For the complete documentation index, see llms.txt. This page is also available as Markdown.

Features Introduced in May 2025

Learn what’s new on Prisma® Cloud in May 2025.

Announcements

Feature

Description

RedHat Enterprise Linux 10 incompatibility with WAAS Defender Agent

Secure the Runtime

34.01.126

RedHat deprecated iptables in RHEL 9 and the upcoming RHEL 10 will not support iptables.

The WAAS defender agent deployed directly on RHEL10 (as Host Defender), which relies on iptables, is incompatible with RHEL 10 due to this change.

Containerized varieties of the WAAS Defender will continue to work.

Enhancements

Feature

Description

Enhanced fsmon monitoring process

Secure the Runtime

34.01.126

To enhance the handling of file system events in the runtime, a new version, fsmon_v2, has been developed. This version improves stability by managing timeouts more promptly and robustly, which reduces bottlenecks and enhances overall stability.

Starting from this release (version 34.01), fsmon_v2 is the default file system monitoring process and runs by default when the defender launches.

Support for Oracle Linux as Base Image

Secure the Runtime

34.01.126

Prisma Cloud now provides runtime protection for containers that use Oracle Linux as the base layer.

Support for mounted paths

Secure the Runtime

34.01.126

A new environment variable (HOST_FIM_MOUNTS) enables you to specify additional host mounted paths for runtime monitoring. By incorporating these specified paths into all applicable policies, this feature provides enhanced flexibility in monitoring critical mounted paths within your environment.

The value of this new variable is a colon separated list of the additional mountpoints to track, for example: /mnt/mountpoint1:/mnt/mountpoint2.

To update the environment variable:

  1. Add or modify the new environment variable in the deployment file to include the desired mounted paths for monitoring.

  2. Deploy the Defender with the new environment variables to activate monitoring of the new paths.

New environment variable for configuring the number of image external labels

Secure the Runtime

34.01.126

A new environment variable — IMAGE_EXTERNAL_LABELS_CAP, enables configuration of the maximum number of external labels (indirect labels collected by Prisma Cloud) that are allowed for an image. The default value is 100, and the maximum configurable value is 1024. This variable is applicable to both Console and Defenders.

Important Considerations:

  • External labels, such as Kubernetes Namespace and Deployment labels, as well as cloud tags, are collected and stored per container.

  • This limit is specific to external labels collect per image and doesn’t impact existing container limitations.

  • External labels are not inherent image properties and are not be displayed if a container is not scanned (for example, short-lived containers).

Vulnerabilities and Compliance data available as PDF files

Secure the Runtime

34.01.126

You can now download the data shown on the following pages as PDF files:

  • Monitor > Vulnerabilities > Images & Hosts

  • Monitor > Compliance > Containers, Images & Hosts

Runtime protection for SUSE Linux Enterprise Server 15 SP6

Secure the Runtime

34.01.126

Prisma Cloud now supports runtime protection of SUSE Linux Enterprise Server 15 SP6 images.

Ingestion of Azure VNet Flow Logs

Prisma Cloud now supports the ingestion of VNet flow logs in addition to the existing ingestion of NSG flow logs, for Microsoft Azure account onboarding. VNet flow logs will also be added as a data source to existing Azure policies. There will be no impact to existing tenants and no additional action is needed.

Ingestion of AWS ca-west-1 Resources

Prisma Cloud AWS resource discovery is now extended to resources on AWS ca-west-1 (Canada/Calgary). With this added ingestion support, assets in this region are discoverable on the Asset Inventory page. No additional action is needed.

Changes in Existing Behavior

Feature

Description

System Requirements: Changes to supported systems and platforms

Secure the Runtime

34.01.126

The following changes have been made to the system requirements:

Support added for the following x86 Operating Systems

  • SLES 15 SP6

  • Talos OS 1.10.1

  • Talos OS 1.9.5

Support removed for the following x86 Operating Systems

  • CentOS 7

  • RedHat Enterprise Linux 7

  • VMWare Photon OS 3.0

Support added for the following ARM-based Orchestrators

  • Google Kubernetes Engine (GKE) autopilot on ARM v1.31.6-gke.1064001

  • Oracle Kubernetes Engine (OKE) V.1.32.1

Support removed for the following ARM-based Orchestrators

  • Elastic Container Service (ECS) 1.86.2

  • Elastic Container Service (ECS) 1.86.3

Support added for the following Auto-Defend platforms

  • AWS Node.js 22

  • AWS Python 3.13

API Ingestions

Service

API Details

AWS HealthLake

aws-healthlake-datastore

Additional permissions required:

  • healthlake:ListFHIRDatastores

  • healthlake:DescribeFHIRDatastore

The Security audit role includes healthlake:ListFHIRDatastores permission but does not include healthlake:DescribeFHIRDatastore permission.

Azure API Management Services

azure-api-management-service-named-value

Additional permissions required:

  • Microsoft.ApiManagement/service/read

  • Microsoft.ApiManagement/service/namedValues/read

The Reader role includes the permissions.

Azure Healthcare Apis

azure-healthcare-apis-workspace-fhir-service

Additional permissions required:

  • `Microsoft.HealthcareApis/workspaces/read

  • Microsoft.HealthcareApis/workspaces/fhirservices/read

The Reader role includes the permission.

Azure Healthcare Apis

azure-healthcare-apis-workspace-dicom-service

Additional permissions required:

  • Microsoft.HealthcareApis/workspaces/read

  • Microsoft.HealthcareApis/workspaces/dicomservices/read

The Reader role includes the permissions.

Azure IoT Central

azure-iot-central-private-endpoint-connections

Additional permissions required:

  • Microsoft.IoTCentral/IoTApps/read

  • Microsoft.IoTCentral/IoTApps/privateEndpointConnections/read

The Reader role includes the permissions.

Azure IoT Hub

azure-iot-hub-device-provisioning-service

Additional permission required:

  • Microsoft.Devices/provisioningServices/Read

The Reader role includes the permission.

Azure IoT Hub

azure-devices-iot-hub-private-endpoint-connections

Additional permissions required:

  • Microsoft.Devices/iotHubs/Read

  • Microsoft.Devices/iotHubs/PrivateEndpointConnections/Read

The Reader role includes the permissions.

Azure Kusto

azure-kusto-database-principal-assignment

Additional permissions required:

  • `Microsoft.Kusto/Clusters/read `

  • Microsoft.Kusto/Clusters/Databases/read

  • Microsoft.Kusto/Clusters/Databases/PrincipalAssignments/read

The Reader role includes the permissions.

Azure Kusto

azure-kusto-cluster-private-link-resource

Additional permissions required:

  • Microsoft.Kusto/Clusters/read

  • Microsoft.Kusto/Clusters/PrivateLinkResources/read

The Reader role includes the permissions.

Azure Kusto

azure-kusto-cluster-principal-assignment

Additional permissions required:

  • Microsoft.Kusto/Clusters/read

  • Microsoft.Kusto/Clusters/PrincipalAssignments/read

The Reader role includes the permissions.

Azure Kusto

azure-kusto-cluster-managed-private-endpoint

Additional permissions required:

  • Microsoft.Kusto/Clusters/read

  • Microsoft.Kusto/Clusters/ManagedPrivateEndpoints/read

The Reader role includes the permissions.

Azure Recovery Services

azure-recovery-service-private-link

Additional permissions required:

  • Microsoft.RecoveryServices/Vaults/read

  • Microsoft.RecoveryServices/Vaults/privateLinkResources/read

The Reader role includes the permissions.

Azure Storage

azure-storage-account-blob-service-property

Additional permissions required:

  • Microsoft.Storage/storageAccounts/read

  • Microsoft.Storage/storageAccounts/blobServices/read

The Reader role includes the permissions.

Update Azure Synapse Analytics

azure-synapse-workspace

Additional permission required:

  • `Microsoft.Synapse/workspaces/dedicatedSQLminimalTlsSettings/read `

The additional permission above is now required.

Update Azure Synapse Analytics

azure-synapse-workspace-sql-pools

Additional permission required:

  • Microsoft.Synapse/workspaces/sqlPools/transparentDataEncryption/read

The additional permission above is now required.

Google Resource Manager

gcloud-project-tag-key

Additional permissions required:

  • resourcemanager.tagKeys.list

  • resourcemanager.tagKeys.getIamPolicy

The Viewer role includes the permissions.

Google Resource Manager

gcloud-organization-tag-key

Additional permissions required:

  • resourcemanager.tagKeys.list

  • resourcemanager.tagKeys.getIamPolicy

The Viewer role includes the permissions.

Google Cloud TPU

gcloud-tpu-node

Additional permission required:

  • tpu.nodes.list

The Viewer role includes the permission.

OCI IAM

oci-iam-password-policy

Additional permissions required:

  • COMPARTMENT_INSPECT

  • DOMAIN_INSPECT

  • PASSWORD_POLICY_INSPECT

The Reader role includes the permissions.

Policy Updates

Policy Updates

Description

Policy Updates—RQL

Cognito service role with wide privileges does not validate authentication

Changes— Policy RQL has been updated with including the condition matching '*' in policy action

Current RQL–

Updated RQL–

Policy Type– Config

Policy Severity– High

Impact– Low. New alerts will be generated as per new RQL.

AWS Cognito service role with wide privileges does not validate authentication

Changes— Policy RQL has been updated with including the condition matching '*' in policy action

Current RQL–

Updated RQL–

Policy Type– Config

Policy Severity– High

Impact– Low. New alerts will be generated as per new RQL.

Policy Updates—Metadata

AWS S3 bucket not configured with secure data transport policy

Changes— Policy description updated to include the publicly accessible check.

Policy Type: Config

Policy Severity: Medium

Impact: No impact on alerts

Updated Description:

AWS S3 bucket not configured with secure data transport policy

Changes— Policy description updated to include the publicly accessible check.

Policy Type: Config

Policy Severity: Medium

Impact: Low

Updated Description:

New Compliance Benchmarks and Updates

Compliance Benchmark

Description

[Update] Australian Cyber Security Centre (ACSC) Essential Eight

New Policy mappings are added to Australian Cyber Security Centre (ACSC) Essential Eight compliance standard across all the levels..

Impact: As new mappings are introduced, compliance scoring might vary.

FedRAMP (High)

FedRAMP High compliance is the highest level of security within the Federal Risk and Authorization Management Program (FedRAMP), designed to protect highly sensitive and classified government data stored in cloud environments.

You can now access this built-in standard and related policies on the Compliance > Standards page. Additionally, you can generate reports to instantly view or download them, or set up scheduled reports to continuously monitor compliance.

[Update] CIS v3.0.0 (OCI) - Level 1 & CIS v3.0.0 (OCI) - Level 2

Prisma Cloud now supports the latest version of CIS Oracle Cloud Infrastructure Foundations Benchmark . This compliance standard supports two levels - Level 1 and Level 2. CIS Oracle Cloud Infrastructure Foundations Benchmark, provides prescriptive guidance for establishing a secure baseline configuration for the Oracle Cloud Infrastructure environment.

You can now access this built-in standard and related policies on the Compliance > Standards page. Additionally, you can generate reports to instantly view or download them, or set up scheduled reports to continuously monitor compliance.

REST API Updates

REST API

Description

Download Image Scan Results API

Secure the Runtime

34.01.126

​A new column, Cloud Security Agent Hosts, is added in the Download Image Scan Results API CSV file response. This new field lists the number of integrated XDR Agents in the Prisma Cloud and Cortex XDR integration.

Support for new agentless APIs

Secure the Runtime

34.01.126

The following new API endpoints enable you to set the maximum number of scanners for an agentless account and get the agentless scan statistics.

Support for a new enum value

Secure the Runtime

34.01.126

A new Enum value gcp-cloud-run-service has been added to the shared.ScanResultType schema.

Deprecation Notices

Feature

Description

Deprecation of the CNNS feature

Secure the Runtime

34.01.126

The ​Cloud Native Network Segmentation (CNNS) feature is deprecated for the enforcement of protection against network threats for both containers and hosts. However, in scenarios where alternative network monitoring modes are unavailable, it can be used only for monitoring, such as radar visibility. The current recommendation is to disable all CNNS-based network monitoring as well.

Last updated

Was this helpful?