Features Introduced in November 2024
Learn what’s new on Prisma® Cloud in November 2024.
Announcement
Prisma Cloud will use the following additional NAT IP addresses on the Google Cloud for the respective Prisma Cloud Enterprise Edition (SaaS) regions.
The following table lists the regions and the additional reserved Ingress IP addresses.
Region
Additional Ingress IP Addresses
us-east1
34.23.229.147
34.74.93.165
35.185.127.202
us-west1
34.19.57.46
34.83.186.93
34.168.3.165
northamerica-northeast1
34.118.176.160
34.47.2.35
europe-west9
34.163.241.103
34.163.12.56
europe-west3
35.198.174.6
34.141.93.246
34.141.89.174
34.141.2.56
35.198.185.51
europe-west2
34.142.29.59
34.89.33.47
australia-southeast1
34.116.88.189
35.189.14.189
asia-southeast1
35.186.153.185
34.87.100.14
asia-south1
34.93.124.157
34.47.154.73
asia-northeast1
35.187.195.198
34.85.99.145
New Features
Feature
Description
Scanning Support for Red Hat UBI Micro-images
Secure the Runtime
33.02.134
Prisma Cloud now supports scanning of Red Hat UBI micro-images (versions 7, 8, and 9).
Improved Vulnerability Detection for non-RPM OpenShift Packages
Secure the Runtime
33.02.134
Vulnerability reports for OpenShift non-RPM container components now ensure consistent vulnerability matching across all OpenShift packages.
This improvement reduces false positives by applying only relevant CVEs and excluding CVEs that have already been patched.
Improved Vulnerability Detection for Google Kubernetes Engine (GKE) Clusters
Secure the Runtime
33.02.134
Vulnerability detection for Google Kubernetes Engine (GKE) Clusters includes the following enhancements:
Integration with Google security bulletins
Aligning CVEs with specific GKE cluster types and versions
Expanded support for all GKE modes, including Autopilot
Refresh Option Available Post Cloud Account Onboarding
Secure the Infrastructure
24.11.1
Enhancements to Prisma Cloud’s onboarding workflow allow you to retry the onboarding of accounts and associated capabilities. Select Home > Settings > Providers > Cloud Accounts and click on the Status of the cloud account you want to refresh. Select Refresh in the Status window to reload components and refresh the status of your onboarded account.

Update Count of Login Failure Messages Displayed Increased from 5 to 10
Secure the Infrastructure
24.11.1
Previously, the SSO configuration page listed the 5 most recent login failures for both OIDC and SAML. The number of messages listed at the bottom of the SSO configuration page has been increased and now displays up to the last 10 login failure error messages for both OIDC and SAML.


Update Highest CVE Score and Severity in the Vulnerability Preview Card
Secure the Infrastructure
24.11.1
The Most Important Vulnerabilities widget now displays the highest score and Severity associated with the CVE ID in the vulnerability CVE preview card.

Permission Groups View Permission
All Prisma Cloud users can now view the Permission Groups associated with their active Role. Additionally, a PermissionGroups:View permission is added that allows you to view all Permission Groups in a tenant when it’s granted via the Permission Group associated with your active Role.
Changes in Existing Behavior
Feature
Description
Audit Logs Pagination and Filter
The Audit Logs include enhancements to improve performance, reduce data load times, and provide more granular control over data retrieval:
The Audit Logs page displays paginated data, which enhances navigation through extensive logs and the filtering options provide you with more control over your log data.
Use the new POST /audit/api/v1/log endpoint to programmatically leverage the new pagination and filter capabilities to streamline your use cases.
Governance Dashboard and Policy Endpoint Updates
A new filter option for Asset Type is available on the Governance page, which allows you to filter the policy list based on the type of asset associated with the policy.
The GET /v2/policy endpoint has a new resource.type query parameter to enable filtering the policy list by asset type. The response also includes the resource.type to indicate the Asset Type associated with each returned policy.
The CSV download from the Governance page also includes a new Asset Type column.
Google Kubernetes Engine
The JSON resource attributes isMasterVersionSupported and isNodeVersionSupported for gcloud-container-describe-clusters API are updated to align with the CSP GetServerConfig API. This change provides accurate results for policy violation alerts related to the default policies— GCP GKE unsupported Master node version and GCP GKE unsupported node version.
Impact— No impact on existing alerts. New alerts will be generated against policy violations based on the complete GKE version used for clusters and nodes. If you have custom policies, you must manually update them to receive the alerts.
AWS Identity Store User Count Updates
Prisma Cloud no longer ingests AWS Identity Store users that are visible to, but not owned by, AWS accounts. Only users directly owned by an AWS account will be ingested.
Impact: Any existing alerts for AWS Identity Store users in accounts that do not own the respective Identity Stores will be automatically closed.
API Ingestions
Service
API Details
AWS Systems Manager
aws-ssm-patch-baseline
Additional permissions required:
ssm:DescribePatchBaselinesssm:GetPatchBaseline
The Security Audit role includes the above permissions.
Amazon MSK
aws-msk-vpc-connection
Additional permissions required:
kafka:ListVpcConnectionskafka:DescribeVpcConnections
The Security Audit role includes the above permissions.
AWS Service Catalog
aws-servicecatalog-portfolio-share
Additional permissions required:
servicecatalog:ListPortfoliosservicecatalog:DescribePortfolioShares
The Security Audit role does not include the above permissions.
Amazon AppStream 2.0
aws-app-stream-image
Additional permission required:
appstream:DescribeImages
The Security Audit role does not include the above permission.
Amazon AppStream 2.0
aws-app-stream-image-builder
Additional permission required:
appstream:DescribeImageBuilders
The Security Audit role does not include the above permission.
AWS Lake Formation
aws-lake-formation-lf-tags
Additional permissions required:
lakeformation:ListLFTagslakeformation:GetLFTag
The Security Audit role does not include the above permissions.
AWS Lake Formation
aws-lake-formation-resource
Additional permissions required:
lakeformation:DescribeResourcelakeformation:ListResources
The Security Audit role does not include the above permissions.
AWS Lake Formation
aws-lake-formation-permission
Additional permission required:
lakeformation:ListPermissions
The Security Audit role does not include the above permission.
AWS Lake Formation
aws-lake-formation-identity-center-configuration
Additional permissions required:
lakeformation:DescribeLakeFormationIdentityCenterConfigurationsso:DescribeApplication
The Security Audit role does not include the above permissions.
AWS KMS
aws-kms-grant
Additional permissions required:
kms:ListKeyskms:ListGrants
The Security Audit role includes the above permissions.
AWS Glue
aws-glue-trigger
Additional permission required:
glue:GetTriggers
The Security Audit role does not include the above permission.
Amazon ECR
aws-ecr-public-registry
Additional permissions required:
ecr-public:DescribeRegistriesecr-public:GetRegistryCatalogData
The Security Audit role includes the ecr-public:DescribeRegistries permission.
The Security Audit role does not include the ecr-public:GetRegistryCatalogData permission.
Amazon Comprehend
aws-comprehend-flywheel
Additional permissions required:
comprehend:ListFlywheelscomprehend:DescribeFlywheelcomprehend:ListTagsForResource
The Security Audit role includes the above permissions.
AWS Elastic Disaster Recovery
aws-drs-source-network
Additional permission required:
drs:DescribeSourceNetworks
The Security Audit role does not include the above permission.
AWS Control Tower
aws-controltower-landing-zone
Additional permissions required:
controltower:ListLandingZonescontroltower:GetLandingZonecontroltower:ListTagsForResource
The Security Audit role does not include the above permissions.
Amazon DataZone
aws-datazone-domain
Additional permissions required:
datazone:ListDomainsdatazone:GetDomain
The Security Audit role does not include the above permissions.
Amazon QuickSight
aws-quicksight-ip-restriction
Additional permission required:
quicksight:DescribeIpRestriction
The Security Audit role includes the above permission.
Amazon Cognito
aws-cognito-user-pool
This API has been updated to include the following new field in the resource JSON:
mfaConfiguration
AWS Signer
aws-signer-signing-job
Additional permissions required:
signer:ListSigningJobssigner:DescribeSigningJob
The Security Audit role does not includes the above permissions.
AWS Fault Injection Service
aws-fis-experiment
Additional permissions required:
fis:ListExperimentsfis:GetExperiment
The Security Audit role does not include the above permissions.
AWS CodeDeploy
aws-code-deploy-deployment-instance
Additional permissions required:
codedeploy:ListDeploymentscodedeploy:ListDeploymentTargetscodedeploy:BatchGetDeploymentTargets
The Security Audit role includes the above permissions.
Amazon DataZone
aws-datazone-data-source
Additional permissions required:
datazone:ListDomainsdatazone:ListProjectsdatazone:ListDataSourcesdatazone:GetDataSource
The Security Audit role includes the above permissions.
Amazon EC2
aws-ec2-reserved-instance
Additional permission required:
ec2:DescribeReservedInstances
The Security Audit role includes the above permission.
Amazon DocumentDB
aws-docdb-db-instance
Additional permissions required:
rds:DescribeDBInstancesrds:ListTagsForResource
The Security Audit role includes the above permissions.
Amazon EventBridge
aws-events-api-destination
Additional permission required:
events:ListApiDestinations
The Security Audit role includes the above permission.
Azure Network Watcher
azure-network-watcher-flowlogs
Additional permissions required:
Microsoft.Network/networkWatchers/readMicrosoft.Network/networkWatchers/configureFlowLog/action
Azure Monitor
azure-monitor-workspaces
Additional permission required:
microsoft.monitor/accounts/read
The Reader role includes the above permissions.
Azure Automation Accounts
azure-automation-account-hybrid-runbook-worker-groups
Additional permissions required:
Microsoft.Automation/automationAccounts/readMicrosoft.Automation/automationAccounts/hybridRunbookWorkerGroups/read
The Reader role includes the above permissions.
Azure Automation Accounts
azure-automation-account-runbooks
Additional permissions required:
Microsoft.Automation/automationAccounts/readMicrosoft.Automation/automationAccounts/runbooks/read
The Reader role includes the above permissions.
Azure Automation Accounts
azure-automation-account-credentials
Additional permissions required:
Microsoft.Automation/automationAccounts/readMicrosoft.Automation/automationAccounts/credentials/read
The Reader role includes the above permissions.
Azure Event Grid
azure-event-grid-topic-diagnostic-settings
Additional permissions required:
Microsoft.EventGrid/topics/readMicrosoft.Insights/DiagnosticSettings/Read
The Reader role includes the above permissions.
Azure Kusto
azure-kusto-clusters-diagnostic-settings
Additional permissions required:
Microsoft.Kusto/clusters/readMicrosoft.Insights/DiagnosticSettings/Read
The Reader role includes the above permissions.
Azure Synapse Analytics
azure-synapse-workspace-sql-pools-geo-backup-policies
Additional permissions required:
Microsoft.Synapse/workspaces/readMicrosoft.Synapse/workspaces/sqlPools/readMicrosoft.Synapse/workspaces/sqlPools/geoBackupPolicies/read
The Reader role includes the above permissions.
Azure Database for PostgreSQL
azure-postgresql-flexible-server-database
Additional permissions required:
Microsoft.DBforPostgreSQL/flexibleServers/readMicrosoft.DBforPostgreSQL/flexibleServers/databases/read
The Reader role includes the above permissions.
Azure Database for MySQL
azure-mysql-flexible-server-database
Additional permissions required:
Microsoft.DBforMySQL/flexibleServers/readMicrosoft.DBforMySQL/flexibleServers/databases/read
The Reader role includes the above permissions.
Azure SQL Database
azure-sql-db-data-masking-policies
Additional permissions required:
Microsoft.Sql/servers/readMicrosoft.Sql/servers/databases/readMicrosoft.Sql/servers/databases/dataMaskingPolicies/read
The Reader role includes the above permissions.
Azure SQL Database
azure-sql-db-transparent-data-encryption
Additional permissions required:
Microsoft.Sql/managedInstances/readMicrosoft.Sql/managedInstances/databases/readMicrosoft.Sql/managedInstances/databases/transparentDataEncryption/read
The Reader role includes the above permissions.
Azure SQL Database
azure-sql-db-data-masking-rules
Additional permissions required:
Microsoft.Sql/servers/readMicrosoft.Sql/servers/databases/readMicrosoft.Sql/servers/databases/dataMaskingPolicies/rules/read
The Reader role includes the above permissions.
Azure API Management Services
azure-api-management-service-identity-provider
Additional permissions required:
Microsoft.ApiManagement/service/readMicrosoft.ApiManagement/service/identityProviders/read
The Reader role includes the above permissions.
Azure API Management Services
azure-api-management-service-alert-rules
Additional permission required:
Microsoft.Insights/MetricAlerts/Read
The Reader role includes the above permission.
Azure API Management Services
azure-api-management-service-products
Additional permissions required:
Microsoft.ApiManagement/service/readMicrosoft.ApiManagement/service/products/read
The Reader role includes the above permissions.
Azure API Management Services
azure-api-management-service-api-policy
Additional permissions required:
Microsoft.ApiManagement/service/readMicrosoft.ApiManagement/service/apis/readMicrosoft.ApiManagement/service/apis/policies/read
The Reader role includes the above permissions.
Azure API Management Services
azure-api-management-service-product-policy
Additional permissions required:
Microsoft.ApiManagement/service/readMicrosoft.ApiManagement/service/products/readMicrosoft.ApiManagement/service/products/policies/read
The Reader role includes the above permissions.
Azure API Management Services
azure-api-management-service-api-diagnostics
Additional permissions required:
Microsoft.ApiManagement/service/readMicrosoft.ApiManagement/service/apis/diagnostics/read
The Reader role includes the above permissions.
Update Azure Active Directory
azure-active-directory-authentication-methods-registration-campaign
The required permission has been updated from Policy.ReadWrite.AuthenticationMethod to Policy.Read.All.
The Reader role includes the Policy.Read.All permission.
Google Cloud VM Looker
gcloud-cloud-looker-instance
Additional permissions required:
looker.instances.listlooker.instances.get
The Viewer role includes the above permissions.
Google Cloud VM Manager
gcloud-vm-manager-patch-deployment
Additional permission required:
osconfig.patchDeployments.list
The Viewer role includes the above permission.
Google Cloud VM Manager
gcloud-vm-manager-feature-settings
Additional permission required:
osconfig.projectFeatureSettings.get
The Viewer role includes the above permission.
Google Cloud Dataflow
gcloud-dataflow-job
Additional permission required:
dataflow.jobs.list
The Viewer role includes the above permission.
This API will only ingest active jobs (those jobs that are currently in a running state). It will not ingest terminated jobs (those jobs that are in terminal states such as, failed or cancelled).
Google Cloud Dataflow Data Pipeline
gcloud-dataflow-data-pipeline
Additional permission required:
datapipelines.pipelines.list
The Viewer role includes the above permission.
Google Cloud Memorystore
gcloud-redis-cluster
Additional permission required:
redis.clusters.list
The Viewer role includes the above permission.
Google Cloud Storage
gcloud-storage-hmac-key
Additional permission required:
storage.hmacKeys.list
The Viewer role includes the above permission.
Google Service Infrastructure Service Management
gcloud-service-management-managed-service
Additional permissions required:
servicemanagement.services.listservicemanagement.services.getIamPolicyservicemanagement.services.get
The Service Management Administrator role includes the above permissions.
Google Cloud SQL
gcloud-sql-instance-database
Additional permissions required:
cloudsql.instances.listcloudsql.databases.list
The Viewer role includes the above permissions.
Google Cloud SQL
gcloud-sql-instance-backup-run
Additional permissions required:
cloudsql.instances.listcloudsql.backupRuns.list
The Viewer role includes the above permissions.
Google API Gateway
gcloud-apigateway-api
Additional permissions required:
apigateway.apis.listapigateway.apis.getIamPolicy
The Viewer role includes the above permissions.
Google Bigquery Reservation
gcloud-bigquery-reservation
Additional permission required:
bigquery.reservations.list
The Viewer role includes the above permission.
Google Bigquery Reservation
gcloud-bigquery-reservation-assignment
Additional permissions required:
bigquery.reservations.listbigquery.reservationAssignments.list
The Viewer role includes the above permissions.
Google Bigquery Reservation
gcloud-bigquery-reservation-bi-engine-reservation
Additional permission required:
bigquery.bireservations.get
The Viewer role includes the above permission.
Google API Gateway
gcloud-apigateway-api-config
Additional permissions required:
apigateway.apis.listapigateway.apiconfigs.list
The Viewer role includes the above permissions.
Google Cloud IAM
gcloud-organization-iam-workforce-pool
Additional permissions required:
iam.googleapis.com/workforcePools.getIamPolicyiam.googleapis.com/workforcePools.list
The Viewer role includes the above permissions.
Google Cloud IAM
gcloud-organization-iam-workforce-pool-provider
Additional permissions required:
iam.googleapis.com/workforcePools.listiam.googleapis.com/workforcePoolProviders.list
The Viewer role includes the above permissions.
Google Integration Connectors
gcloud-integration-connectors-connection
Additional permissions required:
connectors.locations.listconnectors.connections.listconnectors.connections.getIamPolicy
The Viewer role includes the above permission.
Google Integration Connectors
gcloud-integration-connectors-managed-zone
Additional permission required:
connectors.managedZones.list
The Viewer role includes the above permission.
Google Integration Connectors
gcloud-integration-connectors-provider
Additional permission required:
connectors.providers.list
The Viewer role includes the above permission.
Google App Engine
gcloud-app-engine-authorized-certificate
Additional permission required:
appengine.applications.get
The Viewer role includes the above permission.
OCI Object Storage
oci-object-storage-preauthenticated-requests
Additional permissions required:
OBJECTSTORAGE_NAMESPACE_READBUCKET_INSPECTBUCKET_READ
The Reader role includes the above permissions.
OCI Vaults
oci-vault-secrets
Additional permission required:
SECRET_INSPECT
The Reader role includes the above permission.
OCI Block Storage
oci-block-storage-volume-attachment
Additional permission required:
VOLUME_ATTACHMENT_INSPECTVOLUME_ATTACHMENT_READ
OCI Data Safe
oci-data-safe-configuration
Additional permission required:
DATA_SAFE_READ
New Policies
Policies
Description
Azure VM disk configured with public network access
This policy identifies Azure Virtual Machine disks that are configured with public network access.
Allowing public access to Azure Virtual Machine disk resources increases the risk of unauthorized access and potential security breaches. Public network access exposes sensitive data to external threats, which attackers could exploit to compromise VM disks. Disabling public access and using Azure Private Link reduces exposure, ensuring only trusted networks have access and enhancing the security of your Azure environment by minimizing the risk of data leaks and breaches.
As a security best practice, it is recommended to disable public network access for Azure Virtual Machine disks.
Policy Severity— High
Policy Type— Config
RQL—
Azure Microsoft Defender for Cloud set to Off for Agentless container vulnerability assessment
This policy identifies Azure Microsoft Defender for Cloud where the Agentless container vulnerability assessment is set to Off.
Agentless container vulnerability assessment enables automatic scanning for vulnerabilities in container images stored in Azure Container Registry or running in Azure Kubernetes Service without additional agents. Disabling it exposes container images to unpatched security issues and misconfigurations, risking exploitation and data breaches. Enabling agentless container vulnerability assessment ensures continuous scanning for known vulnerabilities, enhancing security by proactively identifying risks and providing remediation suggestions to maintain compliance with industry standards.
As a security best practice, it is recommended to enable Agentless container vulnerability assessment in Azure Microsoft Defender for Cloud.
Policy Severity— Informational
Policy Type— Config
RQL—
Azure Microsoft Defender for Cloud set to Off for File Integrity Monitoring
This policy identifies Azure Microsoft Defender for Cloud where the File Integrity Monitoring is set to Off.
File Integrity Monitoring tracks critical system files in Windows and Linux for unauthorized changes, helping to identify potential attacks. Disabling File Integrity Monitoring leaves your system vulnerable to unnoticed alterations, increasing the risk of data breaches or system failures. Enabling FIM enhances security by alerting you to suspicious changes, allowing for proactive threat detection and prevention of unauthorized modifications to system files.
As a security best practice, it is recommended to enable File Integrity Monitoring in Azure Microsoft Defender for Cloud.
Policy Severity— Informational
Policy Type— Config
RQL—
Azure Microsoft Defender for Cloud set to Off for Agentless scanning for machines
This policy identifies Azure Microsoft Defender for Cloud where the Agentless scanning for machines is set to Off.
Agentless scanning uses disk snapshots to detect installed software, vulnerabilities, and plain text secrets without needing agents on each machine. When disabled, your environment risks exposure to software vulnerabilities and unauthorized software, diminishing visibility into security issues. Enabling Agentless scanning improves security by identifying vulnerabilities and sensitive data with minimal performance impact, streamlining management and ensuring strong threat detection and compliance.
As a security best practice, it is recommended to enable Agentless scanning for machines in Azure Microsoft Defender for Cloud.
Policy Severity— Informational
Policy Type— Config
RQL—
Azure Machine Learning workspace Storage account Datastore using Account key based authentication
This policy identifies Azure Machine Learning workspace datastores that use storage account keys for authentication.
Account key-based authentication is a security risk because it grants full, unrestricted access to the storage account, including the ability to read, write, and delete all data. If compromised, attackers can control all data in the account. This method lacks permission granularity and time limits, increasing the risk of exposing sensitive information. Using SAS tokens provides more granular control, allowing you to limit access to specific resources and set time-bound access, which enhances security and reduces risks in production environments.
As a security best practice, it is recommended to use SAS tokens for authenticating Azure Machine Learning datastores.
Policy Severity— Medium
Policy Type— Config
RQL—
Azure Machine Learning workspace not configured with user-assigned managed identity
This policy identifies Azure Machine Learning workspaces that are not configured with a user-assigned managed identity.
By default, Azure Machine Learning workspaces use system-assigned managed identities to access resources like Azure Container Registry, Key Vault, Storage, and Application Insights. However, user-assigned managed identities offer better control over the identity’s lifecycle and consistent access management across multiple resources. Since system-assigned identities are tied to the workspace and deleted if the workspace is removed, using a user-assigned identity allows access management independently, enhancing security and compliance.
As a security best practice, it is recommended to configure the Azure Machine Learning workspace with a user-assigned managed identity.
Policy Severity— Informational
Policy Type— Config
RQL—
GCP BigQuery Table not encrypted with CMEK
This policy identifies GCP BigQuery Tables that are not encrypted with CMEK.
Customer Managed Encryption Keys (CMEK) for a BigQuery Tables provide control over the encryption of data at rest. Encrypting BigQuery Tables with CMEK enhances security by giving you full control over encryption keys. This ensures data protection, especially for sensitive models and predictions. CMEK allows key rotation and revocation, aligning with compliance requirements and offering better data privacy management.
It is recommended to use CMEK for BigQuery Tables encryption.
Policy Severity— Low
Policy Type— Config
RQL—
GCP VM instance used by Vertex AI Workbench Instance
This policy identifies GCP VM instances used by Vertex AI Workbench.
Vertex AI Workbench relies on GCP Compute Engine VM instances for backend processing. The selection of the appropriate VM instance type, size, and configuration directly impacts the performance and security of the Workbench. Proper configuration of these VM instances is critical to ensuring the security of the associated Vertex AI environment.
It is recommended to regularly identify and assess the VM instances supporting Vertex AI Workbench to maintain a strong security posture and ensure compliance with best practices.
Policy Severity— Informational
Policy Type— Config
RQL—
GCP Vertex AI Endpoint not encrypted with CMEK
This policy identifies GCP Vertex AI Endpoints that are not encrypted with CMEK.
Customer Managed Encryption Keys (CMEK) for a Vertex AI Endpoint provide control over the encryption of data at rest. Encrypting GCP Vertex AI Endpoints with CMEK enhances security by giving you full control over encryption keys. This ensures data protection, especially for sensitive models and predictions. CMEK allows key rotation and revocation, aligning with compliance requirements and offering better data privacy management.
It is recommended to use CMEK for Vertex AI Endpoint encryption.
Policy Severity— Low
Policy Type— Config
RQL—
OCI Load balancer not configured with Web application firewall (WAF)
This policy identifies OCI Load balancers that are not configured with a Web application firewall (WAF).
A Web Application Firewall (WAF) helps protect web applications by filtering and monitoring HTTP traffic between a web application and the Internet. Without WAF, load balancers are vulnerable to various web-based attacks, including SQL injection, cross-site scripting (XSS), and other common exploits. This can lead to unauthorized access, data breaches, and other security incidents.
As a best practice, it is recommended to configure Web Application Firewall (WAF) for OCI Load Balancers to enhance security.
Policy Severity— Medium
Policy Type— Config
RQL—
IAM Policies
The following OOTB IAM policies are newly added.
Policy Name
Description
RQL
Cloud
Policy Severity
VM/Serverless can impersonate an Entra ID application with read access to Microsoft 365 files/Outlook mail
This policy identifies Azure virtual machines or serverless services with a managed identity attached that can impersonate an App Registration using the 'Create Credentials' or 'Change Ownership' features. These App Registrations, accessed via the managed identity, are granted Graph API permissions allowing read access to Microsoft 365 files or Outlook mail.
Azure
High
System/User-assigned managed identity with critical Entra ID permissions
This policy detects Azure system-assigned and user-assigned managed identities that are granted critical Graph API permissions or assigned roles containing high-privilege Entra ID permissions. These permissions, such as the ability to create or modify critical resources, may lead to potential privilege escalation or data exfiltration risks.
Azure
High
Policy Updates
Policy Updates
Description
AWS KMS Key policy overly permissive
The RQL is updated to consider the effect field, which also defines whether the Key policy is overly permissive.
Current RQL
Updated RQL
Policy Type— Config
Policy Severity— Medium
Impact— Low
Alerts Impact— Open alerts where the key policy contains effect as Deny will be resolved.
AWS MFA not enabled for IAM users
The RQL is updated to exclude alerting for root users.
Current RQL
Updated RQL
Policy Type— Config
Policy Severity— Low
Impact— Low
Alerts Impact— Open alerts for root users will be resolved.
Azure DNS Zone having dangling DNS Record vulnerable to subdomain takeover associated with Web App Service
The policy that flags Azure DNS zones with dangling DNS records is updated. This change prevents false positives for stopped resources and ensures only genuine vulnerabilities are flagged.
Current RQL
Updated RQL
Policy Type— Config
Policy Severity— High
Impact— Low
Alerts Impact— Reduced number of alerts since existing false positives are resolved as Policy Updated.
Azure Logic App configured with public network access
The RQL is updated to avoid false positives in case the Logic App has public access disabled using default behavior with a private endpoint configured.
Current RQL
Updated RQL
Policy Type— Config
Policy Severity— Medium
Impact— Low
Alerts Impact— Open alerts on the Logic App have public access disabled using default behavior with a private endpoint configured will be resolved.
GCP SQL Instances do not have valid SSL configuration
Current Policy Description
This policy identifies GCP SQL instances that do not have valid SSL configuration with an unexpired SSL certificate. Cloud SQL supports connecting to an instance using the Secure Socket Layer (SSL) protocol. If Cloud SQL Auth proxy is not used for authentication, it is recommended to utilize SSL for connection to SQL Instance, ensuring the security for data in transit.
Updated Policy Description
This policy identifies GCP SQL instances that either lack SSL configuration or have SSL certificates that have expired.
If an SQL instance is not configured to use SSL, it may accept unencrypted and insecure connections, leading to potential risks such as data interception and authentication vulnerabilities.
It is a best practice to enable SSL configuration to ensure data security and integrity when communicating with a GCP SQL instance.
Current Policy RQL
Updated Policy RQL
Policy Type— Config
Policy Severity— Low
Impact— Low
Alerts Impact— Alerts will be triggered in case the SQL instance is configured with SSL mode as ALLOW_UNENCRYPTED_AND_ENCRYPTED or TRUSTED_CLIENT_CERTIFICATE_REQUIRED with expired certificate.
Open Alerts will be resolved in case the SQL instance is configured with SSL mode as ENCRYPTED_ONLY or TRUSTED_CLIENT_CERTIFICATE_REQUIRED with valid certificate.
IAM Policy Updates
The policy Severity levels for the following IAM policies will be adjusted to better align with the potential risks they pose.
Impact— If your alert rules use the Policy Severity filter, you may notice a slight change in the number of alerts. However, this change will not affect custom policies or policies where you have manually set the severity levels. For policies included in alert rules that are not based on severity, the number of alerts will remain unchanged.
If you have any questions, reach out to your Prisma Cloud Customer Success Representative.
Policy Name
Current Severity
Updated Severity
AWS IAM effective permissions are over-privileged (7 days)
Low
Informational
AWS IAM User with AWS Organization management permissions
Low
Informational
AWS IAM User with IAM policy management permissions
High
Informational
AWS IAM User with IAM write permissions
Low
Informational
AWS Okta User with AWS Organization management permissions
Low
Informational
AWS Okta User with IAM write permissions
Low
Informational
Azure AD user with the Azure built-in roles of Contributor
High
Informational
Azure AD user with the Azure built-in roles of Owner
High
Informational
Azure AD user with the Azure built-in roles of Reader
Low
Informational
Azure AD users with broad Key Vault access through Built-in Azure roles
High
Informational
Azure AD users with broad Key Vault management access
Critical
Informational
Azure entities with risky permissions
Low
Informational
Azure IAM effective permissions are over-privileged (7 days)
Low
Informational
Azure Managed Identity (user assigned or system assigned) with broad Key Vault access through Built-in Azure roles
High
Informational
Azure Managed Identity (user assigned or system assigned) with broad Key Vault management access
High
Informational
Azure Managed Identity (user assigned or system assigned) with the Azure built-in roles of Contributor
High
Informational
Azure Managed Identity (user assigned or system assigned) with the Azure built-in roles of Owner
High
Informational
Azure Managed Identity (user assigned or system assigned) with the Azure built-in roles of Reader
Low
Informational
Azure Service Principals with broad Key Vault access through Built-in Azure roles
High
Informational
Azure Service Principals with broad Key Vault management access
Low
Informational
GCP IAM effective permissions are over-privileged (7 days)
Low
Informational
GCP service accounts with permissions to deploy new resources
High
Informational
GCP User with IAM write access level permissions
Low
Informational
GCP users with permissions to deploy new resources
High
Informational
GCP users with Service Account Token Creator role
High
Informational
Okta user with effective permissions to create AWS IAM users
Low
Informational
AWS EC2 instance with data destruction permissions
High
Low
AWS EC2 instance with privilege escalation risk permissions
High
Low
AWS Lateral Movement to Data Services Through Redshift Cluster Creation
High
Low
AWS Okta User with IAM policy management permissions
High
Low
Azure AD user with effective permissions to create AWS IAM users
High
Low
Azure VM associated with entities that have risky permissions
High
Low
GCP App Engine Web Service Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation
High
Low
GCP App Engine Web Service Assigned Cloud Function IAM Policy Edit Permissions Which Could Lead to Privilege Escalation
High
Low
GCP App Engine Web Service Assigned Cloud Run Creation Which Could Lead to Privilege Escalation
High
Low
GCP App Engine Web Service Assigned Cloud Run IAM Policy Edit Permissions Which Could Lead to Privilege Escalation
High
Low
GCP App Engine Web Service Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation
High
Low
GCP App Engine Web Service Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation
High
Low
GCP Cloud Run Instance Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation
High
Low
GCP Cloud Run Instance Assigned Cloud Function IAM Policy Edit Permissions Which Could Lead to Privilege Escalation
High
Low
GCP Cloud Run Instance Assigned Cloud Run Creation Which Could Lead to Privilege Escalation
High
Low
GCP Cloud Run Instance Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation
High
Low
GCP Cloud Run Instance Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation
High
Low
GCP Cloud Run Job Public Execution via Default Compute SA Modification
High
Low
GCP Compute Instance (VM/Cloud Function) Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation
High
Low
GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run Creation Permissions Which Could Lead to Privilege Escalation
High
Low
GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run IAM Policy Edit Permissions Which Could Lead to Privilege Escalation
High
Low
GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation
High
Low
GCP Compute Instance (VM/Cloud Function) Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation
High
Low
GCP entities with permissions to impersonate a service account in another project
High
Low
GCP Lateral Access Expansion by Making Cloud Run Publicly Executable
High
Low
Publicly Readable Lambda
Medium
Low
Third-party service account with a Lateral Movement to Data Services Through Redshift Cluster Creation
High
Low
Third-party Service Account With Lateral Movement Through CloudFormation Stack Creation
High
Low
AWS Compute Instance (EC2/Lambda) Assigned CloudFormation Creation Permissions Which Could Lead to Privilege Escalation
High
Medium
AWS Compute Instance (EC2/Lambda) Assigned Glue DevEndpoint Creation Permissions Which Could Lead to Privilege Escalation
High
Medium
AWS Compute Instance (EC2/Lambda) Assigned Lambda Creation Permissions Which Could Lead to Privilege Escalation
High
Medium
AWS Compute Instance (EC2/Lambda) Assigned Permissions to Run EC2 Instances Which Could Lead to Privilege Escalation
High
Medium
AWS EC2 machine with write access permission to resource-based policies
Low
Medium
AWS EC2 with IAM role attached has credentials exposure permissions
Low
Medium
AWS IAM policy allows Privilege escalation via Codestar create project and associate team member permissions
Low
Medium
AWS IAM policy allows Privilege escalation via EC2 describe and SSM list and send command permissions
Low
Medium
AWS IAM policy allows Privilege escalation via EC2 describe and SSM session permissions
Low
Medium
AWS IAM policy allows Privilege escalation via EC2 Instance Connect permissions
Low
Medium
AWS IAM policy allows Privilege escalation via Glue Dev Endpoint permissions
Low
Medium
AWS IAM policy allows Privilege escalation via PassRole & Lambda create & invoke Function permissions
Low
Medium
AWS IAM policy allows Privilege escalation via PassRole & Lambda create Function & add permissions
Low
Medium
AWS IAM policy allows Privilege escalation via PassRole & SageMaker create notebook permissions
Low
Medium
AWS IAM policy allows Privilege escalation via PassRole & SageMaker create processing job permissions
Low
Medium
AWS IAM policy allows Privilege escalation via PassRole & SageMaker create training job permissions
Low
Medium
AWS Lambda Function with data destruction permissions
High
Medium
AWS Lambda with IAM role attached has credentials exposure permissions
Low
Medium
Azure AD user with permissions to manage Azure permissions broadly that was not used in the last 90 days
High
Medium
Azure IAM effective permissions are over-privileged (90 days)
Low
Medium
Azure VM instance associated managed identities with Key Vault management access (data access is not included)
High
Medium
Azure VM instance with data destruction permissions
High
Medium
GCP App Engine Web Service Assigned IAM Role Update Permissions Which Could Lead to Privilege Escalation
High
Medium
GCP App Engine Web Service Assigned Permissions to Edit IAM Policy for Service Accounts Which Could Lead to Privilege Escalation
High
Medium
GCP Cloud Run Instance Assigned Permissions to Retrieve Service Account Tokens Which Could Lead to Privilege Escalation
High
Medium
GCP Compute Engine entities with predefined Admin roles
High
Medium
GCP Compute Instance (VM/Cloud Function) Assigned Permissions to Retrieve Service Account Tokens Which Could Lead to Privilege Escalation
High
Medium
GCP IAM effective permissions are over-privileged (90 days)
Low
Medium
GCP service accounts with 'Editor' role on folder level
High
Medium
GCP service accounts with 'Editor' role on org level
High
Medium
GCP service accounts with 'Owner' role on folder level
High
Medium
GCP service accounts with 'Owner' role on org level
High
Medium
GCP VM instance with data destruction permissions
High
Medium
GCP VM instance with database management write access permissions
Low
Medium
GCP VM instance with permissions to impersonate a service account
High
Medium
AWS EC2 instance with the creation of a new Group with attached policy permission
Critical
High
AWS EC2 instance with the creation of a new Role with attached policy permission
Critical
High
AWS EC2 instance with the creation of a new User with attached policy permission
Critical
High
AWS IAM policy allows access and decrypt Secrets Manager Secrets permissions
Low
High
AWS S3 Bucket with Data Destruction Permissions is Publicly Accessible Through Resource-Based Policies
Low
High
Azure Lateral Movement Through SSH Key Replacement and Managed Identity Exploitation on VM
Medium
High
Azure Lateral Movement via VM Command Execution Leveraging Managed Identity
Medium
High
Cloud Service account with high privileges is inactive for 90 days and is assigned to a resource
Medium
High
Service Account with Cross Cloud Administrative Access
Medium
High
Third-Party Service Account with High Privileges at the Folder or Organization Level
Medium
High
User with Administrative Permissions Has Active Access Keys Which Are Unused Over 90 Days
Medium
High
AWS Role With Administrative Permissions Can Be Assumed By All Users
High
Critical
AWS Secret Manager Secret is Publicly Accessible Through Resource-Based Policies
High
Critical
New Compliance Benchmarks and Updates
Compliance Benchmark
Description
CIS v2.0.0 (OCI) Level 1 and CIS v2.0.0 (OCI) Level 2
New mappings are added to the CIS v2.0.0 (OCI) Level 1 and Level 2 compliance standards for enhanced coverage.
Impact: As new mappings are added, the compliance score may vary.
MITRE ATT&CK v15.1 Cloud IaaS for Enterprise
Prisma Cloud now supports the MITRE ATT&CK v15.1 Cloud IaaS for Enterprise compliance standard. This framework includes Att&ck tactics, techniques, and sub-techniques that attackers can leverage to compromise cloud applications and infrastructure.
You can view this built-in compliance standard and related policies on the Compliance > Standards page. You can generate reports for immediate viewing or downloading, or schedule recurring reports to track this compliance standard over time.
IRDAI
Prisma Cloud now supports Insurance Regulatory and Development Authority of India (IRDAI) compliance framework. It has been introduced to assist organizations in adhering to the regulatory requirements specific to the insurance sector. This framework provides a structured approach for managing compliance risks, ensuring that sensitive information is safeguarded while adapting to changing regulations.
You can view this built-in compliance standard and related policies on the Compliance > Standards page. You can generate reports for immediate viewing or downloading, or schedule recurring reports to continuously monitor compliance with the IRDAI framework over time.
NIST 800-53 Rev 5
New mappings are added to the NIST 800-53 Rev 5 compliance standards.
Impact: As new mappings are added, the compliance score may vary.
REST API Updates
Change
Description
Data Security Posture Management API Documentation
Secure the Data
24.11.1
Prisma Cloud Data Security Posture Management (DSPM) API documentation is now available on the Prisma Cloud API documentation site.
Asset Relationship Type Management APIs
Secure the Infrastructure
24.11.1
The following Asset Relationship Type Management (RTM) APIs are introduced to list Prisma Cloud asset relationship type and definitions:
New Settings APIs
Secure the Infrastructure
24.11.1
The following new endpoints are added to the Settings APIs:
Deprecation Notice
Change
Description
Vulnerabilities Dashboard API
Secure the Infrastructure
24.11.1
The following Vulnerabilities Dashboard API endpoints are deprecated as of this release:
Use the replacement endpoint Get CVE Details by ID V3 instead.
Last updated
Was this helpful?

