> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2025/features-introduced-in-april-2025.md).

# Features Introduced in April 2025

Learn what’s new on Prisma® Cloud in April 2025.

* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)

## API Ingestions

| **Service**                       | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                    |
| --------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Amazon Lex**                    | <p><strong>aws-lexv2-slots</strong></p><p>Additional permissions required:</p><ul><li><code>lex:GetBots</code></li><li><code>lex:ListBotLocales</code></li><li><code>lex:ListIntents</code></li><li><code>lex:ListSlots</code></li></ul><p>The Security audit role does not include the permissions.</p>                                                                                                                           |
| **Amazon Detective**              | <p><strong>aws-detective-member</strong></p><p>Additional permissions required:</p><ul><li><code>detective:ListGraphs</code></li><li><code>detective:ListMembers</code></li><li><code>detective:GetMembers</code></li></ul><p>The Security audit role includes the <code>detective:ListGraphs</code> and <code>detective:ListMembers</code> permissions but does not include the <code>detective:GetMembers</code> permission.</p> |
| **AWS AppFabric**                 | <p><strong>aws-appfabric-app-bundle</strong></p><p>Additional permissions required:</p><ul><li><code>appfabric:ListAppBundles</code></li><li><code>appfabric:GetAppBundle</code></li><li><code>appfabric:ListTagsForResource</code></li></ul><p>The Security audit role does not include the permissions.</p>                                                                                                                      |
| **AWS AppFabric**                 | <p><strong>aws-appfabric-app-authorization</strong></p><p>Additional permissions required:</p><ul><li><code>appfabric:ListAppBundles</code></li><li><code>appfabric:ListAppAuthorizations</code></li><li><code>appfabric:GetAppAuthorization</code></li><li><code>appfabric:ListTagsForResource</code></li></ul><p>The Security audit role does not include the permissions.</p>                                                   |
| **AWS Organizations**             | <p><strong>aws-organizations-aws-service-access-for-organization</strong></p><p>Additional permission required:</p><ul><li><code>organizations:ListAWSServiceAccessForOrganization</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                         |
| **AWS Organizations**             | <p><strong>aws-organizations-delegated-services-for-account</strong></p><p>Additional permission required:</p><ul><li><code>organizations:ListDelegatedServicesForAccount</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                  |
| **Amazon Keyspaces**              | <p><strong>aws-keyspaces-table</strong></p><p>Additional permission required:</p><ul><li><code>cassandra:Select</code></li></ul><p>The Security audit role does not include the permission.</p>                                                                                                                                                                                                                                    |
| **Amazon QuickSight**             | <p><strong>aws-quicksight-iam-policy-assignment</strong></p><p>Additional permissions required:</p><ul><li><code>quicksight:DescribeIAMPolicyAssignment</code></li><li><code>quicksight:ListNamespaces</code></li><li><code>quicksight:ListIAMPolicyAssignments</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                           |
| **Azure Log Analytics**           | <p><strong>azure-log-analytics-data-exports</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.OperationalInsights/workspaces/read</code></li><li><code>Microsoft.OperationalInsights/workspaces/dataexports/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                         |
| **Azure Arc**                     | <p><strong>azure-arc-machine-license-profile</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.HybridCompute/machines/read</code></li><li><code>Microsoft.HybridCompute/machines/licenseProfiles/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                    |
| **Azure Arc**                     | <p><strong>azure-arc-machine</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.HybridCompute/machines/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                 |
| **Azure Arc**                     | <p><strong>azure-arc-private-link-scope</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.HybridCompute/privateLinkScopes/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                             |
| **Azure Arc**                     | <p><strong>azure-arc-license</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.HybridCompute/licenses/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                 |
| **Azure App Service**             | <p><strong>azure-app-service-certificate-order</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.CertificateRegistration/certificateOrders/Read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                            |
| **Azure API Management Services** | <p><strong>azure-api-management-service-private-endpoint-connection</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/privateEndpointConnections/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                    |
| **Azure API Management Services** | <p><strong>azure-api-management-service-cache</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/caches/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                              |
| **Azure Event Grid**              | <p><strong>azure-event-grid-topic-event-subscription</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.EventGrid/topics/read</code></li><li><code>Microsoft.EventGrid/topics/eventSubscriptions/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                     |
| **Azure Event Grid**              | <p><strong>azure-event-grid-domain-event-subscription</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.EventGrid/domains/read</code></li><li><code>Microsoft.EventGrid/domains/eventSubscriptions/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                  |
| **Google Backup and DR**          | <p><strong>gcloud-backup-dr-backup-vault-data-source-backup</strong></p><p>Additional permissions required:</p><ul><li><code>backupdr.backupVaults.list</code></li><li><code>backupdr.bvdataSources.list</code></li><li><code>backupdr.bvbackups.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                             |
| **Google Backup and DR**          | <p><strong>gcloud-backup-dr-backup-vault-data-source</strong></p><p>Additional permissions required:</p><ul><li><code>backupdr.backupVaults.list</code></li><li><code>backupdr.bvdataSources.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                 |
| **Google Backup and DR**          | <p><strong>gcloud-backup-dr-backup-vault</strong></p><p>Additional permission required:</p><ul><li><code>backupdr.backupVaults.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                |
| **Google Backup and DR**          | <p><strong>gcloud-backup-dr-backup-plan-association</strong></p><p>Additional permission required:</p><ul><li><code>backupdr.backupPlanAssociations.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                           |
| **Google Backup and DR**          | <p><strong>gcloud-backup-dr-backup-plan</strong></p><p>Additional permission required:</p><ul><li><code>backupdr.backupPlans.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                  |
| **OCI IAM**                       | <p><strong>oci-iam-user-db-credential</strong></p><p>Additional permissions required:</p><ul><li><code>USER\_INSPECT</code></li><li><code>DB\_CREDENTIAL\_INSPECT</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                 |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>AWS Lightsail Instance allows ingress from the internet</strong></td><td><p><strong>Policy Description—</strong> Unrestricted internet ingress to AWS Lightsail instances exposes them to unauthorized access. This misconfiguration leaves instances vulnerable to various attacks.</p><p>AWS Lightsail instances use a built-in firewall to control inbound traffic. By default, or through misconfiguration, all ports might be open to the internet. This allows attackers to easily scan for open ports and exploit known vulnerabilities, leading to instance compromise and data breaches. Attackers can launch brute-force attacks against common services like SSH, potentially gaining full control.</p><p>The impact of this misconfiguration includes data exfiltration, unauthorized modification of instance resources, and potential use as a stepping stone for further attacks within the cloud environment. Limiting access to only trusted IP addresses is crucial for minimizing the attack surface and preventing unauthorized access.</p><p>Implement a least privilege approach. Configure the Lightsail instance’s firewall to allow only necessary ports and specific trusted IP addresses. Regularly review and update firewall rules to remove any unnecessary access and mitigate the risk of unauthorized connections. Monitor logs for suspicious activity.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-lightsail-instance' AND json.rule = state.name contains "running" and networking.ports[?any( accessDirection equals inbound and (cidrs contains "0.0.0.0/0" or ipv6Cidrs contains "::/0"))] exists`
</code></pre></td></tr><tr><td><strong>AWS Lightsail Instance not configured with Instance Metadata Service v2 (IMDSv2)</strong></td><td><p><strong>Policy Description—</strong> AWS Lightsail instances lacking Instance Metadata Service version 2 (IMDSv2) configuration pose a significant security risk. Instances without IMDSv2 are vulnerable to unauthorized access to sensitive metadata, potentially leading to data breaches or server compromise.</p><p>The Instance Metadata Service provides metadata about the instance, including details like instance ID, security credentials, and private IP address. Without IMDSv2’s session authentication, attackers could exploit misconfigurations or vulnerabilities in other services (like misconfigured firewalls or reverse proxies) to access this sensitive information. This access can facilitate lateral movement within an environment or enable unauthorized actions on the instance.</p><p>Failure to enforce IMDSv2 exposes the instance to various attack vectors, resulting in data exfiltration, privilege escalation, and complete system compromise. Employing IMDSv2 ensures requests are authenticated, thereby mitigating these risks and protecting sensitive data.</p><p>To remediate this misconfiguration, explicitly enable IMDSv2 for all AWS Lightsail instances. This can typically be accomplished through the AWS console or CLI, configuring the instance settings. Regularly audit your instances to ensure consistent IMDSv2 implementation across your environment.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-lightsail-instance' AND json.rule = metadataOptions exists and metadataOptions.httpTokens equal ignore case optional`
</code></pre></td></tr><tr><td><strong>GCP AlloyDB Cluster instance allows direct unencrypted connection</strong></td><td><p><strong>Policy Description—</strong> GCP AlloyDB Cluster instances permitting unencrypted connections pose a significant security risk, exposing sensitive data in transit to eavesdropping and unauthorized access.</p><p>The AlloyDB service allows both encrypted and unencrypted connections by default if SSL is not explicitly enabled. Disabling SSL introduces a major security risk, as all communication with the database instance occurs in plain text. Attackers can intercept this data easily, potentially leading to data breaches and unauthorized database modifications.</p><p>A misconfiguration allowing unencrypted connections exposes sensitive data, impacting confidentiality and integrity. Enabling SSL is crucial to protect data in transit, ensuring only authorized users with properly authenticated connections can access the database. This practice aligns with industry best practices for securing database communication.</p><p>To mitigate this, enforce SSL encryption on all AlloyDB Cluster instances. Configure the instance to only accept encrypted connections. Regularly audit configurations to ensure SSL remains enabled and verify all connections utilize SSL encryption.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'gcp' and api.name = 'gcloud-alloydb-cluster-instance' AND json.rule = state equal ignore case ready and clientConnectionConfig.sslConfig.sslMode equal ignore case ALLOW_UNENCRYPTED_AND_ENCRYPTED`
</code></pre></td></tr><tr><td><strong>GCP AlloyDB instance with IAM authentication disabled</strong></td><td><p><strong>Policy Description—</strong> GCP AlloyDB instances lacking IAM authentication are susceptible to unauthorized access. Disabling IAM authentication relies solely on database passwords for access, increasing the risk of breaches via password compromise or leaks.</p><p>AlloyDB’s IAM authentication integrates with Google Cloud’s Identity and Access Management system, enabling granular control over database access. Without IAM, security relies on password management alone, which is vulnerable to brute-force attacks, phishing, or weak password policies. This misconfiguration exposes sensitive data within the database to unauthorized individuals or malicious actors.</p><p>The impact of this misconfiguration includes data breaches, unauthorized database modifications, and potential service disruptions. Enabling IAM authentication provides a more secure authentication method by leveraging the robust security features of GCP’s IAM system, minimizing the risk of unauthorized access and improving overall security posture.</p><p>To mitigate this, ensure IAM authentication is enabled on all AlloyDB instances. Regularly review and update IAM permissions to ensure only authorized users and service accounts have access. Implement strong password policies and multi-factor authentication (MFA) for all database users, even when IAM authentication is enabled, as an additional layer of security.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'gcp' and api.name = 'gcloud-alloydb-cluster-instance' AND json.rule = (['databaseFlags'].['alloydb.iam_authentication'] does not exist or ['databaseFlags'].['alloydb.iam_authentication'] does not equal ignore case on)`
</code></pre></td></tr><tr><td><strong>GCP AlloyDB Instance with insecure password policy</strong></td><td><p><strong>Policy Description—</strong> Insecure password policies on GCP AlloyDB instances allow unauthorized access. Weak or easily guessable passwords increase the risk of database compromise.</p><p>GCP AlloyDB instances utilize password-based authentication. A weak password policy increases the likelihood of brute-force or credential stuffing attacks leading to data breaches and unauthorized modifications. Failure to enforce strong passwords exposes the database to significant security risks.</p><p>Compromised AlloyDB instances can result in data exfiltration, service disruption, and financial losses. Enforcing a robust password policy significantly reduces the risk of unauthorized access by requiring complex and regularly updated passwords.</p><p>Implement a strong password policy for all AlloyDB instances. Ensure 'password.enforce_complexity', 'password.enforce_expiration', and 'password.enforce_password_does_not_contain_username' are set to 'on'. 'password.expiration_in_days' should be less than 90, 'password.min_pass_length' greater than or equal to 10, and 'password.min_uppercase_letters' and 'password.min_numerical_chars' should be at least 1. Regularly review and update password policies.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-alloydb-cluster-instance' AND json.rule = (['databaseFlags'].['password.enforce_complexity'] does not exist or ['databaseFlags'].['password.enforce_complexity'] does not equal ignore case on) or (['databaseFlags'].['password.enforce_expiration'] does not exist or ['databaseFlags'].['password.enforce_expiration'] does not equal ignore case on) or (['databaseFlags'].['password.expiration_in_days'] does not exist or ['databaseFlags'].['password.expiration_in_days'] > 90) or (['databaseFlags'].['password.min_uppercase_letters'] does not exist or ['databaseFlags'].['password.min_uppercase_letters'] &#x3C; 1) or (['databaseFlags'].['password.min_numerical_chars'] does not exist or ['databaseFlags'].['password.min_numerical_chars'] &#x3C; 1) or (['databaseFlags'].['password.min_pass_length'] does not exist or ['databaseFlags'].['password.min_pass_length'] &#x3C; 10) or (['databaseFlags'].['password.enforce_password_does_not_contain_username'] does not exist or ['databaseFlags'].['password.enforce_password_does_not_contain_username'] does not equal ignore case on)`
</code></pre></td></tr><tr><td><strong>GCP AlloyDB Cluster’s Continuous Backup not encrypted with CMEK</strong></td><td><p><strong>Policy Description—</strong> GCP AlloyDB clusters lacking CMEK encryption for continuous backups expose sensitive data to unauthorized access.</p><p>AlloyDB’s continuous backup feature, enabled by default, creates cluster backups. Without CMEK encryption, these backups are protected by Google-managed keys, reducing organizational control over sensitive data. Attackers gaining access to Google’s infrastructure could potentially decrypt and exfiltrate this data.</p><p>A data breach resulting from this misconfiguration could lead to significant financial losses, regulatory penalties, and reputational damage. Encrypting backups with CMEK ensures only authorized users with access to the customer-managed encryption keys can decrypt and access the data, aligning with data security best practices and minimizing the impact of potential breaches.</p><p>To mitigate this risk, enable CMEK encryption for all AlloyDB cluster continuous backups. Regularly review and audit CMEK key management practices to ensure ongoing protection. Implement strong access controls to restrict access to the CMEK keys.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-alloydb-cluster' AND json.rule = continuousBackupInfo.encryptionInfo.encryptionType equal ignore case GOOGLE_DEFAULT_ENCRYPTION`
</code></pre></td></tr><tr><td><strong>GCP Dataproc Serverless Batch is using default network</strong></td><td><p><strong>Policy Description—</strong> GCP Dataproc Serverless Batch instances are deployed on the default network, exposing them to unnecessary risks. This misconfiguration increases the attack surface and compromises security posture.</p><p>The default network lacks granular control over network traffic and resource isolation. It offers broad access between resources, allowing unauthorized communication between Dataproc instances and other GCP services or external entities. This can lead to data breaches, unauthorized access to sensitive data, and lateral movement within the GCP environment.</p><p>This misconfiguration significantly impacts the organization’s security and compliance posture. A compromised Dataproc Serverless Batch instance could lead to data loss, service disruption, and reputational damage. Implementing a custom Virtual Private Cloud (VPC) network with appropriate firewall rules and subnets is crucial for enhancing security and mitigating risks.</p><p>To remediate this, use a custom VPC network for Dataproc Serverless Batch. Configure appropriate firewall rules to restrict inbound and outbound traffic to only necessary services and IP addresses. Segment your network using subnets to isolate resources and enhance security. Utilize private Google Access for secure communication with Google services.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-dataproc-serverless-batch' AND json.rule = state is member of ("PENDING", "RUNNING") and ( environmentConfig.executionConfig.networkUri ends with "default" or environmentConfig.executionConfig.subnetworkUri ends with "default")`
</code></pre></td></tr><tr><td><strong>GCP Dataproc Serverless Session template is using default network</strong></td><td><p><strong>Policy Description—</strong> GDataproc Serverless session templates utilizing the default network in GCP pose a significant security risk. The default network lacks the necessary security controls and isolation for production workloads, increasing the attack surface.</p><p>GCP’s default network offers broad access between resources, enabling unauthorized communication between instances. This lack of segmentation and inherent misconfiguration increases the risk of data breaches and lateral movement if an attacker compromises a single instance. Without customized firewall rules and network policies, the default network’s open nature is easily exploited.</p><p>The impact of this misconfiguration is substantial, potentially leading to unauthorized data access, system compromise, and significant business disruption. Implementing a custom Virtual Private Cloud (VPC) network with tailored firewall rules and appropriate subnet segmentation is crucial for mitigating these risks. This provides better control over network traffic, access, and resource isolation.</p><p>To remediate this issue, use a custom VPC network and migrate Dataproc Serverless session templates to this new network. Implement appropriate firewall rules to restrict access to only authorized IP addresses and services. Segment the network using subnets to further isolate resources and enforce the principle of least privilege. Regularly review and update network configurations to maintain security posture.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-dataproc-serverless-session-template' AND json.rule = environmentConfig.executionConfig.networkUri ends with "default" or environmentConfig.executionConfig.subnetworkUri ends with "default"`
</code></pre></td></tr><tr><td><strong>GCP Dataproc Serverless Session is using default network</strong></td><td><p><strong>Policy Description—</strong> Dataproc Serverless sessions using the default network in GCP pose a significant security risk. This misconfiguration exposes resources to unintended network access and lacks essential security controls.</p><p>The default network in GCP provides broad, unrestricted access between all instances. This lack of network segmentation allows unauthorized communication between sensitive and non-sensitive workloads. An attacker exploiting a misconfigured application within one instance could easily pivot to other instances within the default network. This lack of isolation dramatically increases the attack surface and the potential for data breaches or system compromises.</p><p>The impact of this misconfiguration includes data breaches, unauthorized access to sensitive information, and compromised application integrity. Employing a custom VPC with appropriate firewall rules and network segmentation ensures that only authorized traffic can access resources. This practice enhances security posture and reduces the likelihood of successful attacks.</p><p>To mitigate this risk, use a custom Virtual Private Cloud (VPC) network for Dataproc Serverless. Configure appropriate firewall rules to restrict inbound and outbound network traffic to only authorized sources and destinations. Implement network segmentation by creating subnets for different workloads, further limiting the impact of potential breaches.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-dataproc-serverless-session' AND json.rule = state is member of ("CREATING", "ACTIVE") and ( environmentConfig.executionConfig.networkUri ends with "default" or environmentConfig.executionConfig.subnetworkUri ends with "default")`
</code></pre></td></tr><tr><td><strong>GCP Dataproc Cluster on GKE is using default network</strong></td><td><p><strong>Policy Description—</strong> Dataproc clusters on Google Kubernetes Engine (GKE) using the default network in GCP pose a significant security risk. This misconfiguration allows broad, unrestricted communication between all instances within the default network, bypassing necessary security controls.</p><p>The default network lacks essential security features like segmentation and fine-grained control over network traffic. It offers no inherent isolation between different workloads, increasing the risk of lateral movement and data breaches. Attackers could exploit this lack of isolation to compromise multiple systems, potentially accessing sensitive data or disrupting operations.</p><p>The impact of this misconfiguration is far-reaching. It increases the attack surface, exposes sensitive data to unauthorized access, and hinders compliance efforts. A custom Virtual Private Cloud (VPC) provides robust security through subnets, firewall rules, and improved network segmentation, mitigating these risks. Implementing these controls enhances security posture and reduces the likelihood of successful attacks.</p><p>To remediate this, use a custom VPC network with appropriately configured subnets and firewall rules. Restrict traffic flow between resources based on least privilege principles. Ensure proper segmentation of workloads and implement robust access controls to isolate sensitive data. Regularly review and update network configurations to maintain security.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where api.name = 'gcloud-dataproc-clusters-list' AND json.rule = status.state is member of ("SCHEDULED", "CREATING", "RUNNING") as X; config from cloud.resource where api.name = 'gcloud-container-describe-clusters' AND json.rule = status equals RUNNING and ['network'] ends with "default" as Y; filter ' $.Y.selfLink contains $.X.virtualClusterConfig.kubernetesClusterConfig.gkeClusterConfig.gkeClusterTarget '; show X;`
</code></pre></td></tr><tr><td><strong>GCP Dataproc Cluster on Compute Engine is using default network</strong></td><td><p><strong>Policy Description—</strong> GCP Dataproc clusters deployed on the default network pose significant security risks due to its inherent lack of security controls and segmentation. This misconfiguration exposes the cluster to unauthorized access and potential data breaches.</p><p>The default network in GCP offers minimal security controls, allowing broad access between resources within the network. This lack of isolation increases the attack surface, enabling lateral movement and unauthorized access to sensitive data within the Dataproc cluster. Attackers could exploit this misconfiguration to gain access to the cluster and its underlying resources, potentially leading to data exfiltration or disruption of services.</p><p>The impact of this misconfiguration could range from unauthorized access to sensitive data and system compromise to complete data loss. Using a custom Virtual Private Cloud (VPC) network with appropriate firewall rules, subnets, and access controls enhances security, promotes better resource organization, and enables compliance with security regulations. Implementing robust network segmentation is crucial for isolating sensitive workloads and minimizing the impact of potential breaches.</p><p>To mitigate this risk, use a custom VPC network specifically for your Dataproc cluster. Configure appropriate firewall rules to restrict inbound and outbound traffic, allowing only necessary connections. Utilize subnets to isolate resources and apply appropriate Identity and Access Management ('IAM') policies to limit access to authorized users and services only. Regularly review and update network configurations to maintain a strong security posture.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>`config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-dataproc-clusters-list' AND json.rule = status.state is member of ("SCHEDULED", "CREATING", "RUNNING") and ( environmentConfig.executionConfig.networkUri ends with "default" or environmentConfig.executionConfig.subnetworkUri ends with "default" or ( environmentConfig.executionConfig.networkUri does not exist and environmentConfig.executionConfig.subnetworkUri does not exist ) )`
</code></pre></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>AWS MFA is not enabled on Root account</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated to consider the centralized root access introduced by AWS thereby reducing false positives.</p><p><strong>Current Description–</strong></p><p>This policy identifies root account which has MFA enabled. Root accounts have privileged access to all AWS services. Without MFA, if the root credentials are compromised, unauthorized users will get full access to your account.</p><p>This policy does not apply to AWS GovCloud Accounts. As you cannot enable an MFA device for AWS GovCloud (US) account root user. For more details refer: <a href="https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-console.html">https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-console.html</a>.</p><p><strong>Updated Description–</strong></p><p>This policy identifies root account which does not have MFA enabled. Root accounts have privileged access to all AWS services and can perform critical actions within the environment. In the event that the root credentials are compromised, malicious users could gain full control over the AWS account. This could lead to unauthorized access, data breaches, and potential damage to resources or services.</p><p>To address this risk, the solution is to enforce the activation of MFA for all root accounts. By enabling MFA, any attempt to access the root account would require both the root credentials and the second factor of authentication. This significantly reduces the likelihood of unauthorized access and enhances the overall security of the AWS environment.</p><p>This policy does not apply to AWS GovCloud Accounts. As you cannot enable an MFA device for AWS GovCloud (US) account root user. For more details refer: <a href="https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-console.html">https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-console.html</a>.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-iam-get-credential-report' AND json.rule = 'user equals "&#x3C;root_account>" and mfa_active is false and arn does not contain gov:'
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-iam-get-credential-report' AND json.rule = 'user equals "&#x3C;root_account>" and password_enabled is true and mfa_active is false and arn does not contain gov:'
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Medium</p><p><strong>Impact–</strong> Low. Open alerts where centralized root access is enabled will be resolved.</p></td></tr><tr><td><strong>Azure SQL server public network access setting is enabled</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated to align with the latest changes and updates in Azure Cloud. This update ensures improved compatibility and performance, providing users with the most up-to-date security and compliance checks specific to Azure Cloud environments.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-sql-server-list' AND json.rule = ['sqlServer'].['properties.state'] equal ignore case Ready and ['sqlServer'].['properties.publicNetworkAccess'] equal ignore case Enabled and ['sqlServer'].['properties.privateEndpointConnections'] is empty and firewallRules[*] is empty
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-sql-server-list' AND json.rule = ['sqlServer'].['properties.state'] equal ignore case Ready and ['sqlServer'].['properties.publicNetworkAccess'] equal ignore case Enabled and firewallRules[*] is not empty
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Medium</p><p><strong>Impact–</strong> Low. No impact on the valid alerts. Open alerts are resolved as Policy updated.</p></td></tr><tr><td><strong>Azure Network Watcher Network Security Group (NSG) flow logs are disabled</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated to exclude resources created by Prisma for agentless scans to reduce the noise.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-network-nsg-list' AND json.rule = flowLogsSettings does not exist or flowLogsSettings.enabled is false
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-network-nsg-list' AND json.rule = (flowLogsSettings does not exist or flowLogsSettings.enabled is false) and tags.created-by does not contain "prismacloud-agentless-scan"
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Medium</p><p><strong>Impact–</strong> Low. Open alerts where the resource is created by <em>prismacloud-agentless-scan</em> will be resolved.</p></td></tr><tr><td><strong>Azure Cosmos DB Virtual network is not configured</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated to consider cosmos DB is configured with private access to reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-cosmos-db' AND json.rule = properties.provisioningState equals Succeeded AND properties.publicNetworkAccess equal ignore case Enabled AND properties.virtualNetworkRules[*] is empty
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-cosmos-db' AND json.rule = properties.provisioningState equals Succeeded AND properties.publicNetworkAccess equal ignore case Enabled AND properties.virtualNetworkRules[*] is empty and properties.privateEndpointConnections does not exist
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Open alerts where private access is configured will be resolved.</p></td></tr><tr><td><strong>Azure Microsoft Defender for Cloud email notification for subscription owner is not set</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated to check for notifications configured for Owner role as per the latest Azure updates.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = (securityContacts is empty or securityContacts[*].properties.email is empty or securityContacts[*].properties.alertsToAdmins equal ignore case Off) and pricings[?any(properties.pricingTier equal ignore case Standard)] exists
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = (securityContacts is empty or securityContacts[*].properties.emails is empty or securityContacts[*].properties.notificationsByRole.roles[*] does not contain "Owner") and pricings[?any(properties.pricingTier equal ignore case Standard)] exists
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Informational</p><p><strong>Impact–</strong> Low. New alerts will be generated in case the Owner is not configured to receive email notifications. Open alerts for the security contact where the email is configured will be resolved.</p></td></tr><tr><td><strong>Azure Function app configured with public network access</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated to consider private endpoints as well to reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = 'kind contains functionapp and kind does not contain workflowapp and kind does not equal app and properties.state equal ignore case running and ((properties.publicNetworkAccess exists and properties.publicNetworkAccess equal ignore case Enabled) or (properties.publicNetworkAccess does not exist)) and config.ipSecurityRestrictions[?any((action equals Allow and ipAddress equals Any) or (action equals Allow and ipAddress equals 0.0.0.0/0))] exists'
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = 'kind contains functionapp and kind does not contain workflowapp and kind does not equal app and properties.state equal ignore case running and ((properties.publicNetworkAccess exists and properties.publicNetworkAccess equal ignore case Enabled) or (properties.publicNetworkAccess does not exist and (properties.privateLinkIdentifiers does not exist or properties.privateLinkIdentifiers is empty))) and config.ipSecurityRestrictions[?any((action equals Allow and ipAddress equals Any) or (action equals Allow and ipAddress equals 0.0.0.0/0))] exists'
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Medium</p><p><strong>Impact–</strong> Low. Open alerts where private link identifiers exist will be resolved.</p></td></tr><tr><td><strong>Azure Storage account encryption key is not rotated regularly</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated to alert based on the specific key associated with the storage account reducing false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.encryption.keySource equal ignore case "Microsoft.Keyvault" as X; config from cloud.resource where api.name = 'azure-key-vault-list' and json.rule = keys[?any(attributes.exp equals -1 and attributes.enabled contains true)] exists as Y; filter '$.Y.properties.vaultUri contains $.X.properties.encryption.keyvaultproperties.keyvaulturi'; show X;
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = 'properties.encryption.keySource equal ignore case "Microsoft.Keyvault" and _DateTime.ageInDays(properties.encryption.keyvaultproperties.currentVersionedKeyExpirationTimestamp) > 365'
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Open alerts where multiple keys exist and a correct key is associated with the Storage Account for encryption will be resolved.</p></td></tr><tr><td><strong>GCP Vertex AI Workbench Instance has Secure Boot disabled</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated due to changes in the GCP API.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-workbench-instance' AND json.rule = state equals "ACTIVE" AND shieldedInstanceConfig.enableSecureBoot is false
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-workbench-instance' AND json.rule = state equals "ACTIVE" AND gceSetup.shieldedInstanceConfig.enableSecureBoot is false
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. New alerts are generated based on the updated RQL.</p></td></tr><tr><td><strong>GCP Vertex AI Workbench Instance has Integrity monitoring disabled</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated due to changes in the GCP API.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-workbench-instance' AND json.rule = state equals "ACTIVE" AND shieldedInstanceConfig.enableIntegrityMonitoring is false
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-workbench-instance' AND json.rule = state equals "ACTIVE" AND gceSetup.shieldedInstanceConfig.enableIntegrityMonitoring is false
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. New alerts are generated based on the updated RQL.</p></td></tr><tr><td><strong>GCP Vertex AI Workbench Instance has vTPM disabled</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated due to changes in the GCP API.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-workbench-instance' AND json.rule = state equals "ACTIVE" AND shieldedInstanceConfig.enableVtpm is false
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-workbench-instance' AND json.rule = state equals "ACTIVE" AND gceSetup.shieldedInstanceConfig.enableVtpm is false
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. New alerts are generated based on the updated RQL.</p></td></tr><tr><td><strong>GCP SQL database instance deletion protection is disabled</strong></td><td><p><strong>Changes—</strong> The Policy RQL is updated with the right attribute to raise alerts on the vulnerable resources only.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-sql-instances-list' AND json.rule = state equals "RUNNABLE" and deletionProtectionEnabled is true
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-sql-instances-list' AND json.rule = state equals "RUNNABLE" and settings.deletionProtectionEnabled is false
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Informational</p><p><strong>Impact–</strong> Low. Open alerts where the deletion protection setting is enabled will be resolved.</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                                                          | **Description**                                                                                                                                                                                                                                   |
| ------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **\[Update] AWS Foundational Security Best Practices standard**                                   | <p>New Policy mappings are added to the AWS Foundational Security Best Practices compliance standard.</p><p><strong>Impact</strong>: As new mappings are introduced, compliance scoring may vary.</p>                                             |
| **\[Update] CIS v3.0.0 (Azure) Level 1, CIS v2.1.0 (Azure) Level 1 & CIS v2.0.0 (Azure) Level 1** | <p>New Policy mappings are added to the CIS v3.0.0 (Azure) Level 1, CIS v2.1.0 (Azure) Level 1 & CIS v2.0.0 (Azure) Level 1 compliance standards.</p><p><strong>Impact</strong>: As new mappings are introduced, compliance scoring may vary.</p> |
| **\[Update] CIS v4.0.0 (AWS) Level 2 & CIS v3.0.0 (AWS) Level 2**                                 | <p>New Policy mappings are added to the CIS v4.0.0 (AWS) Level 2 & CIS v3.0.0 (AWS) Level 2 compliance standards.</p><p><strong>Impact</strong>: As new mappings are introduced, compliance scoring may vary.</p>                                 |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2025/features-introduced-in-april-2025.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
