Features Introduced in July 2025
Learn what’s new on Prisma® Cloud in July 2025.
The July (25.7.1) release does not include any new policies.
Enhancements
Feature
Description
Support for Entra ID Authentication
In addition to the currently supported authentications methods, Prisma Cloud now supports Microsoft Entra ID for flow log ingestion. Learn more about authentication using Entra ID.
API Ingestions
Service
API Details
Update Amazon API Gateway
aws-apigatewayv2-stage
The API is updated to ingest an additional apidId attribute.
No additional permissions are required.
Azure Container Apps
azure-app-container-apps-managed-environment
Additional permission required:
Microsoft.app/managedenvironments/read
The Reader role includes the permission.
Azure Fluid Relay
azure-fluid-relay-server
Additional permission required:
Microsoft.FluidRelay/fluidRelayServers/read
The Reader role includes the permission.
Azure Network Watcher
azure-network-watcher-flowlogs
Additional permission required:
Microsoft.Network/networkWatchers/flowLogs/read
The Reader role includes the permission.
Azure Web PubSub Service
azure-signalrservice-web-pub-sub-diagnostic-settings
Additional permissions required:
Microsoft.SignalRService/WebPubSub/readMicrosoft.Insights/DiagnosticSettings/Read
The Reader role includes the permissions.
Update Azure Container Apps
azure-app-container-apps
Additional permissions required:
microsoft.app/containerapps/read(existing permission)microsoft.app/containerapps/authconfigs/read(new permission)
The Reader role includes the permissions.
authConfigs details of container apps are appended to the existing API.
OCI IAM
oci-iam-tag-default
Additional permission required:
TAG_DEFAULT_INSPECT
The Reader role includes the permission.
Policy Updates
Policy Updates
Description
Policy Updates—RQL
AWS EKS cluster does not have secrets encryption enabled
Changes– The policy is updated to identify EKS clusters with versions lesser than 1.28 as per the latest CSP updates.
Current Description–
This policy identifies AWS EKS clusters that do not have secrets encryption enabled.
AWS EKS cluster secrets are, by default, stored unencrypted in the API server’s underlying data store (etcd). Anyone with direct access to etcd or with API access can retrieve or modify the secrets. Using secrets encryption for your Amazon EKS cluster allows you to protect sensitive information such as passwords and API keys using Kubernetes-native APIs.
It is recommended to enable secrets encryption to ensure its security and reduce the risk of unauthorized access or data breaches.
Updated Description–
This policy identifies AWS EKS clusters that do not have secrets encryption enabled.
AWS EKS cluster secrets are, by default, stored unencrypted in the API server’s underlying data store (etcd). Anyone with direct access to etcd or with API access can retrieve or modify the secrets. Using secrets encryption for your Amazon EKS cluster allows you to protect sensitive information such as passwords and API keys using Kubernetes-native APIs.
It is recommended to enable secrets encryption to ensure its security and reduce the risk of unauthorized access or data breaches.
The policy identifies secret encryptions for EKS clusters with versions lesser than 1.28.
Current RQL–
Updated RQL–
Policy Type– Config
Policy Severity– Medium
Impact– Low. Open alerts for EKS clusters with versions higher than 1.27 will be resolved.
AWS Auto Scaling group launch configuration not configured with Instance Metadata Service v2 (IMDSv2)
Changes– The policy is updated to exclude instance configurations created by the Elastic Beanstalk service where the IMDSv1 is deactivated.
Current RQL–
Updated RQL–
Policy Type– Config
Policy Severity– Medium
Impact– Low. Open alerts where the launch configurations are created by Elastic Beanstalk automatically, where the IMDSv1 is deactivated will be resolved.
AWS S3 bucket encrypted using Customer Managed Key (CMK) with overly permissive policy
Changes– The policy RQL and remediation steps are updated to check for Actions and Effect in the KMS policy to reduce false positives.
Current RQL–
Updated RQL–
Policy Type– Config
Policy Severity– Medium
Impact– Low. Open alerts where Effect is not 'Allow' and Action is specific will be resolved.
AWS Kinesis streams encryption using default KMS keys instead of Customer’s Managed Master Keys
Changes– The policy RQL is updated to include the resource using AWS managed key via alias.
Updated RQL–
Policy Type– Config
Policy Severity– Informational
Impact– Low. New alerts will be created for the resource which is using AWS managed key via alias.
AWS RDS instance without Automatic Backup setting
Changes– The policy RQL is updated to exclude SQL Server (Enterprise edition) read replica as automatic backup cannot be enabled for such instances.
Current RQL–
Updated RQL–
Policy Type– Config
Policy Severity– Low
Impact– Low. Open alerts for SQL Server (Enterprise edition) read replica will be resolved.
Azure SQL server using insecure TLS version
Changes– The policy RQL is updated to eliminate the check for "NONE" since it now defaults to using version 1.2 or 1.3 in accordance with the latest CSP updates.
Current RQL–
Updated RQL–
Policy Type– Config
Policy Severity– Low
Impact– Low. Open alerts where minimalTlsVersion is set to 'NONE' will be resolved.
Policy Updates—Metadata
Azure SQL server public network access setting is enabled
Changes– The policy description and remediation steps are updated to reflect the latest changes in Azure to ensure accurate remediation of flagged resources.
Current Description–
This policy identifies Azure SQL servers which have public network access setting enabled. Publicly accessible SQL servers are vulnerable to external threats with risk of unauthorized access or may remotely exploit any vulnerabilities. It is recommended to configure the SQL servers with IP-based strict server-level firewall rules or virtual-network rules or private endpoints so that servers are accessible only to restricted entities.
Updated Description–
This policy identifies Azure SQL servers which have public network access setting enabled. Publicly accessible SQL servers are vulnerable to external threats with risk of unauthorized access or may remotely exploit any vulnerabilities. It is recommended to disable public network access to the Azure SQL servers and use private endpoints or virtual network service endpoints to secure connectivity.
Azure Front Door Web application firewall (WAF) policy rule for Remote Command Execution is disabled
Changes– The policy name and description are updated as per the CSP updates.
Current Name–
Azure Front Door Web application firewall (WAF) policy rule for Remote Command Execution is disabled
Updated Name–
Azure Front Door (Classic) Web application firewall (WAF) policy rule for Remote Command Execution is disabled
Current Description–
This policy identifies Azure Front Door Web application firewall (WAF) policies that have the Remote Command Execution rule disabled. It is recommended to define the criteria in the WAF policy with the rule ‘Remote Command Execution (944240)’ under managed rules to help in detecting and mitigating Log4j vulnerability. For details see: https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/
Updated Description–
This policy identifies Azure Front Door (Classic) Web application firewall (WAF) policies that have the Remote Command Execution rule disabled. It is recommended to define the criteria in the WAF policy with the rule ‘Remote Command Execution (944240)’ under managed rules to help in detecting and mitigating Log4j vulnerability. For details see: https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/
Impact– None. This change does not affect the functionality of the policy.
Impact on Alerts– None.
Policy Deletion
Azure Microsoft Defender for Cloud automatic provisioning of log Analytics agent for Azure VMs is set to Off
Changes– The policy is deleted since Azure has deprecated the Log Analytics agent.
Impact– All alerts will be resolved as Policy Deleted.
New Compliance Benchmarks and Updates
Compliance Benchmark
Description
Australian Energy Sector Cyber Security Framework (AESCSF) V2 - Lite Framework
The AESCSF Version 2 Lite Framework is a simplified cyber security compliance tool tailored for lower-criticality organizations in the Australian energy sector. It enables these entities to self-assess their cyber security maturity across 11 key categories—such as risk management, asset management, identity and access, incident response, and privacy—using 28 plain-language questions. By providing an accessible, structured approach to identifying strengths and gaps, the Lite Framework helps organizations benchmark their security posture, prioritize improvements, and align with foundational industry and national standards, even with limited resources or expertise.
You can access this built-in compliance standard and related policies on the Compliance > Standards page. Additionally, you can generate reports to instantly view or download them, or set up scheduled reports to continuously monitor compliance.
CIS Microsoft Azure Foundations Benchmark v4.0.0 - Level 1 and Level 2
Prisma Cloud now supports the latest version of CIS Microsoft Azure Foundations Benchmark v4.0.0. This compliance standard supports two levels - Level 1 and Level 2. The CIS Azure Foundations Benchmark provides prescriptive guidance for establishing a secure baseline configuration for the Azure environment.
You can access this built-in compliance standard and related policies on the Compliance > Standards page. Additionally, you can generate reports to instantly view or download them, or set up scheduled reports to continuously monitor compliance.
CIS Amazon Web Services Foundations Benchmark v5.0.0 - Level 1 and Level 2
Prisma Cloud now supports the latest version of CIS Amazon Web Services (AWS) Foundations Benchmark v5.0.0. This compliance standard supports two levels - Level 1 and Level 2. The CIS AWS Foundations Benchmark provides prescriptive guidance for establishing a secure baseline configuration for the AWS Cloud Infrastructure environment.
You can access this built-in compliance standard and related policies on the Compliance > Standards page. Additionally, you can generate reports to instantly view or download them, or set up scheduled reports to continuously monitor compliance.
CIS Google Cloud Platform Benchmark v4.0.0 - Level 1 and Level 2
Prisma Cloud now supports the latest version of CIS Google Cloud Platform (GCP) Benchmark v4.0.0. This compliance standard supports two levels - Level 1 and Level 2. The CIS GCP Benchmark v4.0.0 provides a comprehensive set of security best practices and configuration guidelines designed to help organizations secure their Google Cloud environments. Developed through a community consensus process, this benchmark outlines controls for key areas such as identity and access management, logging and monitoring, networking, virtual machines, storage, and database services. By following these recommendations, organizations can strengthen their cloud security posture, meet regulatory requirements, and protect against evolving cyber threats.
You can access this built-in compliance standard and related policies on the Compliance > Standards page. Additionally, you can generate reports to instantly view or download them, or set up scheduled reports to continuously monitor compliance.
Last updated
Was this helpful?

