For the complete documentation index, see llms.txt. This page is also available as Markdown.

Features Introduced in December 2025

Learn what’s new in the Prisma® Cloud December 2025 release.

Changes in Existing Behavior

Feature

Description

Azure Onboarding Terrafom Update

The Microsoft Azure onboarding Terraform script is updated to remove a permission that Microsoft Azure Resource Manager (ARM) has deprecated. The permission below is no longer required during onboarding.

  • Microsoft.MixedReality/ObjectAnchorsAccounts/read

Mitigation- If you encounter an onboarding error, you can remove the permission above and run the Terraform script to resolve the issue.

Vulnerability Management Dashboard Update

The burndown widget on the Vulnerability dashboard will now include data from empty Clusters and Namespaces.

API Ingestions

Service

API Details

Amazon SageMaker

aws-sagemaker-model-package-group

Additional permissions required:

  • sagemaker:ListModelPackageGroups

  • sagemaker:DescribeModelPackageGroup

  • sagemaker:ListTags

The Security audit role includes the permissions.

Amazon SageMaker

aws-sagemaker-image

Additional permissions required:

  • sagemaker:ListImages

  • sagemaker:ListTags

The Security audit role includes the permissions.

Amazon SageMaker

aws-sagemaker-feature-group

Additional permissions required:

  • sagemaker:ListFeatureGroups

  • sagemaker:DescribeFeatureGroup

  • sagemaker:ListTags

The Security audit role includes the permissions.

Amazon SageMaker

aws-sagemaker-app

Additional permissions required:

  • sagemaker:ListApps

  • sagemaker:DescribeApp

The Security audit role includes the permissions.

AWS Batch Scheduling Policy

aws-batch-scheduling-policy

Additional permissions required:

  • batch:ListSchedulingPolicies

  • batch:DescribeSchedulingPolicies

No existing role includes the permissions.

Amazon SageMaker

aws-sagemaker-project

Additional permissions required:

  • sagemaker:ListProjects

  • sagemaker:DescribeProject

  • sagemaker:ListTags

The Security audit role includes the permissions.

Amazon SageMaker

aws-sagemaker-pipeline

Additional permissions required:

  • sagemaker:ListPipelines

  • sagemaker:DescribePipeline

  • sagemaker:ListTags

The Security audit role includes the permissions.

Amazon SageMaker

aws-sagemaker-data-quality-job-definition

Additional permissions required:

  • sagemaker:ListDataQualityJobDefinitions

  • sagemaker:DescribeDataQualityJobDefinition

  • sagemaker:ListTags

The Security audit role includes the permissions.

Amazon Redshift

aws-redshift-cluster-subnet-group

Additional permission required:

  • redshift:DescribeClusterSubnetGroups

The Security audit role includes the permission.

Amazon CloudWatch Update

aws-cloudwatch-log-group

The API now ingests the additional attribute dataProtectionPolicy. The following permission is required for this attribute to be ingested.

  • logs:GetDataProtectionPolicy

The Security audit role does not include the permission.

Amazon RDS

aws-rds-db-subnet-group

Additional permissions required:

  • rds:ListTagsForResource

  • rds:DescribeDBSubnetGroups

The Security audit role includes the permissions.

AWS Config

aws-configservice-aggregator-authorization

Additional permissions required:

  • config:DescribeAggregationAuthorizations

The Security audit role includes the permission.

Amazon MQ

aws-mq-configuration

Additional permission required:

  • mq:ListConfigurations

The Security audit role includes the permission.

AWS Backup

aws-backup-backup-selection

Additional permissions required:

  • backup:GetBackupSelection

  • backup:ListBackupSelections

The Security audit role does not include the permissions.

AWS Backup

aws-backup-report-plan

Additional permissions required:

  • backup:DescribeReportPlan

  • backup:ListTags

  • backup:ListReportPlans

The Security audit role does not include the permissions.

AWS Backup

aws-backup-framework

Additional permissions required:

  • backup:DescribeFramework

  • backup:ListTags

  • backup:ListFrameworks

The Security audit role does not include the permissions.

AWS Step Functions Update

aws-step-functions-activity

Update: Added regionId key:value to the ingested resource.

Amazon EMR Update

aws-emr-studio

Update: Added regionId key:value to the ingested resource.

Amazon QuickSight

aws-quicksight-vpc-connection

Additional permissions required:

  • quicksight:ListVPCConnections

  • quicksight:DescribeVPCConnection

The Security audit role includes the permissions.

Amazon Redshift

aws-redshift-serverless-snapshot

Additional permissions required:

  • redshift-serverless:ListSnapshots

  • redshift-serverless:ListTagsForResource

The Security audit role includes the permission for redshift-serverless:ListTagsForResource. Permissions for redshift-serverless:ListSnapshots are not included.

Amazon Redshift

aws-redshift-serverless-namespace

Additional permissions required:

  • redshift-serverless:ListNamespaces

  • redshift-serverless:ListTagsForResource

The Security audit role includes the permission for redshift-serverless:ListTagsForResource. Permissions for redshift-serverless:ListNamespaces are not included.

Amazon Redshift

aws-redshift-serverless-endpoint-access

Additional permission required:

  • redshift-serverless:ListEndpointAccess

The Security audit role does not include the permission.

AWS Systems Manager

aws-ssm-resource-data-sync

Additional permission required:

  • ssm:ListResourceDataSync

The Security audit role includes the permission.

Amazon EC2 Image Builder

aws-imagebuilder-image

Additional permissions required:

  • imagebuilder:ListImages

  • imagebuilder:GetImage

  • imagebuilder:ListImageBuildVersions

The Security audit role does not includes the permissions.

Amazon EC2 Image Builder

aws-imagebuilder-distribution-configuration

Additional permissions required:

  • imagebuilder:ListDistributionConfigurations

  • imagebuilder:GetDistributionConfiguration

The Security audit role does not includes the permissions.

Amazon ECS

aws-ecs-capacity-provider

Additional permission required:

  • ecs:DescribeCapacityProviders

The Security audit role includes the permission.

Amazon Comprehend

aws-comprehend-entity-recognizer

Additional permissions required:

  • comprehend:ListEntityRecognizers

  • comprehend:ListTagsForResource

The Security audit role includes the permissions.

AWS AppSync Update

aws-appsync-graphql-api

The API now ingests additional attribute apiCache. The following permission is required for this attribute to be ingested.

  • appsync:GetApiCache

Amazon MSK

aws-msk-clusterV2

Additional permission required:

  • kafka:ListClustersV2

The Security audit role includes the permission.

AWS Glue

aws-glue-ml-transform

Additional permission required:

  • glue:GetMLTransforms

The Security audit role does not include the permission.

AWS Directory Service

aws-ds-log-subscription

Additional permission required:

  • ds:ListLogSubscriptions

The Security audit role does not include the permission.

Amazon API Gateway

aws-apigateway-usage-plan

Additional permission required:

  • apigateway:GET

The Security audit role includes the permission.

Amazon Athena

aws-athena-capacity-reservation

Additional permissions required:

  • athena:ListCapacityReservations

  • athena:GetCapacityReservation

The Security audit role includes the permissions.

Amazon Athena

aws-athena-namedquery

Additional permissions required:

  • athena:ListWorkGroups

  • athena:ListNamedQueries

  • athena:GetNamedQuery

The Security audit role includes the permissions.

Amazon Athena

aws-athena-workgroup

Additional permissions required:

  • athena:ListWorkGroups

  • athena:GetWorkGroup

The ReadOnlyAccess role includes the permissions.

Amazon Athena

aws-athena-database

Additional permissions required:

  • athena:ListDataCatalogs

  • athena:ListDatabases

  • athena:GetDatabase

  • glue:GetDatabase

The ReadOnlyAccess role includes the permissions.

Amazon Athena Update

aws-athena-namedquery

Update: Added regionId key:value to the ingested resource.

Additional permissions required:

  • athena:ListWorkGroups

  • athena:ListNamedQueries

  • athena:GetNamedQuery

The Security audit role includes the permissions.

Amazon QuickSight

aws-quicksight-user

Additional permissions required:

  • quicksight:ListUsers

  • quicksight:DescribeUser

The Security audit role includes the permissions.

Amazon API Gateway

aws-apigateway-usage-plan

Additional permission required:

  • apigateway:GET

The Security audit role includes the permission.

AWS CodeBuild

aws-code-build-report-group

Additional permissions required:

  • codebuild:BatchGetReportGroups

  • codebuild:ListReportGroups

The Security audit role includes the permissions.

AWS CodeDeploy

aws-code-deploy-deployment-config

Additional permissions required:

  • codedeploy:ListDeploymentConfigs

  • codedeploy:GetDeploymentConfig

The Security audit role includes the permissions.

AWS CodeDeploy

aws-code-deploy-application

Additional permissions required:

  • codedeploy:ListApplications

  • codedeploy:BatchGetApplications

  • codedeploy:ListTagsForResource

The Security audit role includes the permissions.

AWS Security Hub

aws-securityhub-finding-aggregator

Additional permissions required:

  • securityhub:ListFindingAggregators

  • securityhub:GetFindingAggregator

The Security audit role includes the permissions.

Google AI Applications

gcloud-ai-applications-datastore

Additional permission needed:

  • discoveryengine.dataStores.list

The Viewer role includes the permission.

Google Cloud Task

gcloud-cloud-task-queue

Additional permission needed:

  • cloudtasks.queues.list

The Viewer role includes the permission.

Google Cloud Task

gcloud-cloud-task-cmek-config

Additional permission needed:

  • cloudtasks.cmekConfig.get

The Viewer role includes the permission.

Google Artifact Registry Update

gcloud-artifact-registry-repository

Update to existing API: The API response will now include the resource’s location.

Additional permissions needed:

  • artifactregistry.locations.list

  • artifactregistry.repositories.list

  • artifactregistry.repositories.getIamPolicy

The Viewer role includes the permissions.

Google Compute Engine

gcloud-compute-healthcheck

Additional permission needed:

  • compute.healthChecks.list

The Viewer role includes the permission.

Google Compute Engine Update

gcloud-compute-instance-template

Update to existing API:

  • The API now ingests regional resources along with global resources.

  • The result json now has an additional attribute region.

Google Vertex AI AIPlatform Update

gcloud-vertex-ai-aiplatform-feature-online-store

Update to existing API:

  • The result json now has an additional attributes features and labels.

  • Requires the permission aiplatform.featureViews.list for this field to be ingested.

Google Vertex AI AIPlatform Update

gcloud-vertex-ai-aiplatform-feature-store-entity-type

Update to existing API:

  • The result json now has an additional attributes features and labels.

  • Requires the permission aiplatform.features.list for this field to be ingested.

Google Vertex AI Platform Update

gcloud-vertex-aiplatform-feature-group

Update to existing API:

  • The result json now has an additional attributes features and region.

  • Requires the permission aiplatform.features.list for this field to be ingested.

Google Cloud Dialogflow ES

gcloud-dialogflow-es-agent

Additional permission needed:

  • dialogflow.agents.search

The Viewer role includes the permission.

Google Cloud Dialogflow ES

gcloud-dialogflow-es-encryption-spec

Additional permission needed:

  • dialogflow.encryptionspec.get

The Viewer role includes the permission.

Google Cloud Dialogflow CX

gcloud-dialogflow-cx-agent

Additional permissions needed:

  • dialogflow.agents.list

The Viewer role includes the permission.

Google Cloud Dialogflow CX

gcloud-dialogflow-cx-securitysettings

Additional permission needed:

  • dialogflow.securitySettings.list

The Viewer role includes the permission.

Google Cloud Firestore

gcloud-cloud-firestore-backup

Additional permission needed:

  • datastore.backups.list

The Viewer role includes the permission.

Google Cloud Conversational Insights

gcloud-conversational-insights-settings

Additional permissions needed:

  • contactcenterinsights.settings.get

  • contactcenterinsights.encryptionSpecs.get

The Viewer role includes the permissions.

Google Stackdriver Logging

gcloud-logging-bucket-log-views

Additional permissions needed:

  • logging.buckets.list

  • logging.views.list

The Viewer role includes the permission.

Google Stackdriver Logging Update

gcloud-logging-bucket

Additional permissions required:

  • logging.buckets.list

  • logging.links.list

The Viewer role includes the permissions.

Update to existing API:

  • Added buckets link to the ingested resource.

Google Cloud Data Loss Prevention

gcloud-dlp-discovery-scan-configuration

Additional permission needed:

  • dlp.jobTriggers.list

The Viewer role includes the permission.

Google Dataplex

gcloud-dataplex-entry-type

Additional permissions needed:

  • dataplex.entryTypes.list

  • dataplex.entryTypes.getIamPolicy

The Viewer role includes the permissions.

Google Dataplex

gcloud-dataplex-entry-group

Additional permissions needed:

  • dataplex.entryGroups.list

  • dataplex.entryGroups.getIamPolicy

The Viewer role includes the permissions.

Google Dataplex

gcloud-dataplex-aspect-type

Additional permissions needed:

  • dataplex.aspectTypes.list

  • dataplex.aspectTypes.getIamPolicy

The Viewer role includes the permissions.

Google Cloud Data Loss Prevention

gcloud-dlp-discovery-scan-configuration

Additional permissions needed:

  • dlp.jobTriggers.list

The Viewer role includes the permission.

Google Cloud Memorystore Update

gcloud-redis-instances-list

Update to existing API:

  • Added Redis version to the ingested resource.

Google Cloud Memorystore Update

gcloud-redis-instances-list

Update to existing API:

  • Added Redis version to the ingested resource.

GCP Data Catalog API Deprecation

GCP Data Catalog is deprecated and will be discontinued as of January 30, 2026. The following Data Catalog APIs will be deprecated.

  • gcloud-data-catalog-taxonomy

  • gcloud-data-catalog-entry-group

  • gcloud-data-catalog-tag-template

Policy Updates

Policy Updates

Description

Policy Updates—RQL

GCP Load Balancer HTTPS proxy permits SSL policies with weak cipher suites

Changes– The policy RQL will be updated to improve accuracy and reduce false positives.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Low

Impact– Medium. Existing alerts with an an SSL policy containing http proxy as a substring will be resolved as Policy Updated. New alerts will be generated for policy violations.

AWS Network Load Balancer (NLB) is not using the latest predefined security policy

Changes– This Policy is updated with the latest AWS security policy recommendations.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Low

Impact– Medium. Alerts will be generated for the NLBs not using the latest recommended security policies 'ELBSecurityPolicy-TLS13-1-2-Res-2021-06', 'ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04'. Open Alerts, which use either of the latest recommended security policies 'ELBSecurityPolicy-TLS13-1-2-Res-2021-06', 'ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04', will be resolved.

Azure Network Watcher Network Security Group (NSG) flow logs are disabled

Changes– : The Policy RQL is updated to improve accuracy and reduce false positives.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Medium

Impact– Low. Alerts where the storage does not exist will be resolved.

Azure Network Watcher Network Security Group (NSG) flow logs retention is less than 90 days

Changes– : The Policy RQL is updated to improve accuracy and reduce false positives.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Low

Impact– Low. Alerts where the flow log retention does not exist will be resolved.

Update 22 Azure NSG Policies

Changes– : Enhanced the policy RQLs to handle case-sensitive CSP attribute values, resulting in more accurate alert generation. Verified the provided RQL update for the following 24 policies:

  • Azure Network Security Group allows all traffic on ports which are not commonly used

  • Azure Network Security Group allows all traffic on MySQL (TCP Port 3306)

  • Azure Network Security Group allows all traffic on Windows SMB (TCP Port 445)

  • Azure Network Security Group allows all traffic on FTP-Data (TCP Port 20)

  • Azure Network Security Group allows all traffic on CIFS (UDP Port 445)

  • Azure Network Security Group allows all traffic on PostgreSQL (TCP Port 5432)

  • Azure Network Security Group allows all traffic on SQL Server (UDP Port 1434)

  • Azure Network Security Group allows all traffic on NetBIOS DNS (UDP Port 53)

  • Azure Network Security Group allows all traffic on FTP (TCP Port 21)

  • Azure Network Security Group having Inbound rule overly permissive to all traffic on UDP protocol

  • Azure Network Security Group allows all traffic on NetBIOS (UDP Port 137)

  • Azure Network Security Group allows all traffic on SMTP (TCP Port 25)

  • Azure Network Security Group having Inbound rule overly permissive to all traffic on TCP protocol

  • Azure Network Security Group allows all traffic on NetBIOS (UDP Port 138)

  • Azure Network Security Group allows all traffic on ICMP (Ping)

  • Azure Network Security Group allows all traffic on Windows RPC (TCP Port 135)

  • Azure Network Security Group allows all traffic on SQL Server (TCP Port 1433)

  • Azure Network Security Group allows all traffic on NetBIOS DNS (TCP Port 53)

  • Azure Network Security Group allows all traffic on MSQL (TCP Port 4333)

  • Azure Network Security Group allows all traffic on VNC Server (TCP Port 5900)

  • Azure Network Security Group allows all traffic on VNC Listener (TCP Port 5500)

  • Azure Network Security Group allows all traffic on Telnet (TCP Port 23)

AWS IAM user is not a member of any IAM group

Changes– : The Policy RQL is updated to improve accuracy and reduce false positives.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Informational

Impact– Low. Alerts will be resolved only for user root user, as root user cannot be added to IAM Groups.

Policy Updates—Metadata

AWS S3 bucket publicly writable

Policy Update– A note is added to the description indicating the exclusion of S3 buckets hosting public static websites.

Current Description–

Publicly writable AWS S3 buckets allow unauthorized access to sensitive data stored within. This misconfiguration exposes data to malicious actors and data breaches.

The S3 service relies on Access Control Lists (ACLs) and bucket policies to manage access. Incorrectly configured ACLs or bucket policies that grant 'Put', 'Create', 'Update', 'Replicate', 'Write', or 'Delete' permissions to the world, allow anyone to modify or delete bucket contents. This exposes data to unauthorized access, modification, or deletion.

A successful attack could lead to data exfiltration, modification, or deletion, resulting in significant financial, legal, and reputational damage. Best practices dictate strict control over S3 bucket permissions to prevent unauthorized access. Data loss and compliance violations are possible consequences.

Implement least privilege access controls. Restrict access to only trusted users and services via appropriately configured ACLs and bucket policies. Regularly review and audit S3 bucket permissions to identify and rectify any misconfigurations. Use strong encryption to protect data at rest and in transit. Employ multi-factor authentication (MFA) for enhanced security.

Proposed Description–

Publicly writable AWS S3 buckets allow unauthorized access to sensitive data stored within. This misconfiguration exposes data to malicious actors and data breaches.

The S3 service relies on Access Control Lists (ACLs) and bucket policies to manage access. Incorrectly configured ACLs or bucket policies that grant 'Put', 'Create', 'Update', 'Replicate', 'Write', or 'Delete' permissions to the world, allow anyone to modify or delete bucket contents. This exposes data to unauthorized access, modification, or deletion.

A successful attack could lead to data exfiltration, modification, or deletion, resulting in significant financial, legal, and reputational damage. Best practices dictate strict control over S3 bucket permissions to prevent unauthorized access. Data loss and compliance violations are possible consequences.

Implement least privilege access controls. Restrict access to only trusted users and services via appropriately configured ACLs and bucket policies. Regularly review and audit S3 bucket permissions to identify and rectify any misconfigurations. Use strong encryption to protect data at rest and in transit. Employ multi-factor authentication (MFA) for enhanced security.

Note: This policy excludes AWS S3 buckets that are configured to host public static websites.

Policy Type: Config

Policy Severity: High

Alerts Impact: No impact

Impact: Low

Last updated

Was this helpful?