> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2025/features-introduced-in-may-2025.md).

# Features Introduced in May 2025

Learn what’s new on Prisma® Cloud in May 2025.

* [Announcements](#announcements)
* [Enhancements](#enhancements)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [API Ingestions](#api-ingestions)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)
* [Deprecation Notices](#deprecation-notices)

## Announcements

| **Feature**                                                                                                                                                                                                                      | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>RedHat Enterprise Linux 10 incompatibility with WAAS Defender Agent</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p> | <p>RedHat <a href="https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.0_release_notes/deprecated_functionality#deprecated-functionality_networking">deprecated iptables in RHEL 9</a> and the upcoming RHEL 10 will not support iptables.</p><p>The WAAS defender agent deployed directly on RHEL10 (as Host Defender), which relies on iptables, is incompatible with RHEL 10 due to this change.</p><p>Containerized varieties of the WAAS Defender will continue to work.</p> |

## Enhancements

| **Feature**                                                                                                                                                                                                                               | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Enhanced fsmon monitoring process</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p>                                            | <p>To enhance the handling of file system events in the runtime, a new version, fsmon\_v2, has been developed. This version improves stability by managing timeouts more promptly and robustly, which reduces bottlenecks and enhances overall stability.</p><p>Starting from this release (version 34.01), fsmon\_v2 is the default file system monitoring process and runs by default when the defender launches.</p>                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>Support for Oracle Linux as Base Image</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p>                                       | Prisma Cloud now provides runtime protection for containers that use Oracle Linux as the base layer.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Support for mounted paths</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p>                                                    | <p>A new environment variable (<code>HOST\_FIM\_MOUNTS</code>) enables you to specify additional host mounted paths for runtime monitoring. By incorporating these specified paths into all applicable policies, this feature provides enhanced flexibility in monitoring critical mounted paths within your environment.</p><p>The value of this new variable is a colon separated list of the additional mountpoints to track, for example: <code>/mnt/mountpoint1:/mnt/mountpoint2</code>.</p><p>To update the environment variable:</p><ol><li>Add or modify the new environment variable in the deployment file to include the desired mounted paths for monitoring.</li><li>Deploy the Defender with the new environment variables to activate monitoring of the new paths.</li></ol>                                                    |
| <p><strong>New environment variable for configuring the number of image external labels</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p> | <p>A new environment variable — <code>IMAGE\_EXTERNAL\_LABELS\_CAP</code>, enables configuration of the maximum number of external labels (indirect labels collected by Prisma Cloud) that are allowed for an image. The default value is 100, and the maximum configurable value is 1024. This variable is applicable to both Console and Defenders.</p><p><strong>Important Considerations:</strong></p><ul><li>External labels, such as Kubernetes Namespace and Deployment labels, as well as cloud tags, are collected and stored per container.</li><li>This limit is specific to external labels collect per image and doesn’t impact existing container limitations.</li><li>External labels are not inherent image properties and are not be displayed if a container is not scanned (for example, short-lived containers).</li></ul> |
| <p><strong>Vulnerabilities and Compliance data available as PDF files</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p>                   | <p>You can now download the data shown on the following pages as PDF files:</p><ul><li>Monitor > Vulnerabilities > Images & Hosts</li><li>Monitor > Compliance > Containers, Images & Hosts</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Runtime protection for SUSE Linux Enterprise Server 15 SP6</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p>                   | Prisma Cloud now supports runtime protection of SUSE Linux Enterprise Server 15 SP6 images.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Ingestion of Azure VNet Flow Logs**                                                                                                                                                                                                     | Prisma Cloud now supports the ingestion of [VNet flow logs](https://docs.prismacloud.io/en/enterprise-edition/content-collections/connect/connect-cloud-accounts/onboard-your-azure-account/connect-azure-account#:~:text=Virtual%20Network%20flow%20logs) in addition to the existing ingestion of NSG flow logs, for Microsoft Azure account onboarding. VNet flow logs will also be added as a data source to existing Azure policies. There will be no impact to existing tenants and no additional action is needed.                                                                                                                                                                                                                                                                                                                      |
| **Ingestion of AWS ca-west-1 Resources**                                                                                                                                                                                                  | Prisma Cloud AWS resource discovery is now extended to resources on AWS ca-west-1 (Canada/Calgary). With this added ingestion support, assets in this region are discoverable on the **Asset Inventory** page. No additional action is needed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

## Changes in Existing Behavior

| **Feature**                                                                                                                                                                                                                  | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>System Requirements: Changes to supported systems and platforms</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p> | <p>The following changes have been made to the system requirements:</p><p><strong>Support added for the following x86 Operating Systems</strong></p><ul><li>SLES 15 SP6</li><li>Talos OS 1.10.1</li><li>Talos OS 1.9.5</li></ul><p><strong>Support removed for the following x86 Operating Systems</strong></p><ul><li>CentOS 7</li><li>RedHat Enterprise Linux 7</li><li>VMWare Photon OS 3.0</li></ul><p><strong>Support added for the following ARM-based Orchestrators</strong></p><ul><li>Google Kubernetes Engine (GKE) autopilot on ARM v1.31.6-gke.1064001</li><li>Oracle Kubernetes Engine (OKE) V.1.32.1</li></ul><p><strong>Support removed for the following ARM-based Orchestrators</strong></p><ul><li>Elastic Container Service (ECS) 1.86.2</li><li>Elastic Container Service (ECS) 1.86.3</li></ul><p><strong>Support added for the following Auto-Defend platforms</strong></p><ul><li>AWS Node.js 22</li><li>AWS Python 3.13</li></ul> |

## API Ingestions

| **Service**                                                                      | **API Details**                                                                                                                                                                                                                                                                                                                                                                       |
| -------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **AWS HealthLake**                                                               | <p><strong>aws-healthlake-datastore</strong></p><p>Additional permissions required:</p><ul><li><code>healthlake:ListFHIRDatastores</code></li><li><code>healthlake:DescribeFHIRDatastore</code></li></ul><p>The Security audit role includes <code>healthlake:ListFHIRDatastores</code> permission but does not include <code>healthlake:DescribeFHIRDatastore</code> permission.</p> |
| **Azure API Management Services**                                                | <p><strong>azure-api-management-service-named-value</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/namedValues/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                      |
| **Azure Healthcare Apis**                                                        | <p><strong>azure-healthcare-apis-workspace-fhir-service</strong></p><p>Additional permissions required:</p><ul><li>\`Microsoft.HealthcareApis/workspaces/read</li><li><code>Microsoft.HealthcareApis/workspaces/fhirservices/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                     |
| **Azure Healthcare Apis**                                                        | <p><strong>azure-healthcare-apis-workspace-dicom-service</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.HealthcareApis/workspaces/read</code></li><li><code>Microsoft.HealthcareApis/workspaces/dicomservices/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                       |
| **Azure IoT Central**                                                            | <p><strong>azure-iot-central-private-endpoint-connections</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.IoTCentral/IoTApps/read</code></li><li><code>Microsoft.IoTCentral/IoTApps/privateEndpointConnections/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                       |
| **Azure IoT Hub**                                                                | <p><strong>azure-iot-hub-device-provisioning-service</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Devices/provisioningServices/Read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                      |
| **Azure IoT Hub**                                                                | <p><strong>azure-devices-iot-hub-private-endpoint-connections</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Devices/iotHubs/Read</code></li><li><code>Microsoft.Devices/iotHubs/PrivateEndpointConnections/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                         |
| **Azure Kusto**                                                                  | <p><strong>azure-kusto-database-principal-assignment</strong></p><p>Additional permissions required:</p><ul><li>`Microsoft.Kusto/Clusters/read `</li><li><code>Microsoft.Kusto/Clusters/Databases/read</code></li><li><code>Microsoft.Kusto/Clusters/Databases/PrincipalAssignments/read</code></li></ul><p>The Reader role includes the permissions.</p>                             |
| **Azure Kusto**                                                                  | <p><strong>azure-kusto-cluster-private-link-resource</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Kusto/Clusters/read</code></li><li><code>Microsoft.Kusto/Clusters/PrivateLinkResources/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                          |
| **Azure Kusto**                                                                  | <p><strong>azure-kusto-cluster-principal-assignment</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Kusto/Clusters/read</code></li><li><code>Microsoft.Kusto/Clusters/PrincipalAssignments/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                           |
| **Azure Kusto**                                                                  | <p><strong>azure-kusto-cluster-managed-private-endpoint</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Kusto/Clusters/read</code></li><li><code>Microsoft.Kusto/Clusters/ManagedPrivateEndpoints/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                    |
| **Azure Recovery Services**                                                      | <p><strong>azure-recovery-service-private-link</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.RecoveryServices/Vaults/read</code></li><li><code>Microsoft.RecoveryServices/Vaults/privateLinkResources/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                              |
| **Azure Storage**                                                                | <p><strong>azure-storage-account-blob-service-property</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Storage/storageAccounts/read</code></li><li><code>Microsoft.Storage/storageAccounts/blobServices/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                              |
| <mark style="background-color:orange;">Update</mark> **Azure Synapse Analytics** | <p><strong>azure-synapse-workspace</strong></p><p>Additional permission required:</p><ul><li>`Microsoft.Synapse/workspaces/dedicatedSQLminimalTlsSettings/read `</li></ul><p>The additional permission above is now required.</p>                                                                                                                                                     |
| <mark style="background-color:orange;">Update</mark> **Azure Synapse Analytics** | <p><strong>azure-synapse-workspace-sql-pools</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Synapse/workspaces/sqlPools/transparentDataEncryption/read</code></li></ul><p>The additional permission above is now required.</p>                                                                                                                             |
| **Google Resource Manager**                                                      | <p><strong>gcloud-project-tag-key</strong></p><p>Additional permissions required:</p><ul><li><code>resourcemanager.tagKeys.list</code></li><li><code>resourcemanager.tagKeys.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                            |
| **Google Resource Manager**                                                      | <p><strong>gcloud-organization-tag-key</strong></p><p>Additional permissions required:</p><ul><li><code>resourcemanager.tagKeys.list</code></li><li><code>resourcemanager.tagKeys.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                       |
| **Google Cloud TPU**                                                             | <p><strong>gcloud-tpu-node</strong></p><p>Additional permission required:</p><ul><li><code>tpu.nodes.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                             |
| **OCI IAM**                                                                      | <p><strong>oci-iam-password-policy</strong></p><p>Additional permissions required:</p><ul><li><code>COMPARTMENT\_INSPECT</code></li><li><code>DOMAIN\_INSPECT</code></li><li><code>PASSWORD\_POLICY\_INSPECT</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                         |

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>Cognito service role with wide privileges does not validate authentication</strong></td><td><p><strong>Changes—</strong> Policy RQL has been updated with including the condition matching '*' in policy action</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'aws-iam-list-roles' AND json.rule = role.assumeRolePolicyDocument.Statement[*].Action contains "sts:AssumeRoleWithWebIdentity" and role.assumeRolePolicyDocument.Statement[*].Principal.Federated contains "cognito-identity.amazonaws.com" and role.assumeRolePolicyDocument.Statement[*].Effect contains "Allow" and role.assumeRolePolicyDocument.Statement[*].Condition contains "cognito-identity.amazonaws.com:amr" and role.assumeRolePolicyDocument.Statement[*].Condition contains "unauthenticated" as X; config from cloud.resource where api.name = 'aws-iam-get-policy-version' AND json.rule = document.Statement[?any(Effect equals Allow and Action contains :* and Resource equals * )] exists as Y; filter "($.X.inlinePolicies[*].policyDocument.Statement[?(@.Effect=='Allow' &#x26;&#x26; @.Resource=='*')].Action contains :* ) or ($.X.attachedPolicies[*].policyArn intersects $.Y.policyArn)"; show X;
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'aws-iam-list-roles' AND json.rule = role.assumeRolePolicyDocument.Statement[*].Action contains "sts:AssumeRoleWithWebIdentity" and role.assumeRolePolicyDocument.Statement[*].Principal.Federated contains "cognito-identity.amazonaws.com" and role.assumeRolePolicyDocument.Statement[*].Effect contains "Allow" and role.assumeRolePolicyDocument.Statement[*].Condition contains "cognito-identity.amazonaws.com:amr" and role.assumeRolePolicyDocument.Statement[*].Condition contains "unauthenticated" as X; config from cloud.resource where api.name = 'aws-iam-get-policy-version' AND json.rule = document.Statement[?any(Effect equals Allow and (Action contains :* or Action equals *) and Resource equals * )] exists as Y; filter "($.X.inlinePolicies[*].policyDocument.Statement[?(@.Effect=='Allow' &#x26;&#x26; @.Resource=='*')].Action contains :* ) or ($.X.inlinePolicies[*].policyDocument.Statement[?(@.Effect=='Allow' &#x26;&#x26; @.Resource=='*')].Action equals * ) or ($.X.attachedPolicies[*].policyArn intersects $.Y.policyArn)"; show X;
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> High</p><p><strong>Impact–</strong> Low. New alerts will be generated as per new RQL.</p></td></tr><tr><td><strong>AWS Cognito service role with wide privileges does not validate authentication</strong></td><td><p><strong>Changes—</strong> Policy RQL has been updated with including the condition matching '*' in policy action</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'aws-iam-list-roles' AND json.rule = role.assumeRolePolicyDocument.Statement[*].Action contains "sts:AssumeRoleWithWebIdentity" and role.assumeRolePolicyDocument.Statement[*].Principal.Federated contains "cognito-identity.amazonaws.com" and role.assumeRolePolicyDocument.Statement[*].Effect contains "Allow" and role.assumeRolePolicyDocument.Statement[*].Condition contains "cognito-identity.amazonaws.com:amr" and role.assumeRolePolicyDocument.Statement[*].Condition contains "unauthenticated" as X; config from cloud.resource where api.name = 'aws-iam-get-policy-version' AND json.rule = document.Statement[?any(Effect equals Allow and Action contains :* and Resource equals * )] exists as Y; filter "($.X.inlinePolicies[*].policyDocument.Statement[?(@.Effect=='Allow' &#x26;&#x26; @.Resource=='*')].Action contains :* ) or ($.X.attachedPolicies[*].policyArn intersects $.Y.policyArn)"; show X;
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'aws-iam-list-roles' AND json.rule = role.assumeRolePolicyDocument.Statement[*].Action contains "sts:AssumeRoleWithWebIdentity" and role.assumeRolePolicyDocument.Statement[*].Principal.Federated contains "cognito-identity.amazonaws.com" and role.assumeRolePolicyDocument.Statement[*].Effect contains "Allow" and role.assumeRolePolicyDocument.Statement[*].Condition contains "cognito-identity.amazonaws.com:amr" and role.assumeRolePolicyDocument.Statement[*].Condition contains "unauthenticated" as X; config from cloud.resource where api.name = 'aws-iam-get-policy-version' AND json.rule = document.Statement[?any(Effect equals Allow and (Action contains :* or Action equals *) and Resource equals * )] exists as Y; filter "($.X.inlinePolicies[*].policyDocument.Statement[?(@.Effect=='Allow' &#x26;&#x26; @.Resource=='*')].Action contains :* ) or ($.X.inlinePolicies[*].policyDocument.Statement[?(@.Effect=='Allow' &#x26;&#x26; @.Resource=='*')].Action equals * ) or ($.X.attachedPolicies[*].policyArn intersects $.Y.policyArn)"; show X;
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> High</p><p><strong>Impact–</strong> Low. New alerts will be generated as per new RQL.</p></td></tr><tr><td><strong>Policy Updates—Metadata</strong></td><td></td></tr><tr><td><strong>AWS S3 bucket not configured with secure data transport policy</strong></td><td><p><strong>Changes—</strong> Policy description updated to include the publicly accessible check.</p><p><strong>Policy Type</strong>: Config</p><p><strong>Policy Severity</strong>: Medium</p><p><strong>Impact</strong>: No impact on alerts</p><p><strong>Updated Description</strong>:</p><pre><code>AWS S3 buckets that are publicly accessible and lacking secure data transport are highly susceptible to data breaches during transit.
AWS S3 buckets should enforce data encryption using Secure Sockets Layer (SSL) to protect data transmitted between clients and the S3 service. Failure to enforce HTTPS allows attackers to intercept sensitive data in transit, leading to data exposure and potential breaches. Additionally, because the bucket is publicly accessible, untrusted IPs can access sensitive data without encryption.
The impact of this misconfiguration includes unauthorized access to sensitive data, data breaches, and potential regulatory fines. Enforcing HTTPS ensures all communication with publicly accessible S3 buckets is encrypted, protecting data confidentiality and integrity.
To mitigate this, configure bucket policies to explicitly deny all access except via HTTPS ('aws:SecureTransport: true') and remove public access permissions. Regularly review and update bucket policies to reflect evolving security needs and ensure that public access is minimized or removed.
</code></pre></td></tr><tr><td><strong>AWS S3 bucket not configured with secure data transport policy</strong></td><td><p><strong>Changes—</strong> Policy description updated to include the publicly accessible check.</p><p><strong>Policy Type</strong>: Config</p><p><strong>Policy Severity</strong>: Medium</p><p><strong>Impact</strong>: Low</p><p><strong>Updated Description</strong>:</p><pre><code>AWS S3 buckets that are publicly accessible and lacking secure data transport are highly susceptible to data breaches during transit.
AWS S3 buckets should enforce data encryption using Secure Sockets Layer (SSL) to protect data transmitted between clients and the S3 service. Failure to enforce HTTPS allows attackers to intercept sensitive data in transit, leading to data exposure and potential breaches. Additionally, because the bucket is publicly accessible, untrusted IPs can access sensitive data without encryption.
The impact of this misconfiguration includes unauthorized access to sensitive data, data breaches, and potential regulatory fines. Enforcing HTTPS ensures all communication with publicly accessible S3 buckets is encrypted, protecting data confidentiality and integrity.
To mitigate this, configure bucket policies to explicitly deny all access except via HTTPS ('aws:SecureTransport: true') and remove public access permissions. Regularly review and update bucket policies to reflect evolving security needs and ensure that public access is minimized or removed.
</code></pre></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                              | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| --------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **\[Update] Australian Cyber Security Centre (ACSC) Essential Eight** | <p>New Policy mappings are added to Australian Cyber Security Centre (ACSC) Essential Eight compliance standard across all the levels..</p><p><strong>Impact</strong>: As new mappings are introduced, compliance scoring might vary.</p>                                                                                                                                                                                                                                                                                                                                                                                                       |
| **FedRAMP (High)**                                                    | <p>FedRAMP High compliance is the highest level of security within the Federal Risk and Authorization Management Program (FedRAMP), designed to protect highly sensitive and classified government data stored in cloud environments.</p><p>You can now access this built-in standard and related policies on the <strong>Compliance > Standards</strong> page. Additionally, you can generate reports to instantly view or download them, or set up scheduled reports to continuously monitor compliance.</p>                                                                                                                                  |
| **\[Update] CIS v3.0.0 (OCI) - Level 1 & CIS v3.0.0 (OCI) - Level 2** | <p>Prisma Cloud now supports the latest version of CIS Oracle Cloud Infrastructure Foundations Benchmark . This compliance standard supports two levels - Level 1 and Level 2. CIS Oracle Cloud Infrastructure Foundations Benchmark, provides prescriptive guidance for establishing a secure baseline configuration for the Oracle Cloud Infrastructure environment.</p><p>You can now access this built-in standard and related policies on the <strong>Compliance > Standards</strong> page. Additionally, you can generate reports to instantly view or download them, or set up scheduled reports to continuously monitor compliance.</p> |

## REST API Updates

| **REST API**                                                                                                                                                                                 | **Description**                                                                                                                                                                                                                                                                                                                                                                   |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Download Image Scan Results API</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p> | ​A new column, `Cloud Security Agent Hosts`, is added in the Download Image Scan Results API CSV file response. This new field lists the number of integrated XDR Agents in the Prisma Cloud and Cortex XDR integration.                                                                                                                                                          |
| <p><strong>Support for new agentless APIs</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p>  | <p>The following new API endpoints enable you to set the maximum number of scanners for an agentless account and get the agentless scan statistics.</p><ul><li><a href="https://pan.dev/compute/api/post-agentless-max-scanners/">Agentless Max Scanners</a></li><li><a href="https://pan.dev/compute/api/get-agentless-scan-statistics/">Agentless Scan Statistics</a></li></ul> |
| <p><strong>Support for a new enum value</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p>    | A new Enum value `gcp-cloud-run-service` has been added to the `shared.ScanResultType` schema.                                                                                                                                                                                                                                                                                    |

## Deprecation Notices

| **Feature**                                                                                                                                                                                  | **Description**                                                                                                                                                                                                                                                                                                                                                                                  |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><strong>Deprecation of the CNNS feature</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.01.126</mark></p> | The ​Cloud Native Network Segmentation (CNNS) feature is deprecated for the enforcement of protection against network threats for both containers and hosts. However, in scenarios where alternative network monitoring modes are unavailable, it can be used only for monitoring, such as radar visibility. The current recommendation is to disable all CNNS-based network monitoring as well. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2025/features-introduced-in-may-2025.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
