> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2025/features-introduced-in-february-2025.md).

# Features Introduced in February 2025

Learn what’s new on Prisma® Cloud in February 2025.

* [New Features](#new-features)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [IAM Policy Updates](#iam-policy-updates)
* [REST API Updates](#rest-api-updates)
* [Deprecation Notices](#deprecation-notices)

## New Features

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Feature</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>IAM Enhancement</strong></td><td><p>Updates to the IAM capabilities allow you to map users by filtering results using userPrincipalName (UPN). You can now use the existing <code>grantedby.level.type</code>, <code>grantedby.level.name</code>, and <code>grantedby.level.id</code> attributes in RQL queries to identify users by their UPN. For example:</p><pre><code>config from iam where source.cloud.type = 'AZURE' and source.cloud.azure.userprincipalname = 'my user principal name'
</code></pre></td></tr><tr><td><strong>CIEM Enhancement</strong></td><td><p>Enhancements to the Cloud Infrastructure and Entitlement Management (CIEM) capabilities provide greater visibility and control over Microsoft Azure permissions at the resource group level, helping you secure your identities with greater efficiency. You can now use the existing <code>grantedby.level.type</code>, <code>grantedby.level.name</code>, and <code>grantedby.level.id</code> attributes in RQL queries to investigate resource group specific Azure permissions. For example:</p><pre><code>`config from iam where grantedby.level.type = 'Azure Resource Group'`
</code></pre></td></tr></tbody></table>

## API Ingestions

| **Service**                                                                                            | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Amazon API Gateway**                                                                                 | <p><strong>aws-apigatewayv2-authorizer</strong></p><p>Additional permission needed:</p><ul><li><code>apigateway:GET</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Amazon API Gateway**                                                                                 | <p><strong>aws-apigatewayv2-domain-name</strong></p><p>Additional permission needed:</p><ul><li><code>apigateway:GET</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Amazon API Gateway**                                                                                 | <p><strong>aws-apigatewayv2-integration</strong></p><p>Additional permission needed:</p><ul><li><code>apigateway:GET</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Amazon CloudWatch Synthetics**                                                                       | <p><strong>aws-cloudwatch-synthetics-canary</strong></p><p>Additional permission needed:</p><ul><li><code>synthetics:DescribeCanaries</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Amazon DynamoDB**                                                                                    | <p><strong>aws-dynamo-db-global-table</strong></p><p>Additional permissions needed:</p><ul><li><code>dynamodb:ListGlobalTables</code></li><li><code>dynamodb:DescribeGlobalTable</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Amazon DynamoDB**                                                                                    | <p><strong>aws-dynamo-db-backup</strong></p><p>Additional permissions needed:</p><ul><li><code>dynamodb:ListBackups</code></li><li><code>dynamodb:DescribeBackup</code></li></ul><p>The Security Audit role only includes the <code>dynamodb:ListBackups</code> permission. You must manually add the <code>dynamodb:DescribeBackup</code> permission to the CFT template to enable it.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <mark style="background-color:orange;">Update</mark> **Amazon DynamoDB**                               | <p><strong>aws-dynamodb-describe-table</strong></p><p>The JSON resource for this API has been updated to include <code>timeToLiveDescription</code> field.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Amazon EventBridge**                                                                                 | <p><strong>aws-event-bridge-global-endpoint</strong></p><p>Additional permission needed:</p><ul><li><code>events:ListEndpoints</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Amazon EventBridge Scheduler**                                                                       | <p><strong>aws-event-bridge-scheduler-schedule</strong></p><p>Additional permissions needed:</p><ul><li><code>scheduler:ListSchedules</code></li><li><code>scheduler:GetSchedule</code></li></ul><p>The Security Audit role does not include the permissions. You must manually add the permissions to the CFT template to enable them.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Amazon GuardDuty**                                                                                   | <p><strong>aws-guardduty-member-account-admin-info</strong></p><p>Additional permissions needed:</p><ul><li><code>guardduty:ListDetectors</code></li><li><code>guardduty:GetAdministratorAccount</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Amazon GuardDuty**                                                                                   | <p><strong>aws-guardduty-trusted-ip-list</strong></p><p>Additional permissions needed:</p><ul><li><code>guardduty:ListDetectors</code></li><li><code>guardduty:ListIPSets</code></li><li><code>guardduty:GetIPSet</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Amazon GuardDuty**                                                                                   | <p><strong>aws-guardduty-threat-ip-list</strong></p><p>Additional permissions needed:</p><ul><li><code>guardduty:ListDetectors</code></li><li><code>guardduty:ListThreatIntelSets</code></li><li><code>guardduty:GetThreatIntelSet</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **AWS IAM**                                                                                            | <p><strong>aws-iam-instance-profile</strong></p><p>Additional permissions needed:</p><ul><li><code>iam:ListInstanceProfiles</code></li><li><code>iam:GetInstanceProfile</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **AWS IAM Identity Center**                                                                            | <p><strong>aws-iam-identity-center-permission-set-provisioning-status</strong></p><p>Additional permissions needed:</p><ul><li><code>sso:ListInstances</code></li><li><code>sso:ListPermissionSetProvisioningStatus</code></li><li><code>sso:DescribePermissionSetProvisioningStatus</code></li></ul><p>The Security Audit role only includes the <code>sso:ListInstances</code> and <code>sso:ListPermissionSetProvisioningStatus</code> permissions. You must manually add the <code>sso:DescribePermissionSetProvisioningStatus</code> permission in the CFT template to enable it.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **AWS IAM Identity Center**                                                                            | <p><strong>aws-iam-identity-center-permission-set</strong></p><p>Additional permissions needed:</p><ul><li><code>sso:ListInstances</code></li><li><code>sso:ListPermissionSets</code></li><li><code>sso:DescribePermissionSets</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **AWS IAM Identity Center**                                                                            | <p><strong>aws-iam-identity-center-application</strong></p><p>Additional permissions needed:</p><ul><li><code>sso:ListInstances</code></li><li><code>sso:ListApplications</code></li><li><code>sso:ListApplicationAssignments</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>AWS KMS</strong></p><p><mark style="background-color:orange;">Update</mark></p>             | <p><strong>aws-kms-get-key-rotation-status</strong></p><p>Additional permissions needed:</p><ul><li><code>kms:ListKeyRotations</code></li></ul><p>The Security Audit role includes the permission.</p><p>Also, the JSON resource for this API has been updated to include the following new fields:</p><ul><li><code>nextRotationDate</code></li><li><code>rotationPeriodInDays</code></li><li><code>previousKeyRotations</code></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **AWS Lambda**                                                                                         | <p><strong>aws-lambda-event-source-mapping</strong></p><p>Additional permissions needed:</p><ul><li><code>lambda:ListEventSourceMappings</code></li><li><code>lambda:GetEventSourceMapping</code></li></ul><p>The Security Audit role only includes the <code>lambda:ListEventSourceMappings</code> permission. You must manually add the <code>lambda:GetEventSourceMapping</code> permission to the CFT template to enable it.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **AWS Lambda**                                                                                         | <p><strong>aws-lambda-get-layer-version</strong></p><p>Additional permissions needed:</p><ul><li><code>lambda:ListLayers</code></li><li><code>lambda:ListLayerVersions</code></li><li><code>lambda:GetLayerVersion</code></li></ul><p>The Security Audit role only includes the <code>lambda:ListLayers</code> and <code>lambda:ListLayerVersions</code> permissions. You must manually add the <code>lambda:GetLayerVersion</code> permission to the CFT template to enable it.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **Amazon VPC Lattice**                                                                                 | <p><strong>aws-vpc-lattice-service</strong></p><p>Additional permissions needed:</p><ul><li><code>vpc-lattice:ListServices</code></li><li><code>vpc-lattice:GetService</code></li><li><code>vpc-lattice:ListTagsForResource</code></li></ul><p>The Security Audit role does not include the permissions. You must manually add the permissions to the CFT template to enable them.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Amazon VPC Lattice**                                                                                 | <p><strong>aws-vpc-lattice-target-group</strong></p><p>Additional permissions needed:</p><ul><li><code>vpc-lattice:ListTargetGroups</code></li><li><code>vpc-lattice:GetTargetGroup</code></li><li><code>vpc-lattice:ListTagsForResource</code></li></ul><p>The Security Audit role does not include the permissions. You must manually add the permissions to the CFT template to enable them.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Amazon VPC Lattice**                                                                                 | <p><strong>aws-vpc-lattice-service-listener</strong></p><p>Additional permissions needed:</p><ul><li><code>vpc-lattice:ListServices</code></li><li><code>vpc-lattice:ListListeners</code></li><li><code>vpc-lattice:GetListener</code></li><li><code>vpc-lattice:ListTagsForResource</code></li></ul><p>The Security Audit role does not include the permissions. You must manually add the permissions to the CFT template to enable them.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Amazon VPC Lattice**                                                                                 | <p><strong>aws-vpc-lattice-service-network-vpc-association</strong></p><p>Additional permissions needed:</p><ul><li><code>vpc-lattice:ListServiceNetworks</code></li><li><code>vpc-lattice:ListServiceNetworkVpcAssociations</code></li><li><code>vpc-lattice:ListTagsForResource</code></li></ul><p>The Security Audit role does not include the permissions. You must manually add the permissions to the CFT template to enable them.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Amazon VPC Lattice**                                                                                 | <p><strong>aws-vpc-lattice-service-network-service-association</strong></p><p>Additional permissions needed:</p><ul><li><code>vpc-lattice:ListServices</code></li><li><code>vpc-lattice:ListServiceNetworkServiceAssociations</code></li><li><code>vpc-lattice:ListTagsForResource</code></li></ul><p>The Security Audit role does not include the permissions. You must manually add the permissions to the CFT template to enable them.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Azure Container Registry**                                                                           | <p><strong>azure-container-registry-cache-rules</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.ContainerRegistry/registries/read</code></li><li><code>Microsoft.ContainerRegistry/registries/cacheRules/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Azure Data Protection**                                                                              | <p><strong>azure-data-protection-backup-vaults</strong></p><p>Additional permission needed:</p><ul><li><code>Microsoft.DataProtection/backupVaults/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Azure Data Protection**                                                                              | <p><strong>azure-data-protection-backup-instances</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.DataProtection/backupVaults/read</code></li><li><code>Microsoft.DataProtection/backupVaults/backupInstances/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Azure Data Protection**                                                                              | <p><strong>azure-data-protection-backup-policies</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.DataProtection/backupVaults/read</code></li><li><code>Microsoft.DataProtection/backupVaults/backupPolicies/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Azure Data Protection**                                                                              | <p><strong>azure-data-protection-jobs</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.DataProtection/backupVaults/read</code></li><li><code>Microsoft.DataProtection/backupVaults/backupJobs/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Azure Data Protection**                                                                              | <p><strong>azure-data-protection-recovery-points</strong></p><p>Additional permissions needed:</p><ul><li><code>Microsoft.DataProtection/backupVaults/read</code></li><li><code>Microsoft.DataProtection/backupVaults/backupInstances/read</code></li><li><code>Microsoft.DataProtection/backupVaults/backupInstances/recoveryPoints/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>Azure Kusto</strong></p><p><mark style="background-color:orange;">Update</mark></p>         | <p>Microsoft Azure has deprecated the <code>Microsoft.Kusto/clusters/read/read</code> permission. Due to this change, the permission has been removed from Prisma Cloud CFT template since it is no longer needed.</p><p>The alternative permission is <code>Microsoft.Kusto/Clusters/read</code> and is already part of the Prisma Cloud CFT template.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Azure Network Manager**                                                                              | <p><strong>azure-network-manager</strong></p><p>Additional permission needed:</p><ul><li><code>Microsoft.Network/networkManagers/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Azure SQL Databases</strong></p><p><mark style="background-color:orange;">Update</mark></p> | <p><strong>azure-sql-db-data-masking-policies</strong></p><p><strong>azure-sql-db-data-masking-rules</strong></p><p><strong>azure-sql-db-transparent-data-encryption</strong></p><p>These APIs now restrict data fetching to when the database is in the 'Online' or 'Ready' states. This ensures operations are only performed during these optimal states. This targeted approach prevents data fetching in any other non-active states effectively reducing costs and improving performance.</p><p>Behaviour when the database transitions into a 'Paused' state or any other non-optimal state:</p><ul><li>Data ingestion for affected resources is suspended.</li><li>The deleted status for these specific resources in Prisma is set to 'true'.</li><li>All alerts related to the paused resources are automatically marked as resolved during this pause.</li></ul><p>Upon the database’s return to an 'Online' state, and when data ingestion recommences:</p><ul><li>The 'deleted' status in Prisma is reverted to 'false'.</li><li>Any alerts that were marked as resolved during the pause are reopened.</li></ul> |
| **Google Dataproc Clusters**                                                                           | <p><strong>gcloud-dataproc-serverless-batch</strong></p><p>Additional permissions required:</p><ul><li><code>dataproc.batches.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Google Dataproc Clusters**                                                                           | <p><strong>gcloud-dataproc-serverless-session</strong></p><p>Additional permissions required:</p><ul><li><code>dataproc.sessions.list</code></li></ul><p>The Viewer role includes the permission.</p><p>Only ACTIVE sessions will be ingested and TERMINATED sessions will be deleted in the Prisma Cloud console.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Google Dataproc Clusters**                                                                           | <p><strong>gcloud-dataproc-serverless-session-template</strong></p><p>Additional permissions required:</p><ul><li><code>dataproc.sessionTemplates.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>AWS S3 Buckets Block public access bucket policy setting disabled</strong></td><td><p><strong>Policy Description—</strong> AWS S3 buckets with the 'Block public access' setting disabled or 'Block public access to buckets and objects granted through new public bucket or access point policies' setting or 'Block public and cross-account access to buckets and objects through any public bucket or access point policies' disabled pose a significant security risk, allowing unauthorized access to sensitive data.</p><p>The 'Block public access' setting in Amazon S3 controls public accessibility of buckets and objects. Disabling this setting, either intentionally or through misconfiguration, exposes data to the internet, potentially leading to data breaches, unauthorized modification, or ransomware attacks by malicious actors or accidental exposure.</p><p>The impact of this misconfiguration can range from data loss and regulatory non-compliance to reputational damage and financial losses. Enabling this setting ensures only authorized users can access the data, minimizing the risk of data breaches and improving overall security posture.</p><p>To mitigate this risk, enable the 'Block all public access' setting for all S3 buckets. Alternatively, use 'Block public access to buckets and objects granted through new public bucket or access point policies' and 'Block public and cross-account access to buckets and objects through any public bucket or access point policies', depending on your specific requirements. Regularly review and audit S3 bucket configurations to prevent accidental or malicious changes.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name='aws-s3api-get-bucket-acl' AND json.rule = "((publicAccessBlockConfiguration does not exist or publicAccessBlockConfiguration.blockPublicPolicy is false) and (accountLevelPublicAccessBlockConfiguration does not exist or accountLevelPublicAccessBlockConfiguration.blockPublicPolicy is false)) or ((publicAccessBlockConfiguration does not exist or publicAccessBlockConfiguration.restrictPublicBuckets is false) and (accountLevelPublicAccessBlockConfiguration does not exist or accountLevelPublicAccessBlockConfiguration.restrictPublicBuckets is false))"
</code></pre></td></tr><tr><td><strong>AWS S3 Buckets Block public access ACL setting disabled</strong></td><td><p><strong>Policy Description—</strong> AWS S3 buckets with 'Block public access to buckets and objects granted through new access control lists (ACLs)' setting or 'Block public access to buckets and objects granted through any access control lists (ACLs)' disabled.</p><p>The "Block public access" setting within AWS S3 bucket configurations controls public accessibility. Disabling this setting exposes stored data to the internet, potentially leading to data breaches, unauthorized modifications, or complete data loss through malicious actors exploiting this misconfiguration. Untrusted entities could gain access, compromising sensitive information.</p><p>The impact of this misconfiguration can range from data loss and regulatory non-compliance to reputational damage and financial losses. Enabling this setting ensures only authorized users can access the data, minimizing the risk of data breaches and improving overall security posture.</p><p>To mitigate this risk, ensure all S3 buckets have the "Block public access" setting enabled or 'Block public access to buckets and objects granted through new access control lists (ACLs)' setting or 'Block public access to buckets and objects granted through any access control lists (ACLs)' for all AWS s3 buckets appropriately. Regularly review and audit S3 bucket configurations to identify and remediate any instances where this setting is disabled. Implement strong access control lists (ACLs) and consider using other security measures such as encryption and multi-factor authentication to enhance protection.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name='aws-s3api-get-bucket-acl' AND json.rule = "((publicAccessBlockConfiguration does not exist or publicAccessBlockConfiguration.blockPublicAcls is false) and (accountLevelPublicAccessBlockConfiguration does not exist or accountLevelPublicAccessBlockConfiguration.blockPublicAcls is false)) or ((publicAccessBlockConfiguration does not exist or publicAccessBlockConfiguration.ignorePublicAcls is false) and (accountLevelPublicAccessBlockConfiguration does not exist or accountLevelPublicAccessBlockConfiguration.ignorePublicAcls is false))"
</code></pre></td></tr><tr><td><strong>AWS S3 bucket having ACL write permission to all users or allAuthenticatedUsers</strong></td><td><p><strong>Policy Description—</strong> This policy identifies AWS S3 buckets having ACL write permission to all users or allAuthenticatedUsers.</p><p>AWS S3 Access Control Lists (ACLs) offer granular control over object access within a bucket. Granting "Write" or "FullControl" permissions to "AllUsers" or "AuthenticatedUsers" poses a significant security risk, potentially exposing sensitive data to unauthorized access or modification. Best practices emphasize restricting access to only authorized users and groups based on the principle of least privilege.</p><p>To mitigate this risk, configure S3 bucket policies and ACLs to explicitly grant permissions to specific users or groups requiring access.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-s3api-get-bucket-acl' AND json.rule = policyStatus.isPublic is true and acl.grants[?any( grantee is member of ( 'AllUsers', 'AuthenticatedUsers' ) and permission is member of (Write,FullControl) )] exists
</code></pre></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>Azure Function App doesn’t use latest TLS version</strong></td><td><p><strong>Changes—</strong> The policy description and reccomendation steps are updated. Also, the RQL policy is updated to consider the latest TLS version 1.3.</p><p><strong>Current Description–</strong> This policy identifies Azure Function Apps that are not set with the latest version of TLS encryption. Azure currently allows the Function App to set TLS versions 1.0, 1.1, and 1.2. Using the latest TLS 1.2 version for Function App secure connections is highly recommended.</p><p><strong>Updated Description–</strong> This policy identifies Azure Function App which are not set with the latest version of TLS encryption.</p><p>Azure currently allows the Function App to set TLS versions 1.0, 1.1, 1.2, and 1.3. TLS 1.0 and 1.1 are no longer regarded as secure protocols and are deemed outdated.</p><p>As a security best practice, TLS 1.2 or above is typically advised as the minimum TLS version for Azure function apps. </p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case "Running" AND kind contains "functionapp" AND kind does not contain "workflowapp" AND kind does not equal "app" AND config.minTlsVersion does not equal "1.2"
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case "Running" AND kind contains "functionapp" AND kind does not contain "workflowapp" AND kind does not equal "app" AND config.minTlsVersion is not member of ("1.2", "1.3")
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Existing alerts where the minTlsVersion is set to 1.3 will be resolved.</p></td></tr><tr><td><strong>Azure Storage Account default network access is set to 'Allow'</strong></td><td><p><strong>Changes—</strong> The policy RQL is updated to reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-storage-account-list' AND json.rule = 'networkRuleSet.defaultAction equals Allow'
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-storage-account-list' AND json.rule = properties.publicNetworkAccess equal ignore case "Enabled" AND networkRuleSet.defaultAction equal ignore case "Allow"
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Informational</p><p><strong>Impact–</strong> Low. Existing alerts where the storage account is not publicly accessible from all networks will be resolved.</p></td></tr><tr><td><strong>GCP Log metric filter and alert does not exist for VPC network changes</strong></td><td><p><strong>Changes—</strong> The policy description and reccomendation steps are updated align with current standards of the policy. Also, the RQL is updated to stay in line with the CSP changes.</p><p><strong>Current Description–</strong> This policy identifies the GCP account which does not have a log metric filter and alert for VPC network changes. Monitoring network insertion, patching, deletion, removePeering and addPeering activities will help in identifying VPC traffic flow is not getting impacted. It is recommended to create a metric filter and alarm to detect activities related to the insertion, patching, deletion, removePeering and addPeering of VPC network.</p><p><strong>Updated Description–</strong> This policy identifies GCP accounts that do not have a log metric filter and alert for VPC network changes.</p><p>Without proper monitoring of activities like network insertions, patching, deletions, and peering modifications, organizations risk undetected misconfigurations that could compromise network security and impact traffic flow. Real-time alerts on these events are crucial for rapid response to malicious activity or accidental changes, ensuring network integrity and availability. Establishing these monitoring capabilities provides a critical layer of visibility and control over VPC network configurations.</p><p>It is recommended to create a log metric filter and alert configuration in your GCP project for VPC network changes. This will enable proactive detection of unauthorized modifications and ensure the integrity and security of your VPC network.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-logging-metric' as X; config from cloud.resource where api.name = 'gcloud-monitoring-policies-list' as Y; filter '$.Y.conditions[*].metricThresholdFilter contains $.X.name and ($.X.filter contains "resource.type =" or $.X.filter contains "resource.type=") and ($.X.filter does not contain "resource.type !=" and $.X.filter does not contain "resource.type!=") and $.X.filter contains "gce_network" and ($.X.filter contains "jsonPayload.event_subtype=" or $.X.filter contains "jsonPayload.event_subtype =") and ($.X.filter does not contain "jsonPayload.event_subtype!=" and $.X.filter does not contain "jsonPayload.event_subtype !=") and $.X.filter contains "compute.networks.insert" and $.X.filter contains "compute.networks.patch" and $.X.filter contains "compute.networks.delete" and $.X.filter contains "compute.networks.removePeering" and $.X.filter contains "compute.networks.addPeering"'; show X; count(X) less than 1
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-logging-metric' as X; config from cloud.resource where api.name = 'gcloud-monitoring-policies-list' as Y; filter '$.Y.conditions[*].metricThresholdFilter contains $.X.name and ($.X.filter contains "resource.type =" or $.X.filter contains "resource.type=") and ($.X.filter does not contain "resource.type !=" and $.X.filter does not contain "resource.type!=") and $.X.filter contains "gce_network" and ((($.X.filter contains "protoPayload.methodName=" or $.X.filter contains "protoPayload.methodName =") or ($.X.filter contains "protoPayload.methodName:" or $.X.filter contains "protoPayload.methodName :")) and (($.X.filter does not contain "protoPayload.methodName!=" and $.X.filter does not contain "protoPayload.methodName !=") or ($.X.filter does not contain "protoPayload.methodName!:" and $.X.filter does not contain "protoPayload.methodName !:"))) and $.X.filter contains "compute.networks.insert" and $.X.filter contains "compute.networks.patch" and $.X.filter contains "compute.networks.delete" and $.X.filter contains "compute.networks.removePeering" and $.X.filter contains "compute.networks.addPeering"'; show X; count(X) less than 1
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Informational</p><p><strong>Impact–</strong> Low. New alerts will be generated for failing resources.</p></td></tr><tr><td><strong>GCP Log metric filter and alert does not exist for VPC Network Firewall rule changes</strong></td><td><p><strong>Changes—</strong> The policy description and reccomendation steps are updated align with current standards of the policy. Also, the RQL is updated to stay in line with the CSP changes.</p><p><strong>Current Description–</strong> This policy identifies the GCP account which does not have a log metric filter and alert for VPC network changes. Monitoring network insertion, patching, deletion, removePeering and addPeering activities will help in identifying VPC traffic flow is not getting impacted. It is recommended to create a metric filter and alarm to detect activities related to the insertion, patching, deletion, removePeering and addPeering of VPC network.</p><p><strong>Updated Description–</strong> This policy identifies GCP projects that do not have log metric filters and alerts for VPC Network Firewall rule modifications.</p><p>VPC Network Firewall rules govern network traffic flow, and unauthorized changes can severely impact security and availability. Without real-time monitoring and alerting on rule modifications (additions, deletions, or updates), organizations are vulnerable to undetected attacks, misconfigurations, and performance issues. Proactive alerts enable swift responses to suspicious activity, preventing breaches and ensuring business continuity. Implementing this monitoring provides crucial visibility and control over network security posture.</p><p>It is recommended to configure log metric filters and alerts within your GCP projects to monitor all VPC Network Firewall rule changes. This will enable prompt detection of unauthorized modifications, facilitating rapid remediation and maintaining the integrity and security of your network infrastructure.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-logging-metric' as X; config from cloud.resource where api.name = 'gcloud-monitoring-policies-list' as Y; filter '($.Y.conditions[*].metricThresholdFilter contains $.X.name) and ($.X.filter contains "resource.type =" or $.X.filter contains "resource.type=") and ($.X.filter does not contain "resource.type !=" and $.X.filter does not contain "resource.type!=") and $.X.filter contains "gce_firewall_rule" and ($.X.filter contains "jsonPayload.event_subtype=" or $.X.filter contains "jsonPayload.event_subtype =") and ($.X.filter does not contain "jsonPayload.event_subtype!=" and $.X.filter does not contain "jsonPayload.event_subtype !=") and $.X.filter contains "compute.firewalls.patch" and $.X.filter contains "compute.firewalls.insert"'; show X; count(X) less than 1
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'gcloud-logging-metric' as X; config from cloud.resource where api.name = 'gcloud-monitoring-policies-list' as Y; filter '($.Y.conditions[*].metricThresholdFilter contains $.X.name) and ($.X.filter contains "resource.type =" or $.X.filter contains "resource.type=") and ($.X.filter does not contain "resource.type !=" and $.X.filter does not contain "resource.type!=") and $.X.filter contains "gce_firewall_rule" and ((($.X.filter contains "protoPayload.methodName=" or $.X.filter contains "protoPayload.methodName =") or ($.X.filter contains "protoPayload.methodName:" or $.X.filter contains "protoPayload.methodName :")) and (($.X.filter does not contain "protoPayload.methodName!=" and $.X.filter does not contain "protoPayload.methodName !=") or ($.X.filter does not contain "protoPayload.methodName!:" and $.X.filter does not contain "protoPayload.methodName !:"))) and $.X.filter contains "compute.firewalls.patch" and $.X.filter contains "compute.firewalls.insert" and $.X.filter contains "compute.firewalls.delete"'; show X; count(X) less than 1
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Informational</p><p><strong>Impact–</strong> Low. New alerts will be generated for failing resources.</p></td></tr><tr><td><strong>Policy Updates - Metadata</strong></td><td></td></tr><tr><td><strong>Azure App service HTTP logging is disabled</strong></td><td><p><strong>Changes—</strong> The recommendation steps are updated.</p><p><strong>Current Recommendation Steps–</strong></p><ol><li>Log in to Azure Portal</li><li>Go to App Services dashboard</li><li>Click on the reported App service</li><li>Under the 'Monitoring' menu, click on 'App Service logs'</li><li>Under 'Web server logging', select Storage to store logs on blob storage, or File System to store logs on the App Service file system.</li><li>In Retention Period (Days), set the number of days the logs should be retained.</li><li>Click on 'Save'</li></ol><p>As a security best practice, it is recommended to disable public network access for Azure Virtual Machine disks.</p><p><strong>Updated Recommendation Steps–</strong></p><p>Configuring http logging via User Interface varies depending on the type of Azure App Service.</p><p>Alternatively, you may use the CLI command below to configure http logging for all kinds of Azure App Service:</p><p><code>az webapp log config --name &#x3C;App name> --resource-group &#x3C;Resource Group Name> --web-server-logging filesystem</code></p><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> No impact on alerts.</p></td></tr><tr><td><strong>GCP Log metric filter and alert does not exist for Project Ownership assignments/changes</strong></td><td><p><strong>Changes—</strong> The policy description is updated to better align with the policy.</p><p><strong>Current Description–</strong> This policy identifies the GCP account which does not have a log metric filter and alert for Project Ownership assignments/changes. Project Ownership Having highest level of privileges on a project, to avoid misuse of project resources project ownership assignment/change actions mentioned should be monitored and alerted to concerned recipients.</p><p><strong>Updated Description–</strong> This policy identifies GCP projects that do not have log metric filters and alert for project ownership assignments and changes.</p><p>Project ownership grants extensive privileges. Without monitoring ownership changes, organizations risk unauthorized access, resource misappropriation, and potential security breaches. Real-time alerts on ownership transfers enable prompt detection of suspicious activity, facilitating rapid response and minimizing the impact of compromised accounts. Establishing this monitoring provides crucial visibility and control over project access, improving overall security posture.</p><p>It is recommended to configure log metric filters and alerts for project ownership changes in all GCP projects. This proactive approach ensures that any changes to project ownership are immediately flagged, allowing for timely investigation and mitigation of potential risks.</p><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Informational</p><p><strong>Impact–</strong> Low. New alerts will be generated for the failing resources.</p></td></tr><tr><td><strong>GCP IAM user with service account privileges</strong></td><td><p><strong>Changes—</strong> The policy name and description are updated to better align with the policy.</p><p><strong>Current Policy Name–</strong> GCP IAM user with service account privileges</p><p><strong>Updated Policy Name–</strong> GCP IAM principals with service account privileges</p><p><strong>Current Description–</strong> This policy identifies IAM users which have overly permissive service account privileges. Any user should not have Service Account Admin and Service Account User, both roles assigned at a time. Built-in/Predefined IAM role Service Account admin allows the user to create, delete, manage service accounts. Built-in/Predefined IAM role Service Account User allows the user to assign service accounts to Apps/Compute Instances. It is recommended to follow the principle of 'Separation of Duties' ensuring that one individual does not have all the necessary permissions to be able to complete a malicious action or meant to help avoid security or privacy incidents and errors.</p><p><strong>Updated Description–</strong> This policy identifies IAM principals which have overly permissive service account privileges.</p><p>Assigning a principals the Service account role in Google Cloud allows them to  impersonate service accounts and use their permissions. This means the principals can perform actions on behalf of the service account, essentially inheriting all permissions granted to that service account.</p><p>To maintain the security of your information and resources, it is crucial to assign this role only to authorized and trusted IAM Principals. </p><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> No impact on alerts.</p></td></tr><tr><td><strong>Config Policy Updates</strong></td><td><p><strong>Changes—</strong> The descriptions are updated for the following policies:</p><ul><li>AWS Cognito service role with wide privileges does not validate authentication</li><li>AWS Access key enabled on root account</li><li>AWS Lambda function managed ENI reachable from any untrust internet source</li><li>AWS Redshift managed ENI reachable from any untrust internet source</li><li>AWS RDS instance with network path from the untrust internet source</li><li>AWS Redshift cluster with network path from the untrust internet source</li><li>AWS Systems Manager EC2 instance having NON_COMPLIANT patch compliance status</li><li>AWS CloudTrail S3 bucket encrypted with Customer Managed Key (CMK) that is scheduled for deletion</li><li>AWS RDS managed ENI reachable from any untrust internet source</li><li>AWS EC2 instance with network path from the untrust internet source on ports with high risk</li><li>AWS Route53 Hosted Zone having dangling DNS record with subdomain takeover risk associated with AWS S3 Bucket</li><li>AWS Route53 Hosted Zone having dangling DNS record with subdomain takeover risk associated with AWS Elastic Beanstalk Instance</li><li>AWS EKS K8s service with network path from the internet (0.0.0.0/0)</li><li>AWS EC2 instance with network path from the internet (0.0.0.0/0)</li><li>AWS EC2 instance with network path from the internet (0.0.0.0/0) on Admin ports</li><li>AWS EC2 instance with network path from the internet (0.0.0.0/0) on ports 80/443</li><li>AWS EC2 instance not configured with Instance Metadata Service v2 (IMDSv2)</li><li>AWS Lambda function URL AuthType set to NONE</li><li>AWS S3 bucket not configured with secure data transport policy</li><li>AWS Lambda function URL having overly permissive cross-origin resource sharing permissions</li><li>AWS S3 bucket policy overly permissive to any principal</li><li>AWS S3 buckets with configurations set to host websites</li><li>AWS S3 bucket publicly readable</li><li>AWS Access logging not enabled on S3 buckets</li><li>AWS S3 bucket accessible to unmonitored cloud accounts</li><li>AWS S3 buckets are accessible to any authenticated user</li><li>AWS S3 bucket used for storing AWS Sagemaker training job output</li><li>AWS S3 bucket encrypted with Customer Managed Key (CMK) is not enabled for regular rotation</li><li>AWS S3 bucket is not configured with MFA Delete</li><li>AWS S3 bucket publicly writable</li><li>AWS S3 bucket encrypted using Customer Managed Key (CMK) with overly permissive policy</li><li>AWS S3 bucket is utilized for AWS Sagemaker training job data</li><li>AWS EC2 instance with network path to the internet (0.0.0.0/0)</li><li>AWS EKS K8s service with network path from the internet (0.0.0.0/0) on ports 80/443</li><li>AWS EKS K8s service with network path from the untrust internet source on ports with high risk</li><li>Azure Virtual machine configured with public IP and serial console access</li><li>Azure Function app configured with public network access</li><li>Azure Storage account encryption key is not rotated regularly</li><li>Azure Virtual Machine with network path from the internet (0.0.0.0/0) on ports 80/443</li><li>Azure Virtual Machine with network path from the internet (0.0.0.0/0) on Admin ports</li><li>Azure SQL server not configured with Active Directory admin authentication</li><li>Azure App Service Web app authentication is off</li><li>Azure Storage Account storing Cognitive service diagnostic logs is publicly accessible</li><li>Azure SQL on Virtual Machine (Linux) with basic authentication</li><li>Azure App Services Remote debugging is enabled</li><li>Azure Storage account Encryption Customer Managed Keys Disabled</li><li>Azure storage account has a blob container with public access</li><li>Azure Storage account encryption key configured by access policy with privileged operations</li><li>Azure Virtual Machine (Linux) does not authenticate using SSH keys</li><li>Azure Cosmos DB key based authentication is enabled</li><li>Azure Function App authentication is off</li><li>Azure Cosmos DB (PaaS) instance with network path from the untrust internet source</li><li>Azure Storage Account default network access is set to 'Allow'</li><li>Azure App Service web apps with public network access</li><li>Azure SQL Server (PaaS) with network path from the untrust internet source</li><li>Azure Storage Account without Secure transfer enabled</li><li>Azure Storage Account storing Machine Learning workspace high business impact data is publicly accessible</li><li>Azure Virtual Machine with network path from the internet (0.0.0.0/0)</li><li>Azure AKS K8s service that is internet reachable with unrestricted access (0.0.0.0/0) [Beta]</li><li>Azure Storage account configured with Shared Key authorization</li><li>Azure Machine learning workspace configured with high business impact data have unrestricted network access</li><li>Azure subscription permission for Microsoft Entra tenant is set to 'Allow everyone'</li><li>Azure subscriptions with custom roles are overly permissive</li><li>Azure Machine learning workspace configured with overly permissive network access</li><li>Azure Batch Account configured with overly permissive network access</li><li>Azure Storage Sync Service configured with overly permissive network access</li><li>Azure Cognitive Services account configured with public network access</li><li>Azure MySQL (PaaS) instance reachable from untrust internet source on TCP port 3306</li><li>Azure PostgreSQL (PaaS) instance reachable from untrust internet source on TCP port 5432</li><li>Azure Virtual Machine reachable from any untrust internet source to ports with high risk</li><li>Azure Cognitive Services account hosted with OpenAI is not configured with data loss prevention</li><li>Azure DNS Zone having dangling DNS Record vulnerable to subdomain takeover associated with Azure Storage account blob</li><li>Azure DNS Zone having dangling DNS Record vulnerable to subdomain takeover associated with Web App Service</li><li>Azure AKS K8s service with network path from the internet (0.0.0.0/0) on ports 80/443</li><li>Azure AKS K8s service with network path from the untrust internet source on ports with high risk</li><li>Azure VM disk configured with public network access</li><li>GCP Service account is publicly accessible</li><li>GCP VM instance with network path from the internet (0.0.0.0/0) on ports 80/443</li><li>GCP VM instance with network path from the untrust internet source on ports with high risk</li><li>GCP VM instance with network path from the internet (0.0.0.0/0) on Admin ports</li><li>GCP VM instance with network path from the internet (0.0.0.0/0)</li><li>GCP Storage buckets are publicly accessible to all users</li><li>GCP Storage buckets are publicly accessible to all authenticated users</li><li>GCP BigQuery dataset is publicly accessible</li><li>GCP Cloud Function is publicly accessible</li><li>GCP Cloud Function configured with overly permissive Ingress setting</li><li>GCP Cloud Function has risky basic role assigned</li><li>GCP Cloud Run service is publicly accessible</li><li>GCP GKE K8s service with network path from the internet (0.0.0.0/0)</li><li>GCP Storage Bucket does not have Access and Storage Logging enabled</li><li>GCP Storage Bucket storing GCP Vertex AI pipeline output data</li><li>GCP Storage Bucket storing GCP Vertex AI training pipeline output model</li><li>GCP Storage Bucket storing Vertex AI model</li><li>GCP VM instance configured with default service account</li><li>GCP VM instance has risky basic role assigned</li><li>GCP VM instance using a default service account with Cloud Platform access scope</li><li>GCP Google Workspace Super Admin not enrolled with 2-step verification</li><li>GCP GKE K8s service with network path from the internet (0.0.0.0/0) on ports 80/443</li><li>GCP GKE K8s service with network path from the untrust internet source on ports with high risk</li></ul></td></tr></tbody></table>

## IAM Policy Updates

| **Policy Name**                                                                             | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **IAM Policy Updates—Metadata**                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **AWS IAM policy allows access and decrypt Secrets Manager Secrets permissions**            | <p><strong>Changes—</strong> The IAM policy name is updated as follows.</p><p><strong>Current Policy Name–</strong> AWS IAM policy allows access and decrypt Secrets Manager Secrets permissions</p><p><strong>Updated Policy Name–</strong> AWS EC2 with access to read and decrypt Secret Manager Secrets</p>                                                                                                                                                                                    |
| **IAM Policy Updates—Deletion**                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **AWS EC2 with IAM role with destruction permissions for AWS Key Management Service (KMS)** | <p><strong>Changes—</strong> This IAM policy has been deleted. Instead, use <strong>AWS EC2 with access to read and decrypt Secret Manager Secrets</strong> to receive alerts for policy violations.</p><p><strong>Impact—</strong></p><ul><li>Previously generated alerts will be resolved as <code>Policy\_Deleted</code>.</li><li>New alerts will be generated for policy violations based on <strong>AWS EC2 with access to read and decrypt Secret Manager Secrets</strong> policy.</li></ul> |

**IAM Policy Updates—Severity**

Prisma Cloud updated the policy severity levels based on updated risk assessment.

**Note—** These changes are reflective of previously intended changes (version 24.11.1) which did not take place due to internal circumstances.

**Impact—**

* Your existing open alerts associated with updated policies will have a change in their severity levels.
* If you have Alert rules set up based on the **Policy Severity** filter, there may be a decrease or increase in the number of alerts.
* The overall Compliance posture may change due to possible alert number changes.
* If you change a custom severity of a policy back to the default severity, the new severity update will apply.

This update will not affect the severities of your custom policies or the system default policies for which you have manually changed the severities (custom severity). Also, if you have included a policy in at least one other alert rule \`(not based on severity filter)], there will be no change in the alert numbers.

| **Policy Name**                                                                                                                           | **Current Severity** | **Updated Severity** |
| ----------------------------------------------------------------------------------------------------------------------------------------- | -------------------- | -------------------- |
| AWS IAM effective permissions are over-privileged (7 days)                                                                                | Low                  | Informational        |
| AWS IAM User with AWS Organization management permissions                                                                                 | Low                  | Informational        |
| AWS IAM User with IAM policy management permissions                                                                                       | High                 | Informational        |
| AWS IAM User with IAM write permissions                                                                                                   | Low                  | Informational        |
| AWS Okta User with AWS Organization management permissions                                                                                | Low                  | Informational        |
| AWS Okta User with IAM write permissions                                                                                                  | Low                  | Informational        |
| Azure AD user with the Azure built-in roles of Contributor                                                                                | High                 | Informational        |
| Azure AD user with the Azure built-in roles of Owner                                                                                      | High                 | Informational        |
| Azure AD user with the Azure built-in roles of Reader                                                                                     | Low                  | Informational        |
| Azure AD users with broad Key Vault access through Built-in Azure roles                                                                   | High                 | Informational        |
| Azure AD users with broad Key Vault management access                                                                                     | Critical             | Informational        |
| Azure entities with risky permissions                                                                                                     | Low                  | Informational        |
| Azure IAM effective permissions are over-privileged (7 days)                                                                              | Low                  | Informational        |
| Azure Managed Identity (user assigned or system assigned) with broad Key Vault access through Built-in Azure roles                        | High                 | Informational        |
| Azure Managed Identity (user assigned or system assigned) with broad Key Vault management access                                          | High                 | Informational        |
| Azure Managed Identity (user assigned or system assigned) with the Azure built-in roles of Contributor                                    | High                 | Informational        |
| Azure Managed Identity (user assigned or system assigned) with the Azure built-in roles of Owner                                          | High                 | Informational        |
| Azure Managed Identity (user assigned or system assigned) with the Azure built-in roles of Reader                                         | Low                  | Informational        |
| Azure Service Principals with broad Key Vault access through Built-in Azure roles                                                         | High                 | Informational        |
| Azure Service Principals with broad Key Vault management access                                                                           | Low                  | Informational        |
| GCP service accounts with permissions to deploy new resources                                                                             | High                 | Informational        |
| GCP User with IAM write access level permissions                                                                                          | Low                  | Informational        |
| GCP users with permissions to deploy new resources                                                                                        | High                 | Informational        |
| GCP users with Service Account Token Creator role                                                                                         | High                 | Informational        |
| Okta user with effective permissions to create AWS IAM users                                                                              | Low                  | Informational        |
| AWS IAM policy allows access and decrypt Secrets Manager Secrets permissions                                                              | Low                  | Informational        |
| AWS EC2 instance with data destruction permissions                                                                                        | High                 | Low                  |
| AWS Lateral Movement to Data Services Through Redshift Cluster Creation                                                                   | High                 | Low                  |
| AWS Okta User with IAM policy management permissions                                                                                      | High                 | Low                  |
| Azure AD user with effective permissions to create AWS IAM users                                                                          | High                 | Low                  |
| GCP App Engine Web Service Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation                          | High                 | Low                  |
| GCP App Engine Web Service Assigned Cloud Function IAM Policy Edit Permissions Which Could Lead to Privilege Escalation                   | High                 | Low                  |
| GCP App Engine Web Service Assigned Cloud Run Creation Which Could Lead to Privilege Escalation                                           | High                 | Low                  |
| GCP App Engine Web Service Assigned Cloud Run IAM Policy Edit Permissions Which Could Lead to Privilege Escalation                        | High                 | Low                  |
| GCP App Engine Web Service Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation                   | High                 | Low                  |
| GCP App Engine Web Service Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation                                 | High                 | Low                  |
| GCP Cloud Run Instance Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation                              | High                 | Low                  |
| GCP Cloud Run Instance Assigned Cloud Function IAM Policy Edit Permissions Which Could Lead to Privilege Escalation                       | High                 | Low                  |
| GCP Cloud Run Instance Assigned Cloud Run Creation Which Could Lead to Privilege Escalation                                               | High                 | Low                  |
| GCP Cloud Run Instance Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation                       | High                 | Low                  |
| GCP Cloud Run Instance Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation                                     | High                 | Low                  |
| GCP Cloud Run Job Public Execution via Default Compute SA Modification                                                                    | High                 | Low                  |
| GCP Compute Instance (VM/Cloud Function) Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation            | High                 | Low                  |
| GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run IAM Policy Edit Permissions Which Could Lead to Privilege Escalation          | High                 | Low                  |
| GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run Creation Permissions Which Could Lead to Privilege Escalation                 | High                 | Low                  |
| GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation     | High                 | Low                  |
| GCP Compute Instance (VM/Cloud Function) Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation                   | High                 | Low                  |
| GCP entities with permissions to impersonate a service account in another project                                                         | High                 | Low                  |
| GCP Lateral Access Expansion by Making Cloud Run Publicly Executable                                                                      | High                 | Low                  |
| Publicly Readable Lambda                                                                                                                  | Medium               | Low                  |
| Third-party service account with a Lateral Movement to Data Services Through Redshift Cluster Creation                                    | High                 | Low                  |
| Third-party Service Account With Lateral Movement Through CloudFormation Stack Creation                                                   | High                 | Low                  |
| AWS Compute Instance (EC2/Lambda) Assigned CloudFormation Creation Permissions Which Could Lead to Privilege Escalation                   | High                 | Medium               |
| AWS Compute Instance (EC2/Lambda) Assigned Glue DevEndpoint Creation Permissions Which Could Lead to Privilege Escalation                 | High                 | Medium               |
| AWS Compute Instance (EC2/Lambda) Assigned Lambda Creation Permissions Which Could Lead to Privilege Escalation                           | High                 | Medium               |
| AWS Compute Instance (EC2/Lambda) Assigned Permissions to Run EC2 Instances Which Could Lead to Privilege Escalation                      | High                 | Medium               |
| AWS EC2 machine with write access permission to resource-based policies                                                                   | Low                  | Medium               |
| AWS EC2 with IAM role attached has credentials exposure permissions                                                                       | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via Codestar create project and associate team member permissions                              | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via EC2 describe and SSM list and send command permissions                                     | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via EC2 describe and SSM session permissions                                                   | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via EC2 Instance Connect permissions                                                           | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via Glue Dev Endpoint permissions                                                              | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via PassRole & Lambda create & invoke Function permissions                                     | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via PassRole & Lambda create Function & add permissions                                        | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via PassRole & SageMaker create notebook permissions                                           | Low                  | Medium               |
| AWS IAM policy allows Privilege escalation via PassRole & SageMaker create training job permissions                                       | Low                  | Medium               |
| AWS Lambda Function with data destruction permissions                                                                                     | High                 | Medium               |
| AWS Lambda with IAM role attached has credentials exposure permissions                                                                    | Low                  | Medium               |
| Azure AD user with permissions to manage Azure permissions broadly that was not used in the last 90 days                                  | High                 | Medium               |
| Azure IAM effective permissions are over-privileged (90 days)                                                                             | Low                  | Medium               |
| Azure VM instance associated managed identities with Key Vault management access (data access is not included)                            | High                 | Medium               |
| GCP App Engine Web Service Assigned IAM Role Update Permissions Which Could Lead to Privilege Escalation                                  | High                 | Medium               |
| GCP App Engine Web Service Assigned Permissions to Edit IAM Policy for Service Accounts Which Could Lead to Privilege Escalation          | High                 | Medium               |
| GCP Cloud Run Instance Assigned Permissions to Retrieve Service Account Tokens Which Could Lead to Privilege Escalation                   | High                 | Medium               |
| GCP Compute Engine entities with predefined Admin roles                                                                                   | High                 | Medium               |
| GCP Compute Instance (VM/Cloud Function) Assigned Permissions to Retrieve Service Account Tokens Which Could Lead to Privilege Escalation | High                 | Medium               |
| GCP IAM effective permissions are over-privileged (90 days)                                                                               | Low                  | Medium               |
| GCP service accounts with 'Editor' role on folder level                                                                                   | High                 | Medium               |
| GCP service accounts with 'Editor' role on org level                                                                                      | High                 | Medium               |
| GCP service accounts with 'Owner' role on folder level                                                                                    | High                 | Medium               |
| GCP service accounts with 'Owner' role on org level                                                                                       | High                 | Medium               |
| GCP VM instance with data destruction permissions                                                                                         | High                 | Medium               |
| GCP VM instance with database management write access permissions                                                                         | Low                  | Medium               |
| GCP VM instance with permissions to impersonate a service account                                                                         | High                 | Medium               |
| AWS EC2 instance with the creation of a new Group with attached policy permission                                                         | Critical             | High                 |
| AWS EC2 instance with the creation of a new Role with attached policy permission                                                          | Critical             | High                 |
| AWS EC2 instance with the creation of a new User with attached policy permission                                                          | Critical             | High                 |
| AWS S3 Bucket with Data Destruction Permissions is Publicly Accessible Through Resource-Based Policies                                    | Low                  | High                 |
| Azure Lateral Movement Through SSH Key Replacement and Managed Identity Exploitation on VM                                                | Medium               | High                 |
| Azure Lateral Movement via VM Command Execution Leveraging Managed Identity                                                               | Medium               | High                 |
| AWS EC2 instance with the creation of a new Group with attached policy permission                                                         | Medium               | High                 |
| Cloud Service account with high privileges is inactive for 90 days and is assigned to a resource                                          | Medium               | High                 |
| Service Account with Cross Cloud Administrative Access                                                                                    | Medium               | High                 |
| Third-Party Service Account with High Privileges at the Folder or Organization Level                                                      | Medium               | High                 |
| User with Administrative Permissions Has Active Access Keys Which Are Unused Over 90 Days                                                 | Medium               | High                 |
| AWS Role With Administrative Permissions Can Be Assumed By All Users                                                                      | High                 | Critical             |
| AWS Secret Manager Secret is Publicly Accessible Through Resource-Based Policies                                                          | High                 | Critical             |

## REST API Updates

| **REST API**       | **Description**                                                                                                                                                                                                                                                                              |
| ------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Satellite APIs** | <p>The request body for <strong>Add Satellite Details</strong> - <a href="https://pan.dev/prisma-cloud/api/cspm/add-cluster-info/">POST /appid/api/v1/satellite</a> has been updated.</p><p>Request now only requires <code>clusterAssetId</code> string and <code>config</code> object.</p> |

## Deprecation Notices

| **Deprecated Endpoints**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | **Replacement Endpoints**                                                                                                                                                                                                                                                                                                                                |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>The following <strong>Get Vulnerability Overview</strong> endpoints have been deprecated:</p><ul><li>Get Vulnerability Overview V1 - <a href="https://pan.dev/prisma-cloud/api/cspm/vulnerability-dashboard-overview/">GET /uve/api/v1/dashboard/vulnerabilities/overview</a></li><li>Get Vulnerability Overview V2 - <a href="https://pan.dev/prisma-cloud/api/cspm/vulnerability-dashboard-overview-v-2/">GET /uve/api/v2/dashboard/vulnerabilities/overview</a></li><li>Get Vulnerability Overview V3 - <a href="https://pan.dev/prisma-cloud/api/cspm/vulnerability-dashboard-overview-v-3/">GET /uve/api/v3/dashboard/vulnerabilities/overview</a></li></ul>                                                                                                                                                                                                       | <p>The following endpoint is available as a replacement to the deprecated <strong>Get Vulnerability Overview</strong> endpoints.</p><ul><li>Get Vulnerability Overview - POST - <a href="https://pan.dev/prisma-cloud/api/cspm/vulnerability-dashboard-overview-v-4/">POST /uve/api/v4/dashboard/vulnerabilities/overview</a></li></ul>                  |
| <p>The following <strong>Get Prioritized Vulnerabilities</strong> endpoints have been deprecated:</p><ul><li>Get Prioritized Vulnerabilities V1 - <a href="https://pan.dev/prisma-cloud/api/cspm/prioritised-vulnerability/">GET - /uve/api/v1/dashboard/vulnerabilities/prioritised</a></li><li>Get Prioritized Vulnerabilities V2 - <a href="https://pan.dev/prisma-cloud/api/cspm/prioritised-vulnerability-v-2/">GET - /uve/api/v2/dashboard/vulnerabilities/prioritised</a></li><li>Get Prioritized Vulnerabilities V3 - <a href="https://pan.dev/prisma-cloud/api/cspm/prioritised-vulnerability-v-3/">GET - /uve/api/v3/dashboard/vulnerabilities/prioritised</a></li><li>Get Prioritized Vulnerabilities V4 - <a href="https://pan.dev/prisma-cloud/api/cspm/prioritised-vulnerability-v-4/">GET - /uve/api/v4/dashboard/vulnerabilities/prioritised</a></li></ul> | <p>The following endpoint is available as a replacement to the deprecated <strong>Get Prioritized Vulnerabilities</strong> endpoints.</p><ul><li>Get Prioritized Vulnerabilities POST - <a href="https://pan.dev/prisma-cloud/api/cspm/prioritised-vulnerability-v-5/">POST /uve/api/v5/dashboard/vulnerabilities/prioritised</a></li></ul>              |
| <p>The following <strong>Get Top Impacting Vulnerabilities</strong> endpoints have been deprecated:</p><ul><li>Get Top Impacting Vulnerabilities - <a href="https://pan.dev/prisma-cloud/api/cspm/top-prioritised-vulnerability/">GET /uve/api/v1/dashboard/vulnerabilities/prioritised-vuln</a></li><li>Get Top Impacting Vulnerabilities V2 - <a href="https://pan.dev/prisma-cloud/api/cspm/top-prioritised-vulnerability-v-2/">GET /uve/api/v2/dashboard/vulnerabilities/prioritised-vuln</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                | <p>The following endpoint is available as a replacement to the deprecated <strong>Get Top Impacting Vulnerabilities</strong> endpoints.</p><ul><li>Get Top Impacting Vulnerabilities POST - <a href="https://pan.dev/prisma-cloud/api/cspm/top-prioritised-vulnerability-v-3/">POST /uve/api/v3/dashboard/vulnerabilities/prioritised-vuln</a></li></ul> |
| <p>The following <strong>Get CVE Overview “Sidecar APIs”</strong> endpoints have been deprecated:</p><ul><li>Get CVE Overview - <a href="https://pan.dev/prisma-cloud/api/cspm/cve-overview/">GET /uve/api/v1/dashboard/vulnerabilities/cve-overview</a></li><li>Get CVE Overview V2 - <a href="https://pan.dev/prisma-cloud/api/cspm/cve-overview-v-2/">GET /uve/api/v1/cve-overview</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | <p>The following endpoint is available as a replacement to the deprecated <strong>Get CVE Overview “Sidecar APIs”</strong> endpoints.</p><ul><li>Get CVE Overview POST - <a href="https://pan.dev/prisma-cloud/api/cspm/cve-overview-v-3/">POST /uve/api/v2/cve-overview</a></li></ul>                                                                   |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2025/features-introduced-in-february-2025.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
