Features Introduced in December 2025
Learn what’s new in the Prisma® Cloud December 2025 release.
Changes in Existing Behavior
Feature
Description
Azure Onboarding Terrafom Update
The Microsoft Azure onboarding Terraform script is updated to remove a permission that Microsoft Azure Resource Manager (ARM) has deprecated. The permission below is no longer required during onboarding.
Microsoft.MixedReality/ObjectAnchorsAccounts/read
Mitigation- If you encounter an onboarding error, you can remove the permission above and run the Terraform script to resolve the issue.
Vulnerability Management Dashboard Update
The burndown widget on the Vulnerability dashboard will now include data from empty Clusters and Namespaces.
API Ingestions
Service
API Details
Amazon SageMaker
aws-sagemaker-model-package-group
Additional permissions required:
sagemaker:ListModelPackageGroupssagemaker:DescribeModelPackageGroupsagemaker:ListTags
The Security audit role includes the permissions.
Amazon SageMaker
aws-sagemaker-image
Additional permissions required:
sagemaker:ListImagessagemaker:ListTags
The Security audit role includes the permissions.
Amazon SageMaker
aws-sagemaker-feature-group
Additional permissions required:
sagemaker:ListFeatureGroupssagemaker:DescribeFeatureGroupsagemaker:ListTags
The Security audit role includes the permissions.
Amazon SageMaker
aws-sagemaker-app
Additional permissions required:
sagemaker:ListAppssagemaker:DescribeApp
The Security audit role includes the permissions.
AWS Batch Scheduling Policy
aws-batch-scheduling-policy
Additional permissions required:
batch:ListSchedulingPoliciesbatch:DescribeSchedulingPolicies
No existing role includes the permissions.
Amazon SageMaker
aws-sagemaker-project
Additional permissions required:
sagemaker:ListProjectssagemaker:DescribeProjectsagemaker:ListTags
The Security audit role includes the permissions.
Amazon SageMaker
aws-sagemaker-pipeline
Additional permissions required:
sagemaker:ListPipelinessagemaker:DescribePipelinesagemaker:ListTags
The Security audit role includes the permissions.
Amazon SageMaker
aws-sagemaker-data-quality-job-definition
Additional permissions required:
sagemaker:ListDataQualityJobDefinitionssagemaker:DescribeDataQualityJobDefinitionsagemaker:ListTags
The Security audit role includes the permissions.
Amazon Redshift
aws-redshift-cluster-subnet-group
Additional permission required:
redshift:DescribeClusterSubnetGroups
The Security audit role includes the permission.
Amazon CloudWatch Update
aws-cloudwatch-log-group
The API now ingests the additional attribute dataProtectionPolicy. The following permission is required for this attribute to be ingested.
logs:GetDataProtectionPolicy
The Security audit role does not include the permission.
Amazon RDS
aws-rds-db-subnet-group
Additional permissions required:
rds:ListTagsForResourcerds:DescribeDBSubnetGroups
The Security audit role includes the permissions.
AWS Config
aws-configservice-aggregator-authorization
Additional permissions required:
config:DescribeAggregationAuthorizations
The Security audit role includes the permission.
Amazon MQ
aws-mq-configuration
Additional permission required:
mq:ListConfigurations
The Security audit role includes the permission.
AWS Backup
aws-backup-backup-selection
Additional permissions required:
backup:GetBackupSelectionbackup:ListBackupSelections
The Security audit role does not include the permissions.
AWS Backup
aws-backup-report-plan
Additional permissions required:
backup:DescribeReportPlanbackup:ListTagsbackup:ListReportPlans
The Security audit role does not include the permissions.
AWS Backup
aws-backup-framework
Additional permissions required:
backup:DescribeFrameworkbackup:ListTagsbackup:ListFrameworks
The Security audit role does not include the permissions.
AWS Step Functions Update
aws-step-functions-activity
Update: Added regionId key:value to the ingested resource.
Amazon EMR Update
aws-emr-studio
Update: Added regionId key:value to the ingested resource.
Amazon QuickSight
aws-quicksight-vpc-connection
Additional permissions required:
quicksight:ListVPCConnectionsquicksight:DescribeVPCConnection
The Security audit role includes the permissions.
Amazon Redshift
aws-redshift-serverless-snapshot
Additional permissions required:
redshift-serverless:ListSnapshotsredshift-serverless:ListTagsForResource
The Security audit role includes the permission for redshift-serverless:ListTagsForResource. Permissions for redshift-serverless:ListSnapshots are not included.
Amazon Redshift
aws-redshift-serverless-namespace
Additional permissions required:
redshift-serverless:ListNamespacesredshift-serverless:ListTagsForResource
The Security audit role includes the permission for redshift-serverless:ListTagsForResource. Permissions for redshift-serverless:ListNamespaces are not included.
Amazon Redshift
aws-redshift-serverless-endpoint-access
Additional permission required:
redshift-serverless:ListEndpointAccess
The Security audit role does not include the permission.
AWS Systems Manager
aws-ssm-resource-data-sync
Additional permission required:
ssm:ListResourceDataSync
The Security audit role includes the permission.
Amazon EC2 Image Builder
aws-imagebuilder-image
Additional permissions required:
imagebuilder:ListImagesimagebuilder:GetImageimagebuilder:ListImageBuildVersions
The Security audit role does not includes the permissions.
Amazon EC2 Image Builder
aws-imagebuilder-distribution-configuration
Additional permissions required:
imagebuilder:ListDistributionConfigurationsimagebuilder:GetDistributionConfiguration
The Security audit role does not includes the permissions.
Amazon ECS
aws-ecs-capacity-provider
Additional permission required:
ecs:DescribeCapacityProviders
The Security audit role includes the permission.
Amazon Comprehend
aws-comprehend-entity-recognizer
Additional permissions required:
comprehend:ListEntityRecognizerscomprehend:ListTagsForResource
The Security audit role includes the permissions.
AWS AppSync Update
aws-appsync-graphql-api
The API now ingests additional attribute apiCache. The following permission is required for this attribute to be ingested.
appsync:GetApiCache
Amazon MSK
aws-msk-clusterV2
Additional permission required:
kafka:ListClustersV2
The Security audit role includes the permission.
AWS Glue
aws-glue-ml-transform
Additional permission required:
glue:GetMLTransforms
The Security audit role does not include the permission.
AWS Directory Service
aws-ds-log-subscription
Additional permission required:
ds:ListLogSubscriptions
The Security audit role does not include the permission.
Amazon API Gateway
aws-apigateway-usage-plan
Additional permission required:
apigateway:GET
The Security audit role includes the permission.
Amazon Athena
aws-athena-capacity-reservation
Additional permissions required:
athena:ListCapacityReservationsathena:GetCapacityReservation
The Security audit role includes the permissions.
Amazon Athena
aws-athena-namedquery
Additional permissions required:
athena:ListWorkGroupsathena:ListNamedQueriesathena:GetNamedQuery
The Security audit role includes the permissions.
Amazon Athena
aws-athena-workgroup
Additional permissions required:
athena:ListWorkGroupsathena:GetWorkGroup
The ReadOnlyAccess role includes the permissions.
Amazon Athena
aws-athena-database
Additional permissions required:
athena:ListDataCatalogsathena:ListDatabasesathena:GetDatabaseglue:GetDatabase
The ReadOnlyAccess role includes the permissions.
Amazon Athena Update
aws-athena-namedquery
Update: Added regionId key:value to the ingested resource.
Additional permissions required:
athena:ListWorkGroupsathena:ListNamedQueriesathena:GetNamedQuery
The Security audit role includes the permissions.
Amazon QuickSight
aws-quicksight-user
Additional permissions required:
quicksight:ListUsersquicksight:DescribeUser
The Security audit role includes the permissions.
Amazon API Gateway
aws-apigateway-usage-plan
Additional permission required:
apigateway:GET
The Security audit role includes the permission.
AWS CodeBuild
aws-code-build-report-group
Additional permissions required:
codebuild:BatchGetReportGroupscodebuild:ListReportGroups
The Security audit role includes the permissions.
AWS CodeDeploy
aws-code-deploy-deployment-config
Additional permissions required:
codedeploy:ListDeploymentConfigscodedeploy:GetDeploymentConfig
The Security audit role includes the permissions.
AWS CodeDeploy
aws-code-deploy-application
Additional permissions required:
codedeploy:ListApplicationscodedeploy:BatchGetApplicationscodedeploy:ListTagsForResource
The Security audit role includes the permissions.
AWS Security Hub
aws-securityhub-finding-aggregator
Additional permissions required:
securityhub:ListFindingAggregatorssecurityhub:GetFindingAggregator
The Security audit role includes the permissions.
Google AI Applications
gcloud-ai-applications-datastore
Additional permission needed:
discoveryengine.dataStores.list
The Viewer role includes the permission.
Google Cloud Task
gcloud-cloud-task-queue
Additional permission needed:
cloudtasks.queues.list
The Viewer role includes the permission.
Google Cloud Task
gcloud-cloud-task-cmek-config
Additional permission needed:
cloudtasks.cmekConfig.get
The Viewer role includes the permission.
Google Artifact Registry Update
gcloud-artifact-registry-repository
Update to existing API: The API response will now include the resource’s location.
Additional permissions needed:
artifactregistry.locations.listartifactregistry.repositories.listartifactregistry.repositories.getIamPolicy
The Viewer role includes the permissions.
Google Compute Engine
gcloud-compute-healthcheck
Additional permission needed:
compute.healthChecks.list
The Viewer role includes the permission.
Google Compute Engine Update
gcloud-compute-instance-template
Update to existing API:
The API now ingests regional resources along with global resources.
The result json now has an additional attribute
region.
Google Vertex AI AIPlatform Update
gcloud-vertex-ai-aiplatform-feature-online-store
Update to existing API:
The result json now has an additional attributes
featuresandlabels.Requires the permission
aiplatform.featureViews.listfor this field to be ingested.
Google Vertex AI AIPlatform Update
gcloud-vertex-ai-aiplatform-feature-store-entity-type
Update to existing API:
The result json now has an additional attributes
featuresandlabels.Requires the permission
aiplatform.features.listfor this field to be ingested.
Google Vertex AI Platform Update
gcloud-vertex-aiplatform-feature-group
Update to existing API:
The result json now has an additional attributes
featuresandregion.Requires the permission
aiplatform.features.listfor this field to be ingested.
Google Cloud Dialogflow ES
gcloud-dialogflow-es-agent
Additional permission needed:
dialogflow.agents.search
The Viewer role includes the permission.
Google Cloud Dialogflow ES
gcloud-dialogflow-es-encryption-spec
Additional permission needed:
dialogflow.encryptionspec.get
The Viewer role includes the permission.
Google Cloud Dialogflow CX
gcloud-dialogflow-cx-agent
Additional permissions needed:
dialogflow.agents.list
The Viewer role includes the permission.
Google Cloud Dialogflow CX
gcloud-dialogflow-cx-securitysettings
Additional permission needed:
dialogflow.securitySettings.list
The Viewer role includes the permission.
Google Cloud Firestore
gcloud-cloud-firestore-backup
Additional permission needed:
datastore.backups.list
The Viewer role includes the permission.
Google Cloud Conversational Insights
gcloud-conversational-insights-settings
Additional permissions needed:
contactcenterinsights.settings.getcontactcenterinsights.encryptionSpecs.get
The Viewer role includes the permissions.
Google Stackdriver Logging
gcloud-logging-bucket-log-views
Additional permissions needed:
logging.buckets.listlogging.views.list
The Viewer role includes the permission.
Google Stackdriver Logging Update
gcloud-logging-bucket
Additional permissions required:
logging.buckets.listlogging.links.list
The Viewer role includes the permissions.
Update to existing API:
Added buckets link to the ingested resource.
Google Cloud Data Loss Prevention
gcloud-dlp-discovery-scan-configuration
Additional permission needed:
dlp.jobTriggers.list
The Viewer role includes the permission.
Google Dataplex
gcloud-dataplex-entry-type
Additional permissions needed:
dataplex.entryTypes.listdataplex.entryTypes.getIamPolicy
The Viewer role includes the permissions.
Google Dataplex
gcloud-dataplex-entry-group
Additional permissions needed:
dataplex.entryGroups.listdataplex.entryGroups.getIamPolicy
The Viewer role includes the permissions.
Google Dataplex
gcloud-dataplex-aspect-type
Additional permissions needed:
dataplex.aspectTypes.listdataplex.aspectTypes.getIamPolicy
The Viewer role includes the permissions.
Google Cloud Data Loss Prevention
gcloud-dlp-discovery-scan-configuration
Additional permissions needed:
dlp.jobTriggers.list
The Viewer role includes the permission.
Google Cloud Memorystore Update
gcloud-redis-instances-list
Update to existing API:
Added Redis version to the ingested resource.
Google Cloud Memorystore Update
gcloud-redis-instances-list
Update to existing API:
Added Redis version to the ingested resource.
GCP Data Catalog API Deprecation
GCP Data Catalog is deprecated and will be discontinued as of January 30, 2026. The following Data Catalog APIs will be deprecated.
gcloud-data-catalog-taxonomygcloud-data-catalog-entry-groupgcloud-data-catalog-tag-template
Policy Updates
Policy Updates
Description
Policy Updates—RQL
GCP Load Balancer HTTPS proxy permits SSL policies with weak cipher suites
Changes– The policy RQL will be updated to improve accuracy and reduce false positives.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Low
Impact– Medium. Existing alerts with an an SSL policy containing http proxy as a substring will be resolved as Policy Updated. New alerts will be generated for policy violations.
AWS Network Load Balancer (NLB) is not using the latest predefined security policy
Changes– This Policy is updated with the latest AWS security policy recommendations.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Low
Impact– Medium. Alerts will be generated for the NLBs not using the latest recommended security policies 'ELBSecurityPolicy-TLS13-1-2-Res-2021-06', 'ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04'. Open Alerts, which use either of the latest recommended security policies 'ELBSecurityPolicy-TLS13-1-2-Res-2021-06', 'ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04', will be resolved.
Azure Network Watcher Network Security Group (NSG) flow logs are disabled
Changes– : The Policy RQL is updated to improve accuracy and reduce false positives.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Medium
Impact– Low. Alerts where the storage does not exist will be resolved.
Azure Network Watcher Network Security Group (NSG) flow logs retention is less than 90 days
Changes– : The Policy RQL is updated to improve accuracy and reduce false positives.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Low
Impact– Low. Alerts where the flow log retention does not exist will be resolved.
Update 22 Azure NSG Policies
Changes– : Enhanced the policy RQLs to handle case-sensitive CSP attribute values, resulting in more accurate alert generation. Verified the provided RQL update for the following 24 policies:
Azure Network Security Group allows all traffic on ports which are not commonly used
Azure Network Security Group allows all traffic on MySQL (TCP Port 3306)
Azure Network Security Group allows all traffic on Windows SMB (TCP Port 445)
Azure Network Security Group allows all traffic on FTP-Data (TCP Port 20)
Azure Network Security Group allows all traffic on CIFS (UDP Port 445)
Azure Network Security Group allows all traffic on PostgreSQL (TCP Port 5432)
Azure Network Security Group allows all traffic on SQL Server (UDP Port 1434)
Azure Network Security Group allows all traffic on NetBIOS DNS (UDP Port 53)
Azure Network Security Group allows all traffic on FTP (TCP Port 21)
Azure Network Security Group having Inbound rule overly permissive to all traffic on UDP protocol
Azure Network Security Group allows all traffic on NetBIOS (UDP Port 137)
Azure Network Security Group allows all traffic on SMTP (TCP Port 25)
Azure Network Security Group having Inbound rule overly permissive to all traffic on TCP protocol
Azure Network Security Group allows all traffic on NetBIOS (UDP Port 138)
Azure Network Security Group allows all traffic on ICMP (Ping)
Azure Network Security Group allows all traffic on Windows RPC (TCP Port 135)
Azure Network Security Group allows all traffic on SQL Server (TCP Port 1433)
Azure Network Security Group allows all traffic on NetBIOS DNS (TCP Port 53)
Azure Network Security Group allows all traffic on MSQL (TCP Port 4333)
Azure Network Security Group allows all traffic on VNC Server (TCP Port 5900)
Azure Network Security Group allows all traffic on VNC Listener (TCP Port 5500)
Azure Network Security Group allows all traffic on Telnet (TCP Port 23)
AWS IAM user is not a member of any IAM group
Changes– : The Policy RQL is updated to improve accuracy and reduce false positives.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Informational
Impact– Low. Alerts will be resolved only for user root user, as root user cannot be added to IAM Groups.
Policy Updates—Metadata
AWS S3 bucket publicly writable
Policy Update– A note is added to the description indicating the exclusion of S3 buckets hosting public static websites.
Current Description–
Publicly writable AWS S3 buckets allow unauthorized access to sensitive data stored within. This misconfiguration exposes data to malicious actors and data breaches.
The S3 service relies on Access Control Lists (ACLs) and bucket policies to manage access. Incorrectly configured ACLs or bucket policies that grant 'Put', 'Create', 'Update', 'Replicate', 'Write', or 'Delete' permissions to the world, allow anyone to modify or delete bucket contents. This exposes data to unauthorized access, modification, or deletion.
A successful attack could lead to data exfiltration, modification, or deletion, resulting in significant financial, legal, and reputational damage. Best practices dictate strict control over S3 bucket permissions to prevent unauthorized access. Data loss and compliance violations are possible consequences.
Implement least privilege access controls. Restrict access to only trusted users and services via appropriately configured ACLs and bucket policies. Regularly review and audit S3 bucket permissions to identify and rectify any misconfigurations. Use strong encryption to protect data at rest and in transit. Employ multi-factor authentication (MFA) for enhanced security.
Proposed Description–
Publicly writable AWS S3 buckets allow unauthorized access to sensitive data stored within. This misconfiguration exposes data to malicious actors and data breaches.
The S3 service relies on Access Control Lists (ACLs) and bucket policies to manage access. Incorrectly configured ACLs or bucket policies that grant 'Put', 'Create', 'Update', 'Replicate', 'Write', or 'Delete' permissions to the world, allow anyone to modify or delete bucket contents. This exposes data to unauthorized access, modification, or deletion.
A successful attack could lead to data exfiltration, modification, or deletion, resulting in significant financial, legal, and reputational damage. Best practices dictate strict control over S3 bucket permissions to prevent unauthorized access. Data loss and compliance violations are possible consequences.
Implement least privilege access controls. Restrict access to only trusted users and services via appropriately configured ACLs and bucket policies. Regularly review and audit S3 bucket permissions to identify and rectify any misconfigurations. Use strong encryption to protect data at rest and in transit. Employ multi-factor authentication (MFA) for enhanced security.
Note: This policy excludes AWS S3 buckets that are configured to host public static websites.
Policy Type: Config
Policy Severity: High
Alerts Impact: No impact
Impact: Low
Last updated
Was this helpful?

