> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2025/features-introduced-in-december-2025.md).

# Features Introduced in December 2025

Learn what’s new in the Prisma® Cloud December 2025 release.

* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [API Ingestions](#api-ingestions)
* [Policy Updates](#policy-updates)

## Changes in Existing Behavior

| **Feature**                                   | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Azure Onboarding Terrafom Update**          | <p>The Microsoft Azure onboarding Terraform script is updated to remove a permission that Microsoft Azure Resource Manager (ARM) has deprecated. The permission below is no longer required during onboarding.</p><ul><li><code>Microsoft.MixedReality/ObjectAnchorsAccounts/read</code></li></ul><p><strong>Mitigation-</strong> If you encounter an onboarding error, you can remove the permission above and run the Terraform script to resolve the issue.</p> |
| **Vulnerability Management Dashboard Update** | The burndown widget on the Vulnerability dashboard will now include data from empty Clusters and Namespaces.                                                                                                                                                                                                                                                                                                                                                       |

## API Ingestions

| **Service**                                                                          | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Amazon SageMaker**                                                                 | <p><strong>aws-sagemaker-model-package-group</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListModelPackageGroups</code></li><li><code>sagemaker:DescribeModelPackageGroup</code></li><li><code>sagemaker:ListTags</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                         |
| **Amazon SageMaker**                                                                 | <p><strong>aws-sagemaker-image</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListImages</code></li><li><code>sagemaker:ListTags</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                                                            |
| **Amazon SageMaker**                                                                 | <p><strong>aws-sagemaker-feature-group</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListFeatureGroups</code></li><li><code>sagemaker:DescribeFeatureGroup</code></li><li><code>sagemaker:ListTags</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                         |
| **Amazon SageMaker**                                                                 | <p><strong>aws-sagemaker-app</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListApps</code></li><li><code>sagemaker:DescribeApp</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                                                             |
| **AWS Batch Scheduling Policy**                                                      | <p><strong>aws-batch-scheduling-policy</strong></p><p>Additional permissions required:</p><ul><li><code>batch:ListSchedulingPolicies</code></li><li><code>batch:DescribeSchedulingPolicies</code></li></ul><p>No existing role includes the permissions.</p>                                                                                                                                                                     |
| **Amazon SageMaker**                                                                 | <p><strong>aws-sagemaker-project</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListProjects</code></li><li><code>sagemaker:DescribeProject</code></li><li><code>sagemaker:ListTags</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                         |
| **Amazon SageMaker**                                                                 | <p><strong>aws-sagemaker-pipeline</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListPipelines</code></li><li><code>sagemaker:DescribePipeline</code></li><li><code>sagemaker:ListTags</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                      |
| **Amazon SageMaker**                                                                 | <p><strong>aws-sagemaker-data-quality-job-definition</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListDataQualityJobDefinitions</code></li><li><code>sagemaker:DescribeDataQualityJobDefinition</code></li><li><code>sagemaker:ListTags</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                   |
| **Amazon Redshift**                                                                  | <p><strong>aws-redshift-cluster-subnet-group</strong></p><p>Additional permission required:</p><ul><li><code>redshift:DescribeClusterSubnetGroups</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                        |
| **Amazon CloudWatch** <mark style="background-color:orange;">Update</mark>           | <p><strong>aws-cloudwatch-log-group</strong></p><p>The API now ingests the additional attribute <code>dataProtectionPolicy</code>. The following permission is required for this attribute to be ingested.</p><ul><li><code>logs:GetDataProtectionPolicy</code></li></ul><p>The Security audit role does not include the permission.</p>                                                                                         |
| **Amazon RDS**                                                                       | <p><strong>aws-rds-db-subnet-group</strong></p><p>Additional permissions required:</p><ul><li><code>rds:ListTagsForResource</code></li><li><code>rds:DescribeDBSubnetGroups</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                                             |
| **AWS Config**                                                                       | <p><strong>aws-configservice-aggregator-authorization</strong></p><p>Additional permissions required:</p><ul><li><code>config:DescribeAggregationAuthorizations</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                          |
| **Amazon MQ**                                                                        | <p><strong>aws-mq-configuration</strong></p><p>Additional permission required:</p><ul><li><code>mq:ListConfigurations</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                                                    |
| **AWS Backup**                                                                       | <p><strong>aws-backup-backup-selection</strong></p><p>Additional permissions required:</p><ul><li><code>backup:GetBackupSelection</code></li><li><code>backup:ListBackupSelections</code></li></ul><p>The Security audit role does not include the permissions.</p>                                                                                                                                                              |
| **AWS Backup**                                                                       | <p><strong>aws-backup-report-plan</strong></p><p>Additional permissions required:</p><ul><li><code>backup:DescribeReportPlan</code></li><li><code>backup:ListTags</code></li><li><code>backup:ListReportPlans</code></li></ul><p>The Security audit role does not include the permissions.</p>                                                                                                                                   |
| **AWS Backup**                                                                       | <p><strong>aws-backup-framework</strong></p><p>Additional permissions required:</p><ul><li><code>backup:DescribeFramework</code></li><li><code>backup:ListTags</code></li><li><code>backup:ListFrameworks</code></li></ul><p>The Security audit role does not include the permissions.</p>                                                                                                                                       |
| **AWS Step Functions** <mark style="background-color:orange;">Update</mark>          | <p><strong>aws-step-functions-activity</strong></p><p>Update: Added <code>regionId key:value</code> to the ingested resource.</p>                                                                                                                                                                                                                                                                                                |
| **Amazon EMR** <mark style="background-color:orange;">Update</mark>                  | <p><strong>aws-emr-studio</strong></p><p>Update: Added <code>regionId key:value</code> to the ingested resource.</p>                                                                                                                                                                                                                                                                                                             |
| **Amazon QuickSight**                                                                | <p><strong>aws-quicksight-vpc-connection</strong></p><p>Additional permissions required:</p><ul><li><code>quicksight:ListVPCConnections</code></li><li><code>quicksight:DescribeVPCConnection</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                           |
| **Amazon Redshift**                                                                  | <p><strong>aws-redshift-serverless-snapshot</strong></p><p>Additional permissions required:</p><ul><li><code>redshift-serverless:ListSnapshots</code></li><li><code>redshift-serverless:ListTagsForResource</code></li></ul><p>The Security audit role includes the permission for <code>redshift-serverless:ListTagsForResource</code>. Permissions for <code>redshift-serverless:ListSnapshots</code> are not included.</p>    |
| **Amazon Redshift**                                                                  | <p><strong>aws-redshift-serverless-namespace</strong></p><p>Additional permissions required:</p><ul><li><code>redshift-serverless:ListNamespaces</code></li><li><code>redshift-serverless:ListTagsForResource</code></li></ul><p>The Security audit role includes the permission for <code>redshift-serverless:ListTagsForResource</code>. Permissions for <code>redshift-serverless:ListNamespaces</code> are not included.</p> |
| **Amazon Redshift**                                                                  | <p><strong>aws-redshift-serverless-endpoint-access</strong></p><p>Additional permission required:</p><ul><li><code>redshift-serverless:ListEndpointAccess</code></li></ul><p>The Security audit role does not include the permission.</p>                                                                                                                                                                                        |
| **AWS Systems Manager**                                                              | <p><strong>aws-ssm-resource-data-sync</strong></p><p>Additional permission required:</p><ul><li><code>ssm:ListResourceDataSync</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                                           |
| **Amazon EC2 Image Builder**                                                         | <p><strong>aws-imagebuilder-image</strong></p><p>Additional permissions required:</p><ul><li><code>imagebuilder:ListImages</code></li><li><code>imagebuilder:GetImage</code></li><li><code>imagebuilder:ListImageBuildVersions</code></li></ul><p>The Security audit role does not includes the permissions.</p>                                                                                                                 |
| **Amazon EC2 Image Builder**                                                         | <p><strong>aws-imagebuilder-distribution-configuration</strong></p><p>Additional permissions required:</p><ul><li><code>imagebuilder:ListDistributionConfigurations</code></li><li><code>imagebuilder:GetDistributionConfiguration</code></li></ul><p>The Security audit role does not includes the permissions.</p>                                                                                                             |
| **Amazon ECS**                                                                       | <p><strong>aws-ecs-capacity-provider</strong></p><p>Additional permission required:</p><ul><li><code>ecs:DescribeCapacityProviders</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                                       |
| **Amazon Comprehend**                                                                | <p><strong>aws-comprehend-entity-recognizer</strong></p><p>Additional permissions required:</p><ul><li><code>comprehend:ListEntityRecognizers</code></li><li><code>comprehend:ListTagsForResource</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                       |
| **AWS AppSync** <mark style="background-color:orange;">Update</mark>                 | <p><strong>aws-appsync-graphql-api</strong></p><p>The API now ingests additional attribute <code>apiCache</code>. The following permission is required for this attribute to be ingested.</p><ul><li><code>appsync:GetApiCache</code></li></ul>                                                                                                                                                                                  |
| **Amazon MSK**                                                                       | <p><strong>aws-msk-clusterV2</strong></p><p>Additional permission required:</p><ul><li><code>kafka:ListClustersV2</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                                                        |
| **AWS Glue**                                                                         | <p><strong>aws-glue-ml-transform</strong></p><p>Additional permission required:</p><ul><li><code>glue:GetMLTransforms</code></li></ul><p>The Security audit role does not include the permission.</p>                                                                                                                                                                                                                            |
| **AWS Directory Service**                                                            | <p><strong>aws-ds-log-subscription</strong></p><p>Additional permission required:</p><ul><li><code>ds:ListLogSubscriptions</code></li></ul><p>The Security audit role does not include the permission.</p>                                                                                                                                                                                                                       |
| **Amazon API Gateway**                                                               | <p><strong>aws-apigateway-usage-plan</strong></p><p>Additional permission required:</p><ul><li><code>apigateway:GET</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                                                      |
| **Amazon Athena**                                                                    | <p><strong>aws-athena-capacity-reservation</strong></p><p>Additional permissions required:</p><ul><li><code>athena:ListCapacityReservations</code></li><li><code>athena:GetCapacityReservation</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                          |
| **Amazon Athena**                                                                    | <p><strong>aws-athena-namedquery</strong></p><p>Additional permissions required:</p><ul><li><code>athena:ListWorkGroups</code></li><li><code>athena:ListNamedQueries</code></li><li><code>athena:GetNamedQuery</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                          |
| **Amazon Athena**                                                                    | <p><strong>aws-athena-workgroup</strong></p><p>Additional permissions required:</p><ul><li><code>athena:ListWorkGroups</code></li><li><code>athena:GetWorkGroup</code></li></ul><p>The ReadOnlyAccess role includes the permissions.</p>                                                                                                                                                                                         |
| **Amazon Athena**                                                                    | <p><strong>aws-athena-database</strong></p><p>Additional permissions required:</p><ul><li><code>athena:ListDataCatalogs</code></li><li><code>athena:ListDatabases</code></li><li><code>athena:GetDatabase</code></li><li><code>glue:GetDatabase</code></li></ul><p>The ReadOnlyAccess role includes the permissions.</p>                                                                                                         |
| **Amazon Athena** <mark style="background-color:orange;">Update</mark>               | <p><strong>aws-athena-namedquery</strong></p><p>Update: Added regionId key:value to the ingested resource.</p><p>Additional permissions required:</p><ul><li><code>athena:ListWorkGroups</code></li><li><code>athena:ListNamedQueries</code></li><li><code>athena:GetNamedQuery</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                         |
| **Amazon QuickSight**                                                                | <p><strong>aws-quicksight-user</strong></p><p>Additional permissions required:</p><ul><li><code>quicksight:ListUsers</code></li><li><code>quicksight:DescribeUser</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                                                       |
| **Amazon API Gateway**                                                               | <p><strong>aws-apigateway-usage-plan</strong></p><p>Additional permission required:</p><ul><li><code>apigateway:GET</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                                                      |
| **AWS CodeBuild**                                                                    | <p><strong>aws-code-build-report-group</strong></p><p>Additional permissions required:</p><ul><li><code>codebuild:BatchGetReportGroups</code></li><li><code>codebuild:ListReportGroups</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                                  |
| **AWS CodeDeploy**                                                                   | <p><strong>aws-code-deploy-deployment-config</strong></p><p>Additional permissions required:</p><ul><li><code>codedeploy:ListDeploymentConfigs</code></li><li><code>codedeploy:GetDeploymentConfig</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                      |
| **AWS CodeDeploy**                                                                   | <p><strong>aws-code-deploy-application</strong></p><p>Additional permissions required:</p><ul><li><code>codedeploy:ListApplications</code></li><li><code>codedeploy:BatchGetApplications</code></li><li><code>codedeploy:ListTagsForResource</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                            |
| **AWS Security Hub**                                                                 | <p><strong>aws-securityhub-finding-aggregator</strong></p><p>Additional permissions required:</p><ul><li><code>securityhub:ListFindingAggregators</code></li><li><code>securityhub:GetFindingAggregator</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                 |
| **Google AI Applications**                                                           | <p><strong>gcloud-ai-applications-datastore</strong></p><p>Additional permission needed:</p><ul><li><code>discoveryengine.dataStores.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                        |
| **Google Cloud Task**                                                                | <p><strong>gcloud-cloud-task-queue</strong></p><p>Additional permission needed:</p><ul><li><code>cloudtasks.queues.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                          |
| **Google Cloud Task**                                                                | <p><strong>gcloud-cloud-task-cmek-config</strong></p><p>Additional permission needed:</p><ul><li><code>cloudtasks.cmekConfig.get</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                 |
| **Google Artifact Registry** <mark style="background-color:orange;">Update</mark>    | <p><strong>gcloud-artifact-registry-repository</strong></p><p>Update to existing API: The API response will now include the resource’s location.</p><p>Additional permissions needed:</p><ul><li><code>artifactregistry.locations.list</code></li><li><code>artifactregistry.repositories.list</code></li><li><code>artifactregistry.repositories.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>  |
| **Google Compute Engine**                                                            | <p><strong>gcloud-compute-healthcheck</strong></p><p>Additional permission needed:</p><ul><li><code>compute.healthChecks.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                    |
| **Google Compute Engine** <mark style="background-color:orange;">Update</mark>       | <p><strong>gcloud-compute-instance-template</strong></p><p>Update to existing API:</p><ul><li>The API now ingests regional resources along with global resources.</li><li>The result json now has an additional attribute <code>region</code>.</li></ul>                                                                                                                                                                         |
| **Google Vertex AI AIPlatform** <mark style="background-color:orange;">Update</mark> | <p><strong>gcloud-vertex-ai-aiplatform-feature-online-store</strong></p><p>Update to existing API:</p><ul><li>The result json now has an additional attributes <code>features</code> and <code>labels</code>.</li><li>Requires the permission <code>aiplatform.featureViews.list</code> for this field to be ingested.</li></ul>                                                                                                 |
| **Google Vertex AI AIPlatform** <mark style="background-color:orange;">Update</mark> | <p><strong>gcloud-vertex-ai-aiplatform-feature-store-entity-type</strong></p><p>Update to existing API:</p><ul><li>The result json now has an additional attributes <code>features</code> and <code>labels</code>.</li><li>Requires the permission <code>aiplatform.features.list</code> for this field to be ingested.</li></ul>                                                                                                |
| **Google Vertex AI Platform** <mark style="background-color:orange;">Update</mark>   | <p><strong>gcloud-vertex-aiplatform-feature-group</strong></p><p>Update to existing API:</p><ul><li>The result json now has an additional attributes <code>features</code> and <code>region</code>.</li><li>Requires the permission <code>aiplatform.features.list</code> for this field to be ingested.</li></ul>                                                                                                               |
| **Google Cloud Dialogflow ES**                                                       | <p><strong>gcloud-dialogflow-es-agent</strong></p><p>Additional permission needed:</p><ul><li><code>dialogflow\.agents.search</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                    |
| **Google Cloud Dialogflow ES**                                                       | <p><strong>gcloud-dialogflow-es-encryption-spec</strong></p><p>Additional permission needed:</p><ul><li><code>dialogflow\.encryptionspec.get</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                     |
| **Google Cloud Dialogflow CX**                                                       | <p><strong>gcloud-dialogflow-cx-agent</strong></p><p>Additional permissions needed:</p><ul><li><code>dialogflow\.agents.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                     |
| **Google Cloud Dialogflow CX**                                                       | <p><strong>gcloud-dialogflow-cx-securitysettings</strong></p><p>Additional permission needed:</p><ul><li><code>dialogflow\.securitySettings.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                 |
| **Google Cloud Firestore**                                                           | <p><strong>gcloud-cloud-firestore-backup</strong></p><p>Additional permission needed:</p><ul><li><code>datastore.backups.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                    |
| **Google Cloud Conversational Insights**                                             | <p><strong>gcloud-conversational-insights-settings</strong></p><p>Additional permissions needed:</p><ul><li><code>contactcenterinsights.settings.get</code></li><li><code>contactcenterinsights.encryptionSpecs.get</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                             |
| **Google Stackdriver Logging**                                                       | <p><strong>gcloud-logging-bucket-log-views</strong></p><p>Additional permissions needed:</p><ul><li><code>logging.buckets.list</code></li><li><code>logging.views.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                           |
| **Google Stackdriver Logging** <mark style="background-color:orange;">Update</mark>  | <p><strong>gcloud-logging-bucket</strong></p><p>Additional permissions required:</p><ul><li><code>logging.buckets.list</code></li><li><code>logging.links.list</code></li></ul><p>The Viewer role includes the permissions.</p><p>Update to existing API:</p><ul><li>Added buckets link to the ingested resource.</li></ul>                                                                                                      |
| **Google Cloud Data Loss Prevention**                                                | <p><strong>gcloud-dlp-discovery-scan-configuration</strong></p><p>Additional permission needed:</p><ul><li><code>dlp.jobTriggers.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                            |
| **Google Dataplex**                                                                  | <p><strong>gcloud-dataplex-entry-type</strong></p><p>Additional permissions needed:</p><ul><li><code>dataplex.entryTypes.list</code></li><li><code>dataplex.entryTypes.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                             |
| **Google Dataplex**                                                                  | <p><strong>gcloud-dataplex-entry-group</strong></p><p>Additional permissions needed:</p><ul><li><code>dataplex.entryGroups.list</code></li><li><code>dataplex.entryGroups.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                          |
| **Google Dataplex**                                                                  | <p><strong>gcloud-dataplex-aspect-type</strong></p><p>Additional permissions needed:</p><ul><li><code>dataplex.aspectTypes.list</code></li><li><code>dataplex.aspectTypes.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                          |
| **Google Cloud Data Loss Prevention**                                                | <p><strong>gcloud-dlp-discovery-scan-configuration</strong></p><p>Additional permissions needed:</p><ul><li><code>dlp.jobTriggers.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                           |
| **Google Cloud Memorystore** <mark style="background-color:orange;">Update</mark>    | <p><strong>gcloud-redis-instances-list</strong></p><p>Update to existing API:</p><ul><li>Added Redis version to the ingested resource.</li></ul>                                                                                                                                                                                                                                                                                 |
| **Google Cloud Memorystore** <mark style="background-color:orange;">Update</mark>    | <p><strong>gcloud-redis-instances-list</strong></p><p>Update to existing API:</p><ul><li>Added Redis version to the ingested resource.</li></ul>                                                                                                                                                                                                                                                                                 |
| **GCP Data Catalog API** <mark style="background-color:orange;">Deprecation</mark>   | <p>GCP Data Catalog is deprecated and will be discontinued as of January 30, 2026. The following Data Catalog APIs will be deprecated.</p><ul><li><code>gcloud-data-catalog-taxonomy</code></li><li><code>gcloud-data-catalog-entry-group</code></li><li><code>gcloud-data-catalog-tag-template</code></li></ul>                                                                                                                 |

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>GCP Load Balancer HTTPS proxy permits SSL policies with weak cipher suites</strong></td><td><p><strong>Changes–</strong> The policy RQL will be updated to improve accuracy and reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-target-https-proxies' as X; config from cloud.resource where api.name = 'gcloud-compute-ssl-policies' as Y; filter " $.X.sslPolicy does not exist or ($.Y.profile equals COMPATIBLE and $.Y.selfLink contains $.X.sslPolicy) or ( ($.Y.profile equals MODERN or $.Y.profile equals CUSTOM) and $.Y.minTlsVersion does not equal TLS_1_2 and $.Y.selfLink contains $.X.sslPolicy ) or ( $.Y.profile equals CUSTOM and ( $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_128_GCM_SHA256 or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_256_GCM_SHA384 or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_128_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_256_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_3DES_EDE_CBC_SHA ) and $.Y.selfLink contains $.X.sslPolicy ) "; show X;
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-compute-target-https-proxies' as X; config from cloud.resource where api.name = 'gcloud-compute-ssl-policies' as Y; filter " $.X.sslPolicy does not exist or ($.Y.profile equals COMPATIBLE and $.Y.selfLink equals $.X.sslPolicy) or ( ($.Y.profile equals MODERN or $.Y.profile equals CUSTOM) and $.Y.minTlsVersion does not equal TLS_1_2 and $.Y.selfLink equals $.X.sslPolicy ) or ( $.Y.profile equals CUSTOM and ( $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_128_GCM_SHA256 or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_256_GCM_SHA384 or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_128_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_AES_256_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_RSA_WITH_3DES_EDE_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA or $.Y.enabledFeatures[*] contains TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA) and $.Y.selfLink equals $.X.sslPolicy ) "; show X;
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Medium. Existing alerts with an an SSL policy containing http proxy as a substring will be resolved as <code>Policy Updated</code>. New alerts will be generated for policy violations.</p></td></tr><tr><td><strong>AWS Network Load Balancer (NLB) is not using the latest predefined security policy</strong></td><td><p><strong>Changes–</strong> This Policy is updated with the latest AWS security policy recommendations.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = state.code equals active and type equals "network" and listeners[?any(protocol equals TLS and sslPolicy exists and sslPolicy does not contain ELBSecurityPolicy-TLS13-1-2-2021-06)] exists
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = state.code equals active and type equals "network" and listeners[?any(protocol equals TLS and sslPolicy exists and sslPolicy is not member of ('ELBSecurityPolicy-TLS13-1-2-Res-2021-06','ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04'))] exists
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Medium. Alerts will be generated for the NLBs not using the latest recommended security policies 'ELBSecurityPolicy-TLS13-1-2-Res-2021-06', 'ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04'. Open Alerts, which use either of the latest recommended security policies 'ELBSecurityPolicy-TLS13-1-2-Res-2021-06', 'ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04', will be resolved.</p></td></tr><tr><td><strong>Azure Network Watcher Network Security Group (NSG) flow logs are disabled</strong></td><td><p><strong>Changes–</strong> : The Policy RQL is updated to improve accuracy and reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-network-nsg-list' AND json.rule = (flowLogsSettings.storageId is not empty and flowLogsSettings.enabled is false) and tags.created-by does not contain "prismacloud-agentless-scan"
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-network-nsg-list' AND json.rule = ['flowLogsSettings'].['storageId'] exists and ['flowLogsSettings'].['storageId'] is not empty and ['flowLogsSettings'].['enabled'] is false and ['tags'].['created-by'] does not contain "prismacloud-agentless-scan"
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Medium</p><p><strong>Impact–</strong> Low. Alerts where the storage does not exist will be resolved.</p></td></tr><tr><td><strong>Azure Network Watcher Network Security Group (NSG) flow logs retention is less than 90 days</strong></td><td><p><strong>Changes–</strong> : The Policy RQL is updated to improve accuracy and reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-network-nsg-list' AND json.rule = (flowLogsSettings.retentionPolicy.days does not equal 0 and flowLogsSettings.retentionPolicy.days less than 90) and tags.created-by does not contain "prismacloud-agentless-scan"
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-network-nsg-list' AND json.rule = ['flowLogsSettings'].['retentionPolicy'].['days'] exists AND ['flowLogsSettings'].['retentionPolicy'].['days'] does not equal "0" AND ['flowLogsSettings'].['retentionPolicy'].['days'] less than 90 AND ['tags'].['created-by'] does not contain "prismacloud-agentless-scan"
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Alerts where the flow log retention does not exist will be resolved.</p></td></tr><tr><td><strong>Update 22 Azure NSG Policies</strong></td><td><p><strong>Changes–</strong> : Enhanced the policy RQLs to handle case-sensitive CSP attribute values, resulting in more accurate alert generation. Verified the provided RQL update for the following 24 policies:</p><ul><li>Azure Network Security Group allows all traffic on ports which are not commonly used</li><li>Azure Network Security Group allows all traffic on MySQL (TCP Port 3306)</li><li>Azure Network Security Group allows all traffic on Windows SMB (TCP Port 445)</li><li>Azure Network Security Group allows all traffic on FTP-Data (TCP Port 20)</li><li>Azure Network Security Group allows all traffic on CIFS (UDP Port 445)</li><li>Azure Network Security Group allows all traffic on PostgreSQL (TCP Port 5432)</li><li>Azure Network Security Group allows all traffic on SQL Server (UDP Port 1434)</li><li>Azure Network Security Group allows all traffic on NetBIOS DNS (UDP Port 53)</li><li>Azure Network Security Group allows all traffic on FTP (TCP Port 21)</li><li>Azure Network Security Group having Inbound rule overly permissive to all traffic on UDP protocol</li><li>Azure Network Security Group allows all traffic on NetBIOS (UDP Port 137)</li><li>Azure Network Security Group allows all traffic on SMTP (TCP Port 25)</li><li>Azure Network Security Group having Inbound rule overly permissive to all traffic on TCP protocol</li><li>Azure Network Security Group allows all traffic on NetBIOS (UDP Port 138)</li><li>Azure Network Security Group allows all traffic on ICMP (Ping)</li><li>Azure Network Security Group allows all traffic on Windows RPC (TCP Port 135)</li><li>Azure Network Security Group allows all traffic on SQL Server (TCP Port 1433)</li><li>Azure Network Security Group allows all traffic on NetBIOS DNS (TCP Port 53)</li><li>Azure Network Security Group allows all traffic on MSQL (TCP Port 4333)</li><li>Azure Network Security Group allows all traffic on VNC Server (TCP Port 5900)</li><li>Azure Network Security Group allows all traffic on VNC Listener (TCP Port 5500)</li><li>Azure Network Security Group allows all traffic on Telnet (TCP Port 23)</li></ul></td></tr><tr><td><strong>AWS IAM user is not a member of any IAM group</strong></td><td><p><strong>Changes–</strong> : The Policy RQL is updated to improve accuracy and reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-iam-list-users' AND json.rule = groupList is empty
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-iam-list-users' AND json.rule = groupList is empty and userId does not equal ignore case "root"
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Informational</p><p><strong>Impact–</strong> Low. Alerts will be resolved only for user root user, as root user cannot be added to IAM Groups.</p></td></tr><tr><td><strong>Policy Updates—Metadata</strong></td><td></td></tr><tr><td><strong>AWS S3 bucket publicly writable</strong></td><td><p><strong>Policy Update–</strong> A note is added to the description indicating the exclusion of S3 buckets hosting public static websites.</p><p><strong>Current Description–</strong></p><p>Publicly writable AWS S3 buckets allow unauthorized access to sensitive data stored within. This misconfiguration exposes data to malicious actors and data breaches.</p><p>The S3 service relies on Access Control Lists (ACLs) and bucket policies to manage access. Incorrectly configured ACLs or bucket policies that grant 'Put', 'Create', 'Update', 'Replicate', 'Write', or 'Delete' permissions to the world, allow anyone to modify or delete bucket contents. This exposes data to unauthorized access, modification, or deletion.</p><p>A successful attack could lead to data exfiltration, modification, or deletion, resulting in significant financial, legal, and reputational damage. Best practices dictate strict control over S3 bucket permissions to prevent unauthorized access. Data loss and compliance violations are possible consequences.</p><p>Implement least privilege access controls. Restrict access to only trusted users and services via appropriately configured ACLs and bucket policies. Regularly review and audit S3 bucket permissions to identify and rectify any misconfigurations. Use strong encryption to protect data at rest and in transit. Employ multi-factor authentication (MFA) for enhanced security.</p><p><strong>Proposed Description–</strong></p><p>Publicly writable AWS S3 buckets allow unauthorized access to sensitive data stored within. This misconfiguration exposes data to malicious actors and data breaches.</p><p>The S3 service relies on Access Control Lists (ACLs) and bucket policies to manage access. Incorrectly configured ACLs or bucket policies that grant 'Put', 'Create', 'Update', 'Replicate', 'Write', or 'Delete' permissions to the world, allow anyone to modify or delete bucket contents. This exposes data to unauthorized access, modification, or deletion.</p><p>A successful attack could lead to data exfiltration, modification, or deletion, resulting in significant financial, legal, and reputational damage. Best practices dictate strict control over S3 bucket permissions to prevent unauthorized access. Data loss and compliance violations are possible consequences.</p><p>Implement least privilege access controls. Restrict access to only trusted users and services via appropriately configured ACLs and bucket policies. Regularly review and audit S3 bucket permissions to identify and rectify any misconfigurations. Use strong encryption to protect data at rest and in transit. Employ multi-factor authentication (MFA) for enhanced security.</p><p><strong>Note</strong>: This policy excludes AWS S3 buckets that are configured to host public static websites.</p><p><strong>Policy Type</strong>: Config</p><p><strong>Policy Severity</strong>: High</p><p><strong>Alerts Impact</strong>: No impact</p><p><strong>Impact</strong>: Low</p></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2025/features-introduced-in-december-2025.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
