> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-november-2024.md).

# Features Introduced in November 2024

Learn what’s new on Prisma® Cloud in November 2024.

* [Announcement](#announcement)
* [New Features](#new-features)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [IAM Policies](#iam-policies)
* [Policy Updates](#policy-updates)
* [IAM Policy Updates](#iam-policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)
* [Deprecation Notice](#deprecation-notice)

## Announcement

Prisma Cloud will use the following additional NAT IP addresses on the Google Cloud for the respective Prisma Cloud Enterprise Edition (SaaS) regions.

The following table lists the regions and the additional reserved Ingress IP addresses.

| **Region**              | **Additional Ingress IP Addresses**                                                                                  |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------- |
| us-east1                | <ul><li>34.23.229.147</li><li>34.74.93.165</li><li>35.185.127.202</li></ul>                                          |
| us-west1                | <ul><li>34.19.57.46</li><li>34.83.186.93</li><li>34.168.3.165</li></ul>                                              |
| northamerica-northeast1 | <ul><li>34.118.176.160</li><li>34.47.2.35</li></ul>                                                                  |
| europe-west9            | <ul><li>34.163.241.103</li><li>34.163.12.56</li></ul>                                                                |
| europe-west3            | <ul><li>35.198.174.6</li><li>34.141.93.246</li><li>34.141.89.174</li><li>34.141.2.56</li><li>35.198.185.51</li></ul> |
| europe-west2            | <ul><li>34.142.29.59</li><li>34.89.33.47</li></ul>                                                                   |
| australia-southeast1    | <ul><li>34.116.88.189</li><li>35.189.14.189</li></ul>                                                                |
| asia-southeast1         | <ul><li>35.186.153.185</li><li>34.87.100.14</li></ul>                                                                |
| asia-south1             | <ul><li>34.93.124.157</li><li>34.47.154.73</li></ul>                                                                 |
| asia-northeast1         | <ul><li>35.187.195.198</li><li>34.85.99.145</li></ul>                                                                |

## New Features

| **Feature**                                                                                                                                                                                                                                                                             | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Scanning Support for Red Hat UBI Micro-images</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">33.02.134</mark></p>                                                                              | Prisma Cloud now supports scanning of Red Hat UBI micro-images (versions 7, 8, and 9).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Improved Vulnerability Detection for non-RPM OpenShift Packages</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">33.02.134</mark></p>                                                            | <p>Vulnerability reports for OpenShift non-RPM container components now ensure consistent vulnerability matching across all OpenShift packages.</p><p>This improvement reduces false positives by applying only relevant CVEs and excluding CVEs that have already been patched.</p>                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Improved Vulnerability Detection for Google Kubernetes Engine (GKE) Clusters</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">33.02.134</mark></p>                                               | <p>Vulnerability detection for Google Kubernetes Engine (GKE) Clusters includes the following enhancements:</p><ul><li>Integration with Google security bulletins</li><li>Aligning CVEs with specific GKE cluster types and versions</li><li>Expanded support for all GKE modes, including Autopilot</li></ul>                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Refresh Option Available Post Cloud Account Onboarding</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.11.1</mark></p>                                                                | <p>Enhancements to Prisma Cloud’s onboarding workflow allow you to retry the onboarding of accounts and associated capabilities. Select <strong>Home > Settings > Providers > Cloud Accounts</strong> and click on the <strong>Status</strong> of the cloud account you want to refresh. Select <strong>Refresh</strong> in the Status window to reload components and <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/connect/connect-cloud-accounts/onboard-aws/onboard-aws-account#:~:text=If%20you%20encounter%20an%20issue">refresh the status</a> of your onboarded account.</p><p><img src="/files/puHubVeU0WDCXRgVUhTl" alt="" data-size="original"></p> |
| <p><mark style="background-color:orange;">Update</mark> <strong>Count of Login Failure Messages Displayed Increased from 5 to 10</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.11.1</mark></p> | <p>Previously, the <strong>SSO</strong> configuration page listed the 5 most recent login failures for both <strong>OIDC</strong> and <strong>SAML</strong>. The number of messages listed at the bottom of the SSO configuration page has been increased and now displays up to the last <strong>10</strong> login failure error messages for both <strong>OIDC</strong> and <strong>SAML</strong>.</p><p><img src="/files/OfHJ8nH9xGCZRMmas06Z" alt="" data-size="original"></p><p><img src="/files/MbaBh0FMLCiWkCanIUlZ" alt="" data-size="original"></p>                                                                                                                                    |
| <p><mark style="background-color:orange;">Update</mark> <strong>Highest CVE Score and Severity in the Vulnerability Preview Card</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.11.1</mark></p> | <p>The <strong>Most Important Vulnerabilities</strong> widget now displays the highest score and <strong>Severity</strong> associated with the CVE ID in the vulnerability CVE preview card.</p><p><img src="/files/n6eb1bfEGskos6V7hIad" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Permission Groups View Permission**                                                                                                                                                                                                                                                   | All Prisma Cloud users can now view the **Permission Groups** associated with their active Role. Additionally, a `PermissionGroups:View` permission is added that allows you to view all **Permission Groups** in a tenant when it’s granted via the Permission Group associated with your active Role.                                                                                                                                                                                                                                                                                                                                                                                         |

## Changes in Existing Behavior

| **Feature**                                          | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ---------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Audit Logs Pagination and Filter**                 | <p>The Audit Logs include enhancements to improve performance, reduce data load times, and provide more granular control over data retrieval:</p><ul><li>The Audit Logs page displays paginated data, which enhances navigation through extensive logs and the filtering options provide you with more control over your log data.</li><li>Use the new <a href="https://pan.dev/prisma-cloud/api/cspm/get-audit-logs/">POST /audit/api/v1/log</a> endpoint to programmatically leverage the new pagination and filter capabilities to streamline your use cases.</li></ul>                                                                                                                                                                    |
| **Governance Dashboard and Policy Endpoint Updates** | <p>A new filter option for <strong>Asset Type</strong> is available on the <strong>Governance</strong> page, which allows you to filter the policy list based on the type of asset associated with the policy.</p><p>The <a href="https://pan.dev/prisma-cloud/api/cspm/get-policies-v-2/">GET /v2/policy</a> endpoint has a new <code>resource.type</code> query parameter to enable filtering the policy list by asset type. The response also includes the <code>resource.type</code> to indicate the Asset Type associated with each returned policy.</p><p>The CSV download from the <strong>Governance</strong> page also includes a new <strong>Asset Type</strong> column.</p>                                                        |
| **Google Kubernetes Engine**                         | <p>The JSON resource attributes <code>isMasterVersionSupported</code> and <code>isNodeVersionSupported</code> for <strong>gcloud-container-describe-clusters</strong> API are updated to align with the CSP <strong>GetServerConfig</strong> API. This change provides accurate results for policy violation alerts related to the default policies— <strong>GCP GKE unsupported Master node version</strong> and <strong>GCP GKE unsupported node version</strong>.</p><p><strong>Impact—</strong> No impact on existing alerts. New alerts will be generated against policy violations based on the complete GKE version used for clusters and nodes. If you have custom policies, you must manually update them to receive the alerts.</p> |
| **AWS Identity Store User Count Updates**            | <p>Prisma Cloud no longer ingests AWS Identity Store users that are visible to, but not owned by, AWS accounts. Only users directly owned by an AWS account will be ingested.</p><p><strong>Impact</strong>: Any existing alerts for AWS Identity Store users in accounts that do not own the respective Identity Stores will be automatically closed.</p>                                                                                                                                                                                                                                                                                                                                                                                    |

## API Ingestions

| **Service**                                                                     | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                           |
| ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **AWS Systems Manager**                                                         | <p><strong>aws-ssm-patch-baseline</strong></p><p>Additional permissions required:</p><ul><li><code>ssm:DescribePatchBaselines</code></li><li><code>ssm:GetPatchBaseline</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                                                                                                                    |
| **Amazon MSK**                                                                  | <p><strong>aws-msk-vpc-connection</strong></p><p>Additional permissions required:</p><ul><li><code>kafka:ListVpcConnections</code></li><li><code>kafka:DescribeVpcConnections</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                                                                                                              |
| **AWS Service Catalog**                                                         | <p><strong>aws-servicecatalog-portfolio-share</strong></p><p>Additional permissions required:</p><ul><li><code>servicecatalog:ListPortfolios</code></li><li><code>servicecatalog:DescribePortfolioShares</code></li></ul><p>The Security Audit role does not include the above permissions.</p>                                                                                                                           |
| **Amazon AppStream 2.0**                                                        | <p><strong>aws-app-stream-image</strong></p><p>Additional permission required:</p><ul><li><code>appstream:DescribeImages</code></li></ul><p>The Security Audit role does not include the above permission.</p>                                                                                                                                                                                                            |
| **Amazon AppStream 2.0**                                                        | <p><strong>aws-app-stream-image-builder</strong></p><p>Additional permission required:</p><ul><li><code>appstream:DescribeImageBuilders</code></li></ul><p>The Security Audit role does not include the above permission.</p>                                                                                                                                                                                             |
| **AWS Lake Formation**                                                          | <p><strong>aws-lake-formation-lf-tags</strong></p><p>Additional permissions required:</p><ul><li><code>lakeformation:ListLFTags</code></li><li><code>lakeformation:GetLFTag</code></li></ul><p>The Security Audit role does not include the above permissions.</p>                                                                                                                                                        |
| **AWS Lake Formation**                                                          | <p><strong>aws-lake-formation-resource</strong></p><p>Additional permissions required:</p><ul><li><code>lakeformation:DescribeResource</code></li><li><code>lakeformation:ListResources</code></li></ul><p>The Security Audit role does not include the above permissions.</p>                                                                                                                                            |
| **AWS Lake Formation**                                                          | <p><strong>aws-lake-formation-permission</strong></p><p>Additional permission required:</p><ul><li><code>lakeformation:ListPermissions</code></li></ul><p>The Security Audit role does not include the above permission.</p>                                                                                                                                                                                              |
| **AWS Lake Formation**                                                          | <p><strong>aws-lake-formation-identity-center-configuration</strong></p><p>Additional permissions required:</p><ul><li><code>lakeformation:DescribeLakeFormationIdentityCenterConfiguration</code></li><li><code>sso:DescribeApplication</code></li></ul><p>The Security Audit role does not include the above permissions.</p>                                                                                           |
| **AWS KMS**                                                                     | <p><strong>aws-kms-grant</strong></p><p>Additional permissions required:</p><ul><li><code>kms:ListKeys</code></li><li><code>kms:ListGrants</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                                                                                                                                                 |
| **AWS Glue**                                                                    | <p><strong>aws-glue-trigger</strong></p><p>Additional permission required:</p><ul><li><code>glue:GetTriggers</code></li></ul><p>The Security Audit role does not include the above permission.</p>                                                                                                                                                                                                                        |
| **Amazon ECR**                                                                  | <p><strong>aws-ecr-public-registry</strong></p><p>Additional permissions required:</p><ul><li><code>ecr-public:DescribeRegistries</code></li><li><code>ecr-public:GetRegistryCatalogData</code></li></ul><p>The Security Audit role includes the <code>ecr-public:DescribeRegistries</code> permission.</p><p>The Security Audit role does not include the <code>ecr-public:GetRegistryCatalogData</code> permission.</p> |
| **Amazon Comprehend**                                                           | <p><strong>aws-comprehend-flywheel</strong></p><p>Additional permissions required:</p><ul><li><code>comprehend:ListFlywheels</code></li><li><code>comprehend:DescribeFlywheel</code></li><li><code>comprehend:ListTagsForResource</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                                                          |
| **AWS Elastic Disaster Recovery**                                               | <p><strong>aws-drs-source-network</strong></p><p>Additional permission required:</p><ul><li><code>drs:DescribeSourceNetworks</code></li></ul><p>The Security Audit role does not include the above permission.</p>                                                                                                                                                                                                        |
| **AWS Control Tower**                                                           | <p><strong>aws-controltower-landing-zone</strong></p><p>Additional permissions required:</p><ul><li><code>controltower:ListLandingZones</code></li><li><code>controltower:GetLandingZone</code></li><li><code>controltower:ListTagsForResource</code></li></ul><p>The Security Audit role does not include the above permissions.</p>                                                                                     |
| **Amazon DataZone**                                                             | <p><strong>aws-datazone-domain</strong></p><p>Additional permissions required:</p><ul><li><code>datazone:ListDomains</code></li><li><code>datazone:GetDomain</code></li></ul><p>The Security Audit role does not include the above permissions.</p>                                                                                                                                                                       |
| **Amazon QuickSight**                                                           | <p><strong>aws-quicksight-ip-restriction</strong></p><p>Additional permission required:</p><ul><li><code>quicksight:DescribeIpRestriction</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                   |
| **Amazon Cognito**                                                              | <p><strong>aws-cognito-user-pool</strong></p><p>This API has been updated to include the following new field in the resource JSON:</p><ul><li><code>mfaConfiguration</code></li></ul>                                                                                                                                                                                                                                     |
| **AWS Signer**                                                                  | <p><strong>aws-signer-signing-job</strong></p><p>Additional permissions required:</p><ul><li><code>signer:ListSigningJobs</code></li><li><code>signer:DescribeSigningJob</code></li></ul><p>The Security Audit role does not includes the above permissions.</p>                                                                                                                                                          |
| **AWS Fault Injection Service**                                                 | <p><strong>aws-fis-experiment</strong></p><p>Additional permissions required:</p><ul><li><code>fis:ListExperiments</code></li><li><code>fis:GetExperiment</code></li></ul><p>The Security Audit role does not include the above permissions.</p>                                                                                                                                                                          |
| **AWS CodeDeploy**                                                              | <p><strong>aws-code-deploy-deployment-instance</strong></p><p>Additional permissions required:</p><ul><li><code>codedeploy:ListDeployments</code></li><li><code>codedeploy:ListDeploymentTargets</code></li><li><code>codedeploy:BatchGetDeploymentTargets</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                                 |
| **Amazon DataZone**                                                             | <p><strong>aws-datazone-data-source</strong></p><p>Additional permissions required:</p><ul><li><code>datazone:ListDomains</code></li><li><code>datazone:ListProjects</code></li><li><code>datazone:ListDataSources</code></li><li><code>datazone:GetDataSource</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                             |
| **Amazon EC2**                                                                  | <p><strong>aws-ec2-reserved-instance</strong></p><p>Additional permission required:</p><ul><li><code>ec2:DescribeReservedInstances</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                          |
| **Amazon DocumentDB**                                                           | <p><strong>aws-docdb-db-instance</strong></p><p>Additional permissions required:</p><ul><li><code>rds:DescribeDBInstances</code></li><li><code>rds:ListTagsForResource</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                                                                                                                     |
| **Amazon EventBridge**                                                          | <p><strong>aws-events-api-destination</strong></p><p>Additional permission required:</p><ul><li><code>events:ListApiDestinations</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                            |
| **Azure Network Watcher**                                                       | <p><strong>azure-network-watcher-flowlogs</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Network/networkWatchers/read</code></li><li><code>Microsoft.Network/networkWatchers/configureFlowLog/action</code></li></ul>                                                                                                                                                                         |
| **Azure Monitor**                                                               | <p><strong>azure-monitor-workspaces</strong></p><p>Additional permission required:</p><ul><li><code>microsoft.monitor/accounts/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                                                                                                                |
| **Azure Automation Accounts**                                                   | <p><strong>azure-automation-account-hybrid-runbook-worker-groups</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Automation/automationAccounts/read</code></li><li><code>Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                         |
| **Azure Automation Accounts**                                                   | <p><strong>azure-automation-account-runbooks</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Automation/automationAccounts/read</code></li><li><code>Microsoft.Automation/automationAccounts/runbooks/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                              |
| **Azure Automation Accounts**                                                   | <p><strong>azure-automation-account-credentials</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Automation/automationAccounts/read</code></li><li><code>Microsoft.Automation/automationAccounts/credentials/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                        |
| **Azure Event Grid**                                                            | <p><strong>azure-event-grid-topic-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.EventGrid/topics/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                             |
| **Azure Kusto**                                                                 | <p><strong>azure-kusto-clusters-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Kusto/clusters/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                                 |
| **Azure Synapse Analytics**                                                     | <p><strong>azure-synapse-workspace-sql-pools-geo-backup-policies</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Synapse/workspaces/read</code></li><li><code>Microsoft.Synapse/workspaces/sqlPools/read</code></li><li><code>Microsoft.Synapse/workspaces/sqlPools/geoBackupPolicies/read</code></li></ul><p>The Reader role includes the above permissions.</p>                              |
| **Azure Database for PostgreSQL**                                               | <p><strong>azure-postgresql-flexible-server-database</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.DBforPostgreSQL/flexibleServers/read</code></li><li><code>Microsoft.DBforPostgreSQL/flexibleServers/databases/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                 |
| **Azure Database for MySQL**                                                    | <p><strong>azure-mysql-flexible-server-database</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.DBforMySQL/flexibleServers/read</code></li><li><code>Microsoft.DBforMySQL/flexibleServers/databases/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                |
| **Azure SQL Database**                                                          | <p><strong>azure-sql-db-data-masking-policies</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Sql/servers/read</code></li><li><code>Microsoft.Sql/servers/databases/read</code></li><li><code>Microsoft.Sql/servers/databases/dataMaskingPolicies/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                  |
| **Azure SQL Database**                                                          | <p><strong>azure-sql-db-transparent-data-encryption</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Sql/managedInstances/read</code></li><li><code>Microsoft.Sql/managedInstances/databases/read</code></li><li><code>Microsoft.Sql/managedInstances/databases/transparentDataEncryption/read</code></li></ul><p>The Reader role includes the above permissions.</p>                           |
| **Azure SQL Database**                                                          | <p><strong>azure-sql-db-data-masking-rules</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Sql/servers/read</code></li><li><code>Microsoft.Sql/servers/databases/read</code></li><li><code>Microsoft.Sql/servers/databases/dataMaskingPolicies/rules/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                               |
| **Azure API Management Services**                                               | <p><strong>azure-api-management-service-identity-provider</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/identityProviders/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                        |
| **Azure API Management Services**                                               | <p><strong>azure-api-management-service-alert-rules</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Insights/MetricAlerts/Read</code></li></ul><p>The Reader role includes the above permission.</p>                                                                                                                                                                                            |
| **Azure API Management Services**                                               | <p><strong>azure-api-management-service-products</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/products/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                          |
| **Azure API Management Services**                                               | <p><strong>azure-api-management-service-api-policy</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/apis/read</code></li><li><code>Microsoft.ApiManagement/service/apis/policies/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                    |
| **Azure API Management Services**                                               | <p><strong>azure-api-management-service-product-policy</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/products/read</code></li><li><code>Microsoft.ApiManagement/service/products/policies/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                        |
| **Azure API Management Services**                                               | <p><strong>azure-api-management-service-api-diagnostics</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/apis/diagnostics/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                           |
| <mark style="background-color:orange;">Update</mark> **Azure Active Directory** | <p><strong>azure-active-directory-authentication-methods-registration-campaign</strong></p><p>The required permission has been updated from <code>Policy.ReadWrite.AuthenticationMethod</code> to <code>Policy.Read.All</code>.</p><p>The Reader role includes the <code>Policy.Read.All</code> permission.</p>                                                                                                           |
| **Google Cloud VM Looker**                                                      | <p><strong>gcloud-cloud-looker-instance</strong></p><p>Additional permissions required:</p><ul><li><code>looker.instances.list</code></li><li><code>looker.instances.get</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                                                                                           |
| **Google Cloud VM Manager**                                                     | <p><strong>gcloud-vm-manager-patch-deployment</strong></p><p>Additional permission required:</p><ul><li><code>osconfig.patchDeployments.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                        |
| **Google Cloud VM Manager**                                                     | <p><strong>gcloud-vm-manager-feature-settings</strong></p><p>Additional permission required:</p><ul><li><code>osconfig.projectFeatureSettings.get</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                   |
| **Google Cloud Dataflow**                                                       | <p><strong>gcloud-dataflow-job</strong></p><p>Additional permission required:</p><ul><li><code>dataflow\.jobs.list</code></li></ul><p>The Viewer role includes the above permission.</p><p>This API will only ingest active jobs (those jobs that are currently in a running state). It will not ingest terminated jobs (those jobs that are in terminal states such as, failed or cancelled).</p>                        |
| **Google Cloud Dataflow Data Pipeline**                                         | <p><strong>gcloud-dataflow-data-pipeline</strong></p><p>Additional permission required:</p><ul><li><code>datapipelines.pipelines.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                               |
| **Google Cloud Memorystore**                                                    | <p><strong>gcloud-redis-cluster</strong></p><p>Additional permission required:</p><ul><li><code>redis.clusters.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                                                 |
| **Google Cloud Storage**                                                        | <p><strong>gcloud-storage-hmac-key</strong></p><p>Additional permission required:</p><ul><li><code>storage.hmacKeys.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                                            |
| **Google Service Infrastructure Service Management**                            | <p><strong>gcloud-service-management-managed-service</strong></p><p>Additional permissions required:</p><ul><li><code>servicemanagement.services.list</code></li><li><code>servicemanagement.services.getIamPolicy</code></li><li><code>servicemanagement.services.get</code></li></ul><p>The Service Management Administrator role includes the above permissions.</p>                                                   |
| **Google Cloud SQL**                                                            | <p><strong>gcloud-sql-instance-database</strong></p><p>Additional permissions required:</p><ul><li><code>cloudsql.instances.list</code></li><li><code>cloudsql.databases.list</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                                                                                      |
| **Google Cloud SQL**                                                            | <p><strong>gcloud-sql-instance-backup-run</strong></p><p>Additional permissions required:</p><ul><li><code>cloudsql.instances.list</code></li><li><code>cloudsql.backupRuns.list</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                                                                                   |
| **Google API Gateway**                                                          | <p><strong>gcloud-apigateway-api</strong></p><p>Additional permissions required:</p><ul><li><code>apigateway.apis.list</code></li><li><code>apigateway.apis.getIamPolicy</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                                                                                           |
| **Google Bigquery Reservation**                                                 | <p><strong>gcloud-bigquery-reservation</strong></p><p>Additional permission required:</p><ul><li><code>bigquery.reservations.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                                   |
| **Google Bigquery Reservation**                                                 | <p><strong>gcloud-bigquery-reservation-assignment</strong></p><p>Additional permissions required:</p><ul><li><code>bigquery.reservations.list</code></li><li><code>bigquery.reservationAssignments.list</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                                                            |
| **Google Bigquery Reservation**                                                 | <p><strong>gcloud-bigquery-reservation-bi-engine-reservation</strong></p><p>Additional permission required:</p><ul><li><code>bigquery.bireservations.get</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                            |
| **Google API Gateway**                                                          | <p><strong>gcloud-apigateway-api-config</strong></p><p>Additional permissions required:</p><ul><li><code>apigateway.apis.list</code></li><li><code>apigateway.apiconfigs.list</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                                                                                      |
| **Google Cloud IAM**                                                            | <p><strong>gcloud-organization-iam-workforce-pool</strong></p><p>Additional permissions required:</p><ul><li><code>iam.googleapis.com/workforcePools.getIamPolicy</code></li><li><code>iam.googleapis.com/workforcePools.list</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                                      |
| **Google Cloud IAM**                                                            | <p><strong>gcloud-organization-iam-workforce-pool-provider</strong></p><p>Additional permissions required:</p><ul><li><code>iam.googleapis.com/workforcePools.list</code></li><li><code>iam.googleapis.com/workforcePoolProviders.list</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                             |
| **Google Integration Connectors**                                               | <p><strong>gcloud-integration-connectors-connection</strong></p><p>Additional permissions required:</p><ul><li><code>connectors.locations.list</code></li><li><code>connectors.connections.list</code></li><li><code>connectors.connections.getIamPolicy</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                            |
| **Google Integration Connectors**                                               | <p><strong>gcloud-integration-connectors-managed-zone</strong></p><p>Additional permission required:</p><ul><li><code>connectors.managedZones.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                  |
| **Google Integration Connectors**                                               | <p><strong>gcloud-integration-connectors-provider</strong></p><p>Additional permission required:</p><ul><li><code>connectors.providers.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                         |
| **Google App Engine**                                                           | <p><strong>gcloud-app-engine-authorized-certificate</strong></p><p>Additional permission required:</p><ul><li><code>appengine.applications.get</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                      |
| **OCI Object Storage**                                                          | <p><strong>oci-object-storage-preauthenticated-requests</strong></p><p>Additional permissions required:</p><ul><li><code>OBJECTSTORAGE\_NAMESPACE\_READ</code></li><li><code>BUCKET\_INSPECT</code></li><li><code>BUCKET\_READ</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                     |
| **OCI Vaults**                                                                  | <p><strong>oci-vault-secrets</strong></p><p>Additional permission required:</p><ul><li><code>SECRET\_INSPECT</code></li></ul><p>The Reader role includes the above permission.</p>                                                                                                                                                                                                                                        |
| **OCI Block Storage**                                                           | <p><strong>oci-block-storage-volume-attachment</strong></p><p>Additional permission required:</p><ul><li><code>VOLUME\_ATTACHMENT\_INSPECT</code></li><li><code>VOLUME\_ATTACHMENT\_READ</code></li></ul>                                                                                                                                                                                                                 |
| **OCI Data Safe**                                                               | <p><strong>oci-data-safe-configuration</strong></p><p>Additional permission required:</p><ul><li><code>DATA\_SAFE\_READ</code></li></ul>                                                                                                                                                                                                                                                                                  |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Azure VM disk configured with public network access</strong></td><td><p>This policy identifies Azure Virtual Machine disks that are configured with public network access.</p><p>Allowing public access to Azure Virtual Machine disk resources increases the risk of unauthorized access and potential security breaches. Public network access exposes sensitive data to external threats, which attackers could exploit to compromise VM disks. Disabling public access and using Azure Private Link reduces exposure, ensuring only trusted networks have access and enhancing the security of your Azure environment by minimizing the risk of data leaks and breaches.</p><p>As a security best practice, it is recommended to disable public network access for Azure Virtual Machine disks.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-disk-list' AND json.rule = publicNetworkAccess equal ignore case Enabled and networkAccessPolicy equal ignore case AllowAll and managedBy contains virtualMachines
</code></pre></td></tr><tr><td><strong>Azure Microsoft Defender for Cloud set to Off for Agentless container vulnerability assessment</strong></td><td><p>This policy identifies Azure Microsoft Defender for Cloud where the Agentless container vulnerability assessment is set to Off.</p><p>Agentless container vulnerability assessment enables automatic scanning for vulnerabilities in container images stored in Azure Container Registry or running in Azure Kubernetes Service without additional agents. Disabling it exposes container images to unpatched security issues and misconfigurations, risking exploitation and data breaches. Enabling agentless container vulnerability assessment ensures continuous scanning for known vulnerabilities, enhancing security by proactively identifying risks and providing remediation suggestions to maintain compliance with industry standards.</p><p>As a security best practice, it is recommended to enable Agentless container vulnerability assessment in Azure Microsoft Defender for Cloud.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = not (pricings[?any(properties.extensions[?any(name equal ignore case ContainerRegistriesVulnerabilityAssessments AND isEnabled is true)] exists AND properties.pricingTier equal ignore case Standard )] exists)
</code></pre></td></tr><tr><td><strong>Azure Microsoft Defender for Cloud set to Off for File Integrity Monitoring</strong></td><td><p>This policy identifies Azure Microsoft Defender for Cloud where the File Integrity Monitoring is set to Off.</p><p>File Integrity Monitoring tracks critical system files in Windows and Linux for unauthorized changes, helping to identify potential attacks. Disabling File Integrity Monitoring leaves your system vulnerable to unnoticed alterations, increasing the risk of data breaches or system failures. Enabling FIM enhances security by alerting you to suspicious changes, allowing for proactive threat detection and prevention of unauthorized modifications to system files.</p><p>As a security best practice, it is recommended to enable File Integrity Monitoring in Azure Microsoft Defender for Cloud.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = not (pricings[?any(properties.extensions[?any(name equal ignore case FileIntegrityMonitoring AND isEnabled is true)] exists AND properties.pricingTier equal ignore case Standard )] exists)
</code></pre></td></tr><tr><td><strong>Azure Microsoft Defender for Cloud set to Off for Agentless scanning for machines</strong></td><td><p>This policy identifies Azure Microsoft Defender for Cloud where the Agentless scanning for machines is set to Off.</p><p>Agentless scanning uses disk snapshots to detect installed software, vulnerabilities, and plain text secrets without needing agents on each machine. When disabled, your environment risks exposure to software vulnerabilities and unauthorized software, diminishing visibility into security issues. Enabling Agentless scanning improves security by identifying vulnerabilities and sensitive data with minimal performance impact, streamlining management and ensuring strong threat detection and compliance.</p><p>As a security best practice, it is recommended to enable Agentless scanning for machines in Azure Microsoft Defender for Cloud.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = not (pricings[?any(properties.extensions[?any(name equal ignore case AgentlessVmScanning AND isEnabled is true)] exists AND properties.pricingTier equal ignore case Standard )] exists)
</code></pre></td></tr><tr><td><strong>Azure Machine Learning workspace Storage account Datastore using Account key based authentication</strong></td><td><p>This policy identifies Azure Machine Learning workspace datastores that use storage account keys for authentication.</p><p>Account key-based authentication is a security risk because it grants full, unrestricted access to the storage account, including the ability to read, write, and delete all data. If compromised, attackers can control all data in the account. This method lacks permission granularity and time limits, increasing the risk of exposing sensitive information. Using SAS tokens provides more granular control, allowing you to limit access to specific resources and set time-bound access, which enhances security and reduces risks in production environments.</p><p>As a security best practice, it is recommended to use SAS tokens for authenticating Azure Machine Learning datastores.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-machine-learning-datastores' AND json.rule = (properties.datastoreType equal ignore case AzureFile or properties.datastoreType equal ignore case AzureBlob) and properties.credentials.credentialsType equal ignore case AccountKey
</code></pre></td></tr><tr><td><strong>Azure Machine Learning workspace not configured with user-assigned managed identity</strong></td><td><p>This policy identifies Azure Machine Learning workspaces that are not configured with a user-assigned managed identity.</p><p>By default, Azure Machine Learning workspaces use system-assigned managed identities to access resources like Azure Container Registry, Key Vault, Storage, and Application Insights. However, user-assigned managed identities offer better control over the identity’s lifecycle and consistent access management across multiple resources. Since system-assigned identities are tied to the workspace and deleted if the workspace is removed, using a user-assigned identity allows access management independently, enhancing security and compliance.</p><p>As a security best practice, it is recommended to configure the Azure Machine Learning workspace with a user-assigned managed identity.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-machine-learning-workspace' AND json.rule = properties.provisioningState equal ignore case Succeeded and identity.type does not contain UserAssigned
</code></pre></td></tr><tr><td><strong>GCP BigQuery Table not encrypted with CMEK</strong></td><td><p>This policy identifies GCP BigQuery Tables that are not encrypted with CMEK.</p><p>Customer Managed Encryption Keys (CMEK) for a BigQuery Tables provide control over the encryption of data at rest. Encrypting BigQuery Tables with CMEK enhances security by giving you full control over encryption keys. This ensures data protection, especially for sensitive models and predictions. CMEK allows key rotation and revocation, aligning with compliance requirements and offering better data privacy management.</p><p>It is recommended to use CMEK for BigQuery Tables encryption.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-bigquery-table' AND json.rule = encryptionConfiguration.kmsKeyName does not exist
</code></pre></td></tr><tr><td><strong>GCP VM instance used by Vertex AI Workbench Instance</strong></td><td><p>This policy identifies GCP VM instances used by Vertex AI Workbench.</p><p>Vertex AI Workbench relies on GCP Compute Engine VM instances for backend processing. The selection of the appropriate VM instance type, size, and configuration directly impacts the performance and security of the Workbench. Proper configuration of these VM instances is critical to ensuring the security of the associated Vertex AI environment.</p><p>It is recommended to regularly identify and assess the VM instances supporting Vertex AI Workbench to maintain a strong security posture and ensure compliance with best practices.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-instances-list' AND json.rule = status equals "RUNNING" as X; config from cloud.resource where api.name = 'gcloud-vertex-ai-workbench-instance' as Y; filter ' $.Y.labels.resource-name equals $.X.labels.resource-name '; show X;
</code></pre></td></tr><tr><td><strong>GCP Vertex AI Endpoint not encrypted with CMEK</strong></td><td><p>This policy identifies GCP Vertex AI Endpoints that are not encrypted with CMEK.</p><p>Customer Managed Encryption Keys (CMEK) for a Vertex AI Endpoint provide control over the encryption of data at rest. Encrypting GCP Vertex AI Endpoints with CMEK enhances security by giving you full control over encryption keys. This ensures data protection, especially for sensitive models and predictions. CMEK allows key rotation and revocation, aligning with compliance requirements and offering better data privacy management.</p><p>It is recommended to use CMEK for Vertex AI Endpoint encryption.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-aiplatform-endpoint' AND json.rule = encryptionSpec.kmsKeyName does not exist
</code></pre></td></tr><tr><td><strong>OCI Load balancer not configured with Web application firewall (WAF)</strong></td><td><p>This policy identifies OCI Load balancers that are not configured with a Web application firewall (WAF).</p><p>A Web Application Firewall (WAF) helps protect web applications by filtering and monitoring HTTP traffic between a web application and the Internet. Without WAF, load balancers are vulnerable to various web-based attacks, including SQL injection, cross-site scripting (XSS), and other common exploits. This can lead to unauthorized access, data breaches, and other security incidents.</p><p>As a best practice, it is recommended to configure Web Application Firewall (WAF) for OCI Load Balancers to enhance security.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'oci-networking-loadbalancer' AND json.rule = listeners.*.protocol equals HTTP and lifecycleState equals ACTIVE and isPrivate is false as X; config from cloud.resource where api.name = 'oci-loadbalancer-waf' AND json.rule = lifecycleState equal ignore case ACTIVE and (webAppFirewallPolicyId exists and webAppFirewallPolicyId does not equal "null") as Y; filter 'not ($.X.id equals $.Y.loadBalancerId) '; show X;
</code></pre></td></tr></tbody></table>

## IAM Policies

The following OOTB IAM policies are newly added.

<table data-header-hidden><thead><tr><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Name</strong></td><td><strong>Description</strong></td><td><strong>RQL</strong></td><td><strong>Cloud</strong></td><td><strong>Policy Severity</strong></td></tr><tr><td><strong>VM/Serverless can impersonate an Entra ID application with read access to Microsoft 365 files/Outlook mail</strong></td><td>This policy identifies Azure virtual machines or serverless services with a managed identity attached that can impersonate an App Registration using the 'Create Credentials' or 'Change Ownership' features. These App Registrations, accessed via the managed identity, are granted Graph API permissions allowing read access to Microsoft 365 files or Outlook mail.</td><td><pre><code>config from iam where source.cloud.type = 'AZURE' AND source.cloud.resource.type in ('virtualMachines','sites','virtualMachineScaleSets/virtualMachines') and grantedby.cloud.entity.type = 'App Registration' and grantedby.cloud.policy.type = 'Microsoft Graph' and action.name in ('Files.Read.All', 'Files.ReadWrite.All','Sites.Read.All','Sites.ReadWrite.All','Sites.FullControl.All','Sites.Selected','Mail.ReadWrite','Mail.Read')
</code></pre></td><td>Azure</td><td>High</td></tr><tr><td><strong>System/User-assigned managed identity with critical Entra ID permissions</strong></td><td>This policy detects Azure system-assigned and user-assigned managed identities that are granted critical Graph API permissions or assigned roles containing high-privilege Entra ID permissions. These permissions, such as the ability to create or modify critical resources, may lead to potential privilege escalation or data exfiltration risks.</td><td><pre><code>config from iam where source.cloud.type = 'AZURE' AND source.cloud.resource.type IN ('System Assigned','User Assigned' ) and action.name in ('Application.ReadWrite.All','Directory.ReadWrite.All','microsoft.directory/applications/owners/update','microsoft.directory/applications/credentials/update','RoleManagement.ReadWrite.Directory','microsoft.directory/groups.security/owners/update','microsoft.directory/groups.security.assignedMembership/members/update','microsoft.directory/groups.security/members/update','microsoft.directory/groups.unified/owners/update','microsoft.directory/groups.unified.assignedMembership/members/update','microsoft.directory/groups.unified/members/update','microsoft.directory/groupsAssignableToRoles/allProperties/update','User.ReadWrite.All','microsoft.directory/users/password/update','AppRoleAssignment.ReadWrite.All','microsoft.directory/servicePrincipals/appRoleAssignedTo/update','microsoft.directory/groups/members/update','microsoft.directory/groups/owners/update','Mail.ReadWrite','Files.ReadWrite.All','Sites.ReadWrite.All','Sites.FullControl.All')
</code></pre></td><td>Azure</td><td>High</td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>AWS KMS Key policy overly permissive</strong></td><td><p>The RQL is updated to consider the <code>effect</code> field, which also defines whether the Key policy is overly permissive.</p><p><strong>Current RQL</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.keyState equals Enabled and policies.default.Statement[?any(Principal.AWS equals * and Condition does not exist)] exists
</code></pre><p><strong>Updated RQL</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.keyState equals Enabled and policies.default.Statement[?any(Principal.AWS equals * and Effect equal ignore case allow and Condition does not exist)] exists
</code></pre><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Impact—</strong> Low</p><p><strong>Alerts Impact—</strong> Open alerts where the key policy contains effect as <code>Deny</code> will be resolved.</p></td></tr><tr><td><strong>AWS MFA not enabled for IAM users</strong></td><td><p>The RQL is updated to exclude alerting for root users.</p><p><strong>Current RQL</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' and api.name='aws-iam-get-credential-report' AND json.rule='password_enabled equals true and mfa_active is false'
</code></pre><p><strong>Updated RQL</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' and api.name='aws-iam-get-credential-report' AND json.rule='user does not equal "&#x3C;root_account>" and password_enabled equals true and mfa_active is false'
</code></pre><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Impact—</strong> Low</p><p><strong>Alerts Impact—</strong> Open alerts for root users will be resolved.</p></td></tr><tr><td><strong>Azure DNS Zone having dangling DNS Record vulnerable to subdomain takeover associated with Web App Service</strong></td><td><p>The policy that flags Azure DNS zones with dangling DNS records is updated. This change prevents false positives for stopped resources and ensures only genuine vulnerabilities are flagged.</p><p><strong>Current RQL</strong></p><pre><code>config from cloud.resource where api.name = 'azure-dns-recordsets' AND json.rule = type contains CNAME and properties.CNAMERecord.cname contains "azurewebsites.net" as X; config from cloud.resource where api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case Running as Y;  filter 'not ($.Y.properties.hostNames contains $.X.properties.CNAMERecord.cname) '; show X;
</code></pre><p><strong>Updated RQL</strong></p><pre><code>config from cloud.resource where api.name = 'azure-dns-recordsets' AND json.rule = type contains CNAME and properties.CNAMERecord.cname contains "azurewebsites.net" as X; config from cloud.resource where api.name = 'azure-app-service' as Y; filter 'not ($.Y.properties.hostNames contains $.X.properties.CNAMERecord.cname) '; show X;
</code></pre><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Severity—</strong> High</p><p><strong>Impact—</strong> Low</p><p><strong>Alerts Impact—</strong> Reduced number of alerts since existing false positives are resolved as <code>Policy Updated</code>.</p></td></tr><tr><td><strong>Azure Logic App configured with public network access</strong></td><td><p>The RQL is updated to avoid false positives in case the Logic App has public access disabled using default behavior with a private endpoint configured.</p><p><strong>Current RQL</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = 'properties.state equal ignore case running and kind contains workflowapp and ((properties.publicNetworkAccess exists and properties.publicNetworkAccess equal ignore case Enabled) or (properties.publicNetworkAccess does not exist)) and config.ipSecurityRestrictions[?any((action equals Allow and ipAddress equals Any) or (action equals Allow and ipAddress equals 0.0.0.0/0))] exists'
</code></pre><p><strong>Updated RQL</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = 'properties.state equal ignore case running and kind contains workflowapp and ((properties.publicNetworkAccess exists and properties.publicNetworkAccess equal ignore case Enabled) or (properties.publicNetworkAccess does not exist and (properties.privateLinkIdentifiers does not exist or properties.privateLinkIdentifiers is empty))) and config.ipSecurityRestrictions[?any((action equals Allow and ipAddress equals Any) or (action equals Allow and ipAddress equals 0.0.0.0/0))] exists'
</code></pre><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Impact—</strong> Low</p><p><strong>Alerts Impact—</strong> Open alerts on the Logic App have public access disabled using default behavior with a private endpoint configured will be resolved.</p></td></tr><tr><td><strong>GCP SQL Instances do not have valid SSL configuration</strong></td><td><p><strong>Current Policy Description</strong></p><p>This policy identifies GCP SQL instances that do not have valid SSL configuration with an unexpired SSL certificate. Cloud SQL supports connecting to an instance using the Secure Socket Layer (SSL) protocol. If Cloud SQL Auth proxy is not used for authentication, it is recommended to utilize SSL for connection to SQL Instance, ensuring the security for data in transit.</p><p><strong>Updated Policy Description</strong></p><p>This policy identifies GCP SQL instances that either lack SSL configuration or have SSL certificates that have expired.</p><p>If an SQL instance is not configured to use SSL, it may accept unencrypted and insecure connections, leading to potential risks such as data interception and authentication vulnerabilities.</p><p>It is a best practice to enable SSL configuration to ensure data security and integrity when communicating with a GCP SQL instance.</p><p><strong>Current Policy RQL</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name='gcloud-sql-instances-list' and json.rule = "(settings.ipConfiguration.requireSsl is true and _DateTime.ageInDays(serverCaCert.expirationTime) > -1) or not (settings.ipConfiguration.requireSsl is true)"
</code></pre><p><strong>Updated Policy RQL</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name='gcloud-sql-instances-list' and json.rule = "(settings.ipConfiguration.sslMode equal ignore case TRUSTED_CLIENT_CERTIFICATE_REQUIRED and _DateTime.ageInDays(serverCaCert.expirationTime) > -1) or settings.ipConfiguration.sslMode equal ignore case ALLOW_UNENCRYPTED_AND_ENCRYPTED"
</code></pre><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Impact—</strong> Low</p><p><strong>Alerts Impact—</strong> Alerts will be triggered in case the SQL instance is configured with SSL mode as ALLOW_UNENCRYPTED_AND_ENCRYPTED or TRUSTED_CLIENT_CERTIFICATE_REQUIRED with expired certificate.</p><p>Open Alerts will be resolved in case the SQL instance is configured with SSL mode as ENCRYPTED_ONLY or TRUSTED_CLIENT_CERTIFICATE_REQUIRED with valid certificate.</p></td></tr></tbody></table>

## IAM Policy Updates

The policy **Severity** levels for the following IAM policies will be adjusted to better align with the potential risks they pose.

**Impact—** If your alert rules use the **Policy Severity** filter, you may notice a slight change in the number of alerts. However, this change will not affect custom policies or policies where you have manually set the severity levels. For policies included in alert rules that are not based on severity, the number of alerts will remain unchanged.

If you have any questions, reach out to your Prisma Cloud Customer Success Representative.

| **Policy Name**                                                                                                                           | **Current Severity** | **Updated Severity** |
| ----------------------------------------------------------------------------------------------------------------------------------------- | -------------------- | -------------------- |
| AWS IAM effective permissions are over-privileged (7 days)                                                                                | Low                  | Informational        |
| AWS IAM User with AWS Organization management permissions                                                                                 | Low                  | Informational        |
| AWS IAM User with IAM policy management permissions                                                                                       | High                 | Informational        |
| AWS IAM User with IAM write permissions                                                                                                   | Low                  | Informational        |
| AWS Okta User with AWS Organization management permissions                                                                                | Low                  | Informational        |
| AWS Okta User with IAM write permissions                                                                                                  | Low                  | Informational        |
| Azure AD user with the Azure built-in roles of Contributor                                                                                | High                 | Informational        |
| Azure AD user with the Azure built-in roles of Owner                                                                                      | High                 | Informational        |
| Azure AD user with the Azure built-in roles of Reader                                                                                     | Low                  | Informational        |
| Azure AD users with broad Key Vault access through Built-in Azure roles                                                                   | High                 | Informational        |
| Azure AD users with broad Key Vault management access                                                                                     | Critical             | Informational        |
| Azure entities with risky permissions                                                                                                     | Low                  | Informational        |
| Azure IAM effective permissions are over-privileged (7 days)                                                                              | Low                  | Informational        |
| Azure Managed Identity (user assigned or system assigned) with broad Key Vault access through Built-in Azure roles                        | High                 | Informational        |
| Azure Managed Identity (user assigned or system assigned) with broad Key Vault management access                                          | High                 | Informational        |
| Azure Managed Identity (user assigned or system assigned) with the Azure built-in roles of Contributor                                    | High                 | Informational        |
| Azure Managed Identity (user assigned or system assigned) with the Azure built-in roles of Owner                                          | High                 | Informational        |
| Azure Managed Identity (user assigned or system assigned) with the Azure built-in roles of Reader                                         | Low                  | Informational        |
| Azure Service Principals with broad Key Vault access through Built-in Azure roles                                                         | High                 | Informational        |
| Azure Service Principals with broad Key Vault management access                                                                           | Low                  | Informational        |
| GCP IAM effective permissions are over-privileged (7 days)                                                                                | Low                  | Informational        |
| GCP service accounts with permissions to deploy new resources                                                                             | High                 | Informational        |
| GCP User with IAM write access level permissions                                                                                          | Low                  | Informational        |
| GCP users with permissions to deploy new resources                                                                                        | High                 | Informational        |
| GCP users with Service Account Token Creator role                                                                                         | High                 | Informational        |
| Okta user with effective permissions to create AWS IAM users                                                                              | Low                  | Informational        |
| AWS EC2 instance with data destruction permissions                                                                                        | High                 | Low                  |
| AWS EC2 instance with privilege escalation risk permissions                                                                               | High                 | Low                  |
| AWS Lateral Movement to Data Services Through Redshift Cluster Creation                                                                   | High                 | Low                  |
| AWS Okta User with IAM policy management permissions                                                                                      | High                 | Low                  |
| Azure AD user with effective permissions to create AWS IAM users                                                                          | High                 | Low                  |
| Azure VM associated with entities that have risky permissions                                                                             | High                 | Low                  |
| GCP App Engine Web Service Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation                          | High                 | Low                  |
| GCP App Engine Web Service Assigned Cloud Function IAM Policy Edit Permissions Which Could Lead to Privilege Escalation                   | High                 | Low                  |
| GCP App Engine Web Service Assigned Cloud Run Creation Which Could Lead to Privilege Escalation                                           | High                 | Low                  |
| GCP App Engine Web Service Assigned Cloud Run IAM Policy Edit Permissions Which Could Lead to Privilege Escalation                        | High                 | Low                  |
| GCP App Engine Web Service Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation                   | High                 | Low                  |
| GCP App Engine Web Service Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation                                 | High                 | Low                  |
| GCP Cloud Run Instance Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation                              | High                 | Low                  |
| GCP Cloud Run Instance Assigned Cloud Function IAM Policy Edit Permissions Which Could Lead to Privilege Escalation                       | High                 | Low                  |
| GCP Cloud Run Instance Assigned Cloud Run Creation Which Could Lead to Privilege Escalation                                               | High                 | Low                  |
| GCP Cloud Run Instance Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation                       | High                 | Low                  |
| GCP Cloud Run Instance Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation                                     | High                 | Low                  |
| GCP Cloud Run Job Public Execution via Default Compute SA Modification                                                                    | High                 | Low                  |
| GCP Compute Instance (VM/Cloud Function) Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation            | High                 | Low                  |
| GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run Creation Permissions Which Could Lead to Privilege Escalation                 | High                 | Low                  |
| GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run IAM Policy Edit Permissions Which Could Lead to Privilege Escalation          | High                 | Low                  |
| GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation     | High                 | Low                  |
| GCP Compute Instance (VM/Cloud Function) Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation                   | High                 | Low                  |
| GCP entities with permissions to impersonate a service account in another project                                                         | High                 | Low                  |
| GCP Lateral Access Expansion by Making Cloud Run Publicly Executable                                                                      | High                 | Low                  |
| Publicly Readable Lambda                                                                                                                  | Medium               | Low                  |
| Third-party service account with a Lateral Movement to Data Services Through Redshift Cluster Creation                                    | High                 | Low                  |
| Third-party Service Account With Lateral Movement Through CloudFormation Stack Creation                                                   | High                 | Low                  |
| AWS Compute Instance (EC2/Lambda) Assigned CloudFormation Creation Permissions Which Could Lead to Privilege Escalation                   | High                 | Medium               |
| AWS Compute Instance (EC2/Lambda) Assigned Glue DevEndpoint Creation Permissions Which Could Lead to Privilege Escalation                 | High                 | Medium               |
| AWS Compute Instance (EC2/Lambda) Assigned Lambda Creation Permissions Which Could Lead to Privilege Escalation                           | High                 | Medium               |
| AWS Compute Instance (EC2/Lambda) Assigned Permissions to Run EC2 Instances Which Could Lead to Privilege Escalation                      | High                 | Medium               |
| AWS EC2 machine with write access permission to resource-based policies                                                                   | Low                  | Medium               |
| AWS EC2 with IAM role attached has credentials exposure permissions                                                                       | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via Codestar create project and associate team member permissions                              | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via EC2 describe and SSM list and send command permissions                                     | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via EC2 describe and SSM session permissions                                                   | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via EC2 Instance Connect permissions                                                           | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via Glue Dev Endpoint permissions                                                              | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via PassRole & Lambda create & invoke Function permissions                                     | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via PassRole & Lambda create Function & add permissions                                        | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via PassRole & SageMaker create notebook permissions                                           | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via PassRole & SageMaker create processing job permissions                                     | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via PassRole & SageMaker create training job permissions                                       | Low                  | Medium               |
| AWS Lambda Function with data destruction permissions                                                                                     | High                 | Medium               |
| AWS Lambda with IAM role attached has credentials exposure permissions                                                                    | Low                  | Medium               |
| Azure AD user with permissions to manage Azure permissions broadly that was not used in the last 90 days                                  | High                 | Medium               |
| Azure IAM effective permissions are over-privileged (90 days)                                                                             | Low                  | Medium               |
| Azure VM instance associated managed identities with Key Vault management access (data access is not included)                            | High                 | Medium               |
| Azure VM instance with data destruction permissions                                                                                       | High                 | Medium               |
| GCP App Engine Web Service Assigned IAM Role Update Permissions Which Could Lead to Privilege Escalation                                  | High                 | Medium               |
| GCP App Engine Web Service Assigned Permissions to Edit IAM Policy for Service Accounts Which Could Lead to Privilege Escalation          | High                 | Medium               |
| GCP Cloud Run Instance Assigned Permissions to Retrieve Service Account Tokens Which Could Lead to Privilege Escalation                   | High                 | Medium               |
| GCP Compute Engine entities with predefined Admin roles                                                                                   | High                 | Medium               |
| GCP Compute Instance (VM/Cloud Function) Assigned Permissions to Retrieve Service Account Tokens Which Could Lead to Privilege Escalation | High                 | Medium               |
| GCP IAM effective permissions are over-privileged (90 days)                                                                               | Low                  | Medium               |
| GCP service accounts with 'Editor' role on folder level                                                                                   | High                 | Medium               |
| GCP service accounts with 'Editor' role on org level                                                                                      | High                 | Medium               |
| GCP service accounts with 'Owner' role on folder level                                                                                    | High                 | Medium               |
| GCP service accounts with 'Owner' role on org level                                                                                       | High                 | Medium               |
| GCP VM instance with data destruction permissions                                                                                         | High                 | Medium               |
| GCP VM instance with database management write access permissions                                                                         | Low                  | Medium               |
| GCP VM instance with permissions to impersonate a service account                                                                         | High                 | Medium               |
| AWS EC2 instance with the creation of a new Group with attached policy permission                                                         | Critical             | High                 |
| AWS EC2 instance with the creation of a new Role with attached policy permission                                                          | Critical             | High                 |
| AWS EC2 instance with the creation of a new User with attached policy permission                                                          | Critical             | High                 |
| AWS IAM policy allows access and decrypt Secrets Manager Secrets permissions                                                              | Low                  | High                 |
| AWS S3 Bucket with Data Destruction Permissions is Publicly Accessible Through Resource-Based Policies                                    | Low                  | High                 |
| Azure Lateral Movement Through SSH Key Replacement and Managed Identity Exploitation on VM                                                | Medium               | High                 |
| Azure Lateral Movement via VM Command Execution Leveraging Managed Identity                                                               | Medium               | High                 |
| Cloud Service account with high privileges is inactive for 90 days and is assigned to a resource                                          | Medium               | High                 |
| Service Account with Cross Cloud Administrative Access                                                                                    | Medium               | High                 |
| Third-Party Service Account with High Privileges at the Folder or Organization Level                                                      | Medium               | High                 |
| User with Administrative Permissions Has Active Access Keys Which Are Unused Over 90 Days                                                 | Medium               | High                 |
| AWS Role With Administrative Permissions Can Be Assumed By All Users                                                                      | High                 | Critical             |
| AWS Secret Manager Secret is Publicly Accessible Through Resource-Based Policies                                                          | High                 | Critical             |

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                  | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| --------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **CIS v2.0.0 (OCI) Level 1 and CIS v2.0.0 (OCI) Level 2** | <p>New mappings are added to the CIS v2.0.0 (OCI) Level 1 and Level 2 compliance standards for enhanced coverage.</p><p><strong>Impact</strong>: As new mappings are added, the compliance score may vary.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **MITRE ATT\&CK v15.1 Cloud IaaS for Enterprise**         | <p>Prisma Cloud now supports the <strong>MITRE ATT\&CK v15.1 Cloud IaaS for Enterprise</strong> compliance standard. This framework includes Att\&ck tactics, techniques, and sub-techniques that attackers can leverage to compromise cloud applications and infrastructure.</p><p>You can view this built-in compliance standard and related policies on the <strong>Compliance > Standards</strong> page. You can generate reports for immediate viewing or downloading, or schedule recurring reports to track this compliance standard over time.</p>                                                                                                                                                                                     |
| **IRDAI**                                                 | <p>Prisma Cloud now supports <strong>Insurance Regulatory and Development Authority of India (IRDAI)</strong> compliance framework. It has been introduced to assist organizations in adhering to the regulatory requirements specific to the insurance sector. This framework provides a structured approach for managing compliance risks, ensuring that sensitive information is safeguarded while adapting to changing regulations.</p><p>You can view this built-in compliance standard and related policies on the <strong>Compliance > Standards</strong> page. You can generate reports for immediate viewing or downloading, or schedule recurring reports to continuously monitor compliance with the IRDAI framework over time.</p> |
| **NIST 800-53 Rev 5**                                     | <p>New mappings are added to the <strong>NIST 800-53 Rev 5</strong> compliance standards.</p><p><strong>Impact</strong>: As new mappings are added, the compliance score may vary.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |

## REST API Updates

| **Change**                                                                                                                                                                                                 | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Data Security Posture Management API Documentation</strong></p><p><mark style="background-color:orange;">Secure the Data</mark></p><p><mark style="background-color:orange;">24.11.1</mark></p> | Prisma Cloud Data Security Posture Management (DSPM) [API documentation](https://pan.dev/prisma-cloud/api/dspm/data-security-posture-management-dspm-apis/) is now available on the Prisma Cloud API documentation [site](https://pan.dev/prisma-cloud/api/).                                                                                                                                                                                      |
| <p><strong>Asset Relationship Type Management APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.11.1</mark></p>  | <p>The following Asset Relationship Type Management (RTM) APIs are introduced to list Prisma Cloud asset relationship type and definitions:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-asset-relationship-type-definitions/">List Asset Relationship Type Definitions</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-asset-relationship-definitions/">List Asset Relationship Definitions</a></li></ul>         |
| <p><strong>New Settings APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.11.1</mark></p>                        | <p>The following new endpoints are added to the <a href="https://pan.dev/prisma-cloud/api/cspm/settings/">Settings APIs</a>:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/add-cluster-info/">Add Satellite Details</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/list-clusters/">List Cluster Details</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/delete-cluster/">Delete Satellite Details</a></li></ul> |

## Deprecation Notice

| **Change**                                                                                                                                                                                      | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Vulnerabilities Dashboard API</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.11.1</mark></p> | <p>The following Vulnerabilities Dashboard API endpoints are deprecated as of this release:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/download-vulnerability-file/">Get CVE Details by ID</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/download-vulnerability-file-v-2/">Get CVE Details by ID V2</a></li></ul><p>Use the replacement endpoint <a href="https://pan.dev/prisma-cloud/api/cspm/download-vulnerability-file-v-3/">Get CVE Details by ID V3</a> instead.</p> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-november-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
