recommended to have restricted access policies to an encryption key so that only authorized entities can access it with limited operation access.
Policy Severity— Medium
Policy Type— Config
Azure Storage account encrypted by an encryption key that is not rotated regularly
24.1.1
Identifies Azure Storage accounts which are encrypted by an encryption key that is not rotated regularly. As a security best practice, it is important to rotate the keys periodically so that if the keys are compromised, the data in the underlying service is still secure with the new keys.
Policy Severity— Informational
Policy Type— Config
Azure AKS cluster configured with overly permissive API server access
24.1.1
Identifies AKS clusters configured with overly permissive API server access. In Kubernetes, the API server receives requests to perform actions in the cluster such as to create resources or scale the number of nodes. To enhance cluster security and minimize attacks, the API server should only be accessible from a limited set of IP address ranges. These IP ranges allow defined IP address ranges to communicate with the API server. A request made to the API server from an IP address that is not part of these authorized IP ranges is blocked. It is recommended to configure AKS cluster with defined IP address ranges to communicate with the API server.
Policy Severity— Low
Policy Type— Config
Azure Machine learning workspace configured with overly permissive network access
24.1.1
Identifies Machine learning workspaces configured with overly permissive network access. Overly permissive public network access allows access to resource through the internet using a public IP address. It is recommended to restrict IP ranges to allow access to your workspace and endpoint from specific public internet IP address ranges and is accessible only to restricted entities.
Policy Severity— High
Policy Type— Config
New CI/CD Configuration Build Policies
24.1.1
Added the following default CI/CD policies within the Build subtype of Configuration policies under Governance for enhanced continuous integration and deployment pipeline security.
Azure Repo Policies
Potential dependency confusion in an Azure Repos repository due to package name or scope available in registry
Deprecated package used in NPM project of an Azure Repos repository
Missing ‘.npmrc’ file in Azure Repos repository
Possible Python typosquatting detected in an Azure Repos repository
Secret exposed in registry URL within ‘.npmrc’ file of an Azure Repos repository
Unencrypted channel used by ‘.npmrc’ file of an Azure Repos repository to download dependencies from proxy
Azure Pipelines uses an unpinned container image
Secret exposed in proxy URL within ‘.npmrc’ file of an Azure Repos repository
Deprecated package used in NPM project of a Bitbucket repository
Bitbucket Policies
Missing ‘.npmrc’ file in Bitbucket repository
Possible Python typosquatting detected in a Bitbucket repository
Potential dependency confusion in a Bitbucket repository due to package name or scope available in registry
Private Bitbucket repository made public
Secret exposed in proxy URL within ‘.npmrc’ file of a Bitbucket repository
Secret exposed in registry URL within ‘.npmrc’ file of a Bitbucket repository
Unencrypted channel used by ‘.npmrc’ file of a Bitbucket repository to download dependencies from proxy
Unencrypted channel used by ‘.npmrc’ file of a Bitbucket repository to download dependencies from registry
CircleCI Policies
CircleCI pipeline uses an unpinned container image
GitHub Policies
Deprecated package used in NPM project of a GitHub repository
Missing ‘.npmrc’ file in GitHub repository
Possible Python typosquatting detected in a GitHub repository
Potential dependency confusion in a GitHub repository due to package name or scope available in registry
Secret exposed in proxy URL within ‘.npmrc’ file of a GitHub repository
Secret exposed in registry URL within ‘.npmrc’ file of a GitHub repository
Unencrypted channel used by ‘.npmrc’ file of a GitHub repository to download dependencies from proxy
Unencrypted channel used by ‘.npmrc’ file of a GitHub repository to download dependencies from registry
Unrotated organization secrets in GitHub Actions
Unrotated repository secrets in GitHub Actions
GitLab Policies
Deprecated package used in NPM project of a GitLab repository
Missing ‘.npmrc’ file in GitLab repository
Possible Python typosquatting detected in a GitLab repository
Potential dependency confusion in a GitLab repository due to package name or scope available in registry
Secrets found in logs of a GitLab CI pipeline
Secret exposed in proxy URL within ‘.npmrc’ file of a GitLab repository
Secret exposed in registry URL within ‘.npmrc’ file of a GitLab repository
Unencrypted channel used by ‘.npmrc’ file of a GitLab repository to download dependencies from proxy
Unencrypted channel used by ‘.npmrc’ file of a GitLab repository to download dependencies from registry
Policy Updates
Policy Updates
Description
Policy Updates—RQL
Azure Function App authentication is off
24.1.2
Changes— The policy RQL is updated to only report Function Apps for which authentication is disabled. Azure Function App Authentication prevents anonymous HTTP requests from reaching the API app or authenticates token-enabled requests before they reach the API app, but not the Logic app or Web App resources created in Azure.
Severity— Low
Policy Type— Config
Current RQL—
Updated RQL—
Impact— Low. Existing alerts generated for Logic App and Web App will be resolved and new alerts will be generated.
AWS Elasticsearch domain publicly accessible
24.1.1
Changes— The policy RQL is updated to check for vpc-options instead of vpc.endpoints.
Severity— Medium
Policy Type— Config
Current RQL—
Updated RQL—
Impact— No impact on alerts.
Azure Key Vault Firewall is not enabled
24.1.1
Changes— The policy RQL is updated to not trigger alerts when the public access is disabled.
Severity— Low
Policy Type— Config
Current RQL—
Updated RQL—
Impact— Low. Existing alerts which were triggered when the public access was disabled will be resolved.
Azure Storage account is not configured with private endpoint connection
24.1.1
Changes— The policy RQL has been updated to report azure storage account which allow all networks with IPrule and VirtualNetworkRule not being empty.
Severity— Medium
Policy Type— Config
Current RQL—
Updated RQL—
Impact— Low. New alerts will be generated when the IPrule and VirtualNetworkRule are retained.
AWS S3 bucket publicly readable
24.1.1
Changes— The policy remediation steps and RQL will be updated to check for Authenticated User with read access.
Policy Type— Config
Severity— High
Current RQL—
Updated RQL—
Impact— Low. New alerts will be generated when Authenticated users have read permissions.
Policy Updates—Metadata
GCP VM instance using a default service account with full access to all Cloud APIs
24.1.1
Changes— The policy name, description and remediation details are updated.
Current Policy Name— GCP VM instance using a default service account with full access to all Cloud APIs
Updated Policy Name— GCP VM instance using a default service account with Cloud Platform access scope
Current Policy Description— This policy identifies the GCP VM instances which are using a default service account with full access to all Cloud APIs. To compliant with the principle of least privileges and prevent potential privilege escalation it is recommended that instances are not assigned to default service account 'Compute Engine default service account' with scope 'Allow full access to all Cloud APIs'.
Updated Policy Description— This policy identifies the GCP VM instances that are using a default service account with cloud-platform access scope. To compliant with the principle of least privileges and prevent potential privilege escalation it is recommended that instances are not assigned to default service account 'Compute Engine default service account' with scope 'cloud-platform'.
Severity— Medium
Policy Type— Config
Impact— No impact on alerts.
Policy Deletion
Azure Policies Deletion
24.1.1
Changes— Azure has deprecated Azure Storage classic metrics. Due to this change the following associated policies have been deleted:
Azure storage account logging (Classic Diagnostic Setting) for queues is disabled (fde9482f-3ac2-43f6-bda2-bf2013074acd)
Azure storage account logging (Classic Diagnostic Setting) for blobs is disabled (85a4a77f-0d46-4c3d-ae8c-37d945a0b44e)
Azure storage account logging (Classic Diagnostic Setting) for tables is disabled (f4784022-48f3-4f3b-bc16-2b7fef56aea3)
Impact— Low. Existing alerts are resolved as Policy_Deleted.
Policy Updates - IAM
tt:[24.1.2]
The following IAM policy has updated RQL.
Policy Name
Old RQL
New RQL
AWS cross-account resource access through IAM policies
tt:[24.1.1]
The following IAM policies has updated names and description.
Old Policy Name
Old Policy Description
New Policy Name
New Policy Description
AWS EC2 instance with IAM permissions management access level
This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.AWS IAM permissions management access level that are risky for AWS EC2 instances. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of permissions management access to minimize security risks.
AWS EC2 Instance with IAM policy management permissions
This policy identifies IAM permissions that allow EC2 instances to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
AWS EC2 instance with IAM write access level
This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS EC2 Instance with IAM write permissions
This policy identifies IAM permissions that allow EC2 instances to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
AWS EC2 instance with org write access level
This policy identifies org write access that is defined as risky permissions. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS EC2 Instance with AWS Organization management permissions
This policy identifies IAM permissions that allow EC2 instances to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
AWS Lambda Function with IAM permissions management access level
This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS Lambda Function instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS Lambda Function with IAM policy management permissions
This policy identifies IAM permissions that allow Lambda functions to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
AWS Lambda Function with IAM write access level
This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS Lambda Function instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS Lambda Function with IAM write permissions
This policy identifies IAM permissions that allow Lambda functions to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
AWS Lambda Function with org write access level
This policy identifies org write access that is defined as risky permissions. Ensure that the AWS Lambda Function instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS Lambda Function with AWS Organization management permissions
This policy identifies IAM permissions that allow Lambda functions to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
Okta User with IAM permissions management access level
This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the Okta Users in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS Okta User with IAM policy management permissions
This policy identifies IAM permissions that allow Okta users to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
Okta User with IAM write access level
This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the Okta Users in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS Okta User with IAM write permissions
This policy identifies IAM permissions that allow Okta users to perform write operations for IAM, such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
Okta User with org write access level
This policy identifies org write access that is defined as risky permissions. Ensure that the Okta Users in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS Okta User with AWS Organization management permissions
This policy identifies IAM permissions that allow Okta users to manage AWS Organizations, such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
ECS Task Definition with IAM permissions management access level
This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS ECS Task Definition instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS ECS Task Definition with IAM policy management permissions
This policy identifies IAM permissions that allow ECS task definitions to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
ECS Task Definition with IAM write access level
This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS ECS Task Definition instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks
AWS ECS Task Definition with IAM write permissions
This policy identifies IAM permissions that allow ECS task definitions to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
ECS Task Definition with org write access level
This policy identifies org write access that is defined as risky permissions. Ensure that the AWS ECS Task Definition instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS ECS Task Definition with AWS Organization management permissions
This policy identifies IAM permissions that allow ECS task definitions to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
IAM User with IAM permissions management access level
This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the IAM Users in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS IAM User with IAM policy management permissions
This policy identifies IAM permissions that allow IAM users to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
IAM User with IAM write access level
This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the IAM Users in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS IAM User with IAM write permissions
This policy identifies IAM permissions that allow IAM users to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
IAM User with org write access level
This policy identifies org write access that is defined as risky permissions. Ensure that the IAM Users in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS IAM User with AWS Organization management permissions
This policy identifies IAM permissions that allow IAM users to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
Elasticbeanstalk Platform with IAM permissions management access level
This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS Elasticbeanstalk Platform instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS Elastic Beanstalk Platform with IAM policy management permissions
This policy identifies IAM permissions that allows an Elastic Beanstalk Platform to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
Elasticbeanstalk Platform with IAM write access level
This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS Elasticbeanstalk Platform instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS Elastic Beanstalk Platform with IAM write permissions
This policy identifies IAM permissions that allows an Elastic Beanstalk Platform to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
Elasticbeanstalk Platform with org write access level
This policy identifies org write access that is defined as risky permissions. Ensure that the AWS Elasticbeanstalk Platform instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.
AWS Elastic Beanstalk Platform with AWS Organization management permissions
This policy identifies IAM permissions that allows an Elastic Beanstalk Platform to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.
New Compliance Benchmarks and Updates
Compliance Benchmark
Description
Support for RBI Compliance Standard
24.1.2
Prisma Cloud now supports the Reserve Bank of India (RBI) compliance standard. This comprehensive framework mandates a proactive stance on cybersecurity, ensuring secure networks and databases, constant protection of customer information, and immediate response plans for security incidents.
You can now view this built-in standard and the associated policies on Compliance > Standards. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.
Support for SEBI Compliance Standard
24.1.2
Prisma Cloud now supports the Securities and Exchange Board of India (SEBI) compliance standard. This regulation lays down the listing obligations of companies that have listed their securities on stock exchanges in India. It also provides for the disclosure requirements that these companies must comply with.
You can now view this built-in standard and the associated policies on Compliance > Standards. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.
Update Policy Mappings for Azure CIS 2.0
24.1.2
The following compliance requirements in Azure CIS 2.0 Level 1 and Azure CIS 2.0 Level 2 are updated with new mappings:
Azure CIS 2.0 Level 1
Database Services
Microsoft Defender
Storage Accounts
Azure CIS 2.0 Level 2
Database Services
Microsoft Defender
Impact— Compliance score can vary as new mappings are introduced.
REST API Updates
Change
Description
New Alerts API
24.1.2
A new Create On Demand Notification endpoint is now available. It allows you to configure and share alert notifications through Email, Jira, or Slack.
New Widget APIs
24.1.2
The following new APIs are added to get the data from some of the widgets used to create custom dashboards:
Get Alerts Count by Resolution Reason - POST api/v1/metrics/alert-count-by-resolution-reason
Get Mean Resolution Time - POST /api/v1/metrics/alert-mean-resolution-time
Unified Vulnerability Explorer API
24.1.2
A new Get Prioritized Vulnerabilities V2 API is now available. It allows to view the top priority vulnerabilities along with the number of assets in which they occur.
Update Policy APIs
24.1.2
The policy APIs now support the following types and subtypes:
Policy types - malware and grayware
Policy subtypes - host and container_image
IAM APIs
24.1.1
Widget APIs
24.1.1
The following new APIs are added to get the data from some of the widgets used to create custom dashboards:
Get Discovered and Secured Resources - POST /adoptionadvisor/api/v2/compute/discovered-secured/trend
Get Vulnerabilities Trend - POST /adoptionadvisor/api/v2/compute/vulnerabilities/trend
Get Assets with Alerts - POST /adoptionadvisor/api/v2/cspm/riskyasset/trend
Unified Vulnerability Explorer APIs
24.1.1
New APIs are available in the Unified Vulnerability Explorer category to get the list of vulnerabilities based on CVE, priority, stage, RQL, and so on. In addition, you have endpoints to get the remediation status and create a remediation request.
Background Job APIs
24.1.1
The following new endpoints are available to get background job reports:
Get Reports Metadata - GET /report-service/api/v1/report
Get Report Metadata by ID - GET /report-service/api/v1/report/:reportId
Get Report Status - GET /report-service/api/v1/report/:reportId/status
Download a Report - GET /report-service/api/v1/report/:reportId/download
Add a New Collection
24.1.1
Collections that were added using the Add a New Collection did not display as expected in the Console. This issue has been resolved by making all request body fields, except name, optional. Any field that is not provided will default to the wildcard value '*'.
Deprecation Notices
Change
Description
End of Life (EOL) for Prisma Cloud Microsegmentation in 24.1.2
24.1.2
EOL was first announced in 23.9.2
The Prisma Cloud Microsegmentation module was announced as End-of-Sale effective 31 August, 2022. As of the 24.1.2 release, the Microsegmentation solution is disconnected and any active agents will no longer work.
Make sure to uninstall all instances of the Enforcer (the Microsegmentation agent) deployed in your environment, as these agents will no longer enforce any security policies on traffic on or across your hosts.
app.sg Stack Decommissioned for Prisma Cloud Data Security
Secure the Infrastructure
24.1.1
You will no longer be able to use the app.sg stack for Data Security since it’s being decommissioned. If you want to use Data Security, contact your Prisma Cloud customer support representative.
Support for BridgecrewCLI
Secure the Source
24.1.1
BridgecrewCLI including GitHub Action, CircleCI Orb, and container have been deprecated. You can continue using Checkov and its compatible plugins without any disruptions.
Alerts
Secure the Runtime
24.1.1
Deprecated the AccountID and Cluster macros used in alerts. This removes the AccountID and Cluster fields in the following alerts using the macros.
Webhook
AWS SQS
Prisma Cortex Alert
Splunk
Last updated
Was this helpful?

