For the complete documentation index, see llms.txt. This page is also available as Markdown.

Features Introduced in April 2026

Learn what’s new in the Prisma® Cloud April (26.4.1) 2026 release.

Enhancements

Feature

Description

AWS SDK for Java 2.x Support

Secure the Runtime

Prisma Cloud now supports the AWS SDK for Java 2.x, replacing the older AWS SDK for Java 1.x.This upgrade ensures compatibility with the latest AWS services and features, providing improved performance and security.

Restrict UI access for access key logins

Secure the Runtime

Added ability to block login using an access key via the CWP login UI page under a feature flag, aligning with the way access key based logins are handled by the main Prisma login page.

FIPS configuration via environment variable

Secure the Runtime

Added support for setting the FIPS_ENABLED configuration from an environment variable in twistlock.cfg.

nginx_unit vulnerability detection

Secure the Runtime

Added vulnerability detection support for nginx_unit application server binaries.

Configurable Cap for Per-Image Clusters

Secure the Runtime

You can now configure a cap on the number of clusters stored per image in MongoDB. This prevents excessive document growth for widely-deployed images and improves database performance.

OCI Compartment Support for Agentless Scanning

Secure the Runtime

Agentless scanning configuration now accepts OCI compartments by OCID in addition to compartment name. Use the OCID when you need to reference compartments programmatically or avoid ambiguity with duplicate names.

Package URL Augmentation for Binary Packages

Secure the Runtime

The scanner now augments binary packages with Package URLs (PURLs), improving software composition analysis accuracy and enabling better vulnerability correlation.

Upgrade xmlquery to avoid CVE-2026-32287

Secure the Runtime

Upgraded xmlquery (and xpath) dependencies to remediate CVE-2026-32287.

Remove libnghttp2 from Defender Dockerfile

Secure the Runtime

Removed the libnghttp2 package from the Defender Dockerfile to eliminate a known vulnerability from the container image.

Updated MongoDB to 7.0.31

Secure the Runtime

Updated MongoDB from 7.0.29 to 7.0.31 to address additional security vulnerabilities.

Changes in Existing Behavior

Audit Log Retention Policy

The retention period for audit events stored in the Prisma Cloud database changed from 120 days to 30 days. This update is part of our ongoing efforts to optimize performance and resource usage. The new retention period ensures a more responsive experience and efficient resource utilization across all environments.

Impact: Features that rely on historical audit data will be impacted: * Audit Trail & Investigation: Tracing user actions and general audit log investigations will now be limited to the last 30 days of data. * Alert Details: For alerts triggered by audit events, the associated event details will no longer be available for investigation, when you select Investigate 30 + days after the event occurred. * Policy Evaluation: Evaluation of audit-event-based policies will focus on events within a 30-day window. * General Impact: Other platform features or custom workflows that rely on the retention of audit events beyond 30 days may be impacted.

The following functional areas will continue to operate without change, as they rely on real-time event processing: * Event Assisted Ingestion (EAI): Real-time ingestion triggers remain unaffected. * IAM Security: Real-time IAM analysis and monitoring remain unaffected. * Real-time Alerting: The triggering of alerts based on immediate event matches is not impacted.

No additional action is required. If your compliance or operational requirements necessitate audit log retention beyond 30 days, we recommend ensuring your CSP (AWS, Azure, GCP) is configured to archive these logs in their respective native storage (e.g., S3, GCS, or Azure Blob Storage).

VPC Resource Ingestion

Prisma Cloud will now ingest accepter side VPC connections in addition to requester side VPC connections. This will ensure better coverage of VPC peering endpoints irrespective of whether the given VPC functions as a requester or an accepter for a given connection.

API Ingestions

Service

API Details

Amazon Web Services

Amazon AppStream 2.0

aws-app-stream-app-block-builder

Additional permissions required:

  • appstream:DescribeAppBlockBuilders

  • appstream:ListTagsForResource

The Security Audit role does not include the permissions. A custom role is required.

Amazon Cognito

aws-cognito-identity-provider

Additional permissions required:

  • cognito-idp:ListUserPools

  • cognito-idp:ListIdentityProviders

  • cognito-idp:DescribeIdentityProvider

The Security Audit role includes the permissions.

Amazon Elasticsearch Service

aws-es-serverless-access-policy

Additional permissions required:

  • aoss:ListAccessPolicies

  • aoss:GetAccessPolicy

The Security Audit role does not include the permissions. You must add a custom role that includes these permissions.

Amazon Elasticsearch Service

aws-es-serverless-security-policy

Additional permissions required:

  • aoss:ListSecurityPolicies

  • aoss:GetSecurityPolicy

The Security Audit role does not include the permissions. You must add a custom role that includes these permissions.

Amazon Neptune

aws-neptune-analytics-graph

Additional permissions required:

  • neptune-graph:ListGraphs

  • neptune-graph:GetGraph

  • neptune-graph:ListTagsForResource

The Security Audit role does not include the permissions. A custom role is required.

Amazon Q Business

aws-qbusiness-index

Additional permissions required:

  • qbusiness:ListIndices

  • qbusiness:GetIndex

  • qbusiness:ListApplications

  • qbusiness:GetApplication

  • qbusiness:ListDataSources

  • qbusiness:GetDataSource

The Security Audit role includes the permissions.

Amazon Q Business

aws-qbusiness-application

Additional permissions required:

  • qbusiness:ListApplications

  • qbusiness:GetApplication

  • qbusiness:GetPolicy

  • qbusiness:GetChatControlsConfiguration

  • qbusiness:ListTagsForResource

The Security Audit role includes the permissions.

Amazon Route53

aws-route53-profile

Additional permissions required:

  • route53profiles:ListProfiles

  • route53profiles:GetProfile

  • route53profiles:ListTagsForResource

The Security Audit role does not include the permissions. A custom role is required.

Amazon Route53

aws-route53-domains-operation

Additional permission required:

  • route53domains:ListOperations

The Security Audit role includes the permission.

AWS Database Migration Service

aws-dms-data-provider

Additional permissions required:

  • dms:DescribeDataProviders

  • dms:ListTagsForResource

The Security Audit role includes the permissions.

AWS Database Migration Service

aws-dms-replication-config

Additional permissions required:

  • dms:DescribeReplicationConfigs

  • dms:ListTagsForResource

The Security Audit role includes the permissions.

AWS Database Migration Service

aws-dms-replication-subnet-group

Additional permissions required:

  • dms:DescribeReplicationSubnetGroups

  • dms:ListTagsForResource

The Security Audit role includes the permissions.

AWS Database Migration Service

aws-dms-instance-profile

Additional permissions required:

  • dms:ListInstanceProfiles

  • dms:ListTagsForResource

dms:ListTagsForResource is included in the Security Audit role. dms:ListInstanceProfiles is not included in the Security Audit role.

AWS Service Quotas

aws-servicequotas-service-quota

Additional permissions required:

  • servicequotas:ListServiceQuotas

  • servicequotas:ListTagsForResource

The Security Audit role includes the permissions.

This API only supports AWS service 'VPC' quota details.

Microsoft Azure

Azure Power BI Embedded

azure-powerbi-dedicated-capacities-diagnostic-settings

Additional permissions required:

  • Microsoft.PowerBIDedicated/servers/read

  • Microsoft.PowerBIDedicated/capacities/read

The Reader role includes the permissions.

Google Cloud Platform

Google Backup For GKE

gcloud-gke-backup-backup-plan

Additional permissions required:

  • gkebackup.backupPlans.list

  • gkebackup.backupPlans.getIamPolicy

The Viewer role includes the permissions.

Google Backup For GKE

gcloud-gke-backup-restore-plan

Additional permissions required:

  • gkebackup.restorePlans.list

  • gkebackup.restorePlans.getIamPolicy

The Viewer role includes the permissions.

Google Cloud SQL

gcloud-sql-instance-user

Additional permission required:

  • cloudsql.users.list

The Viewer role includes the permission.

Google Network Security

gcloud-network-security-project-address-group

Additional permission required:

  • networksecurity.addressGroups.list

The Viewer role includes the permission.

Google Network Security

gcloud-network-security-organization-address-group

Additional permission required:

  • networksecurity.addressGroups.list

The Viewer role includes the permission.

Google Private Service Connect

gcloud-psc-service-attachment

Additional permissions required:

  • compute.serviceAttachments.list

  • compute.serviceAttachments.getIamPolicy

The Viewer role includes the permissions.

Google Private Service Connect

gcloud-psc-connection-policy

Additional permissions required:

  • networkconnectivity.serviceConnectionPolicies.list

The Viewer role includes the permissions.

Google Private Service Connect

gcloud-psc-network-attachment

Additional permissions required:

  • compute.networkAttachments.list

  • compute.networkAttachments.getIamPolicy

The Viewer role includes the permissions.

Oracle Cloud Infrastructure

OCI Regions

Update

Prisma Cloud now supports the following four new Oracle Cloud Infrastructure (OCI) regions:

  • Indonesia North (Batam) - ap-batam-1

  • Serbia Central (Jovanovac) - eu-jovanovac-1

  • Spain Central (Madrid 3) - eu-madrid-3

  • Italy North (Turin) - eu-turin-1

API Updates

Amazon EventBridge

Update

aws-events-eventbus

Additional permission required:

  • events:DescribeEventBus

The API now ingests additional fields related to the eventbus resource.

Amazon Route 53

Update

aws-route53-list-hosted-zones

The API now ingests additional fields related to the hosted zones resource:

  • DelegationSet →Id CallerReference NameServers

Amazon Route53 Resolver

Update

aws-route53resolver-resolver-endpoint

The API now ingests additional attribute IpAddresses.

Additional permission required:

  • route53resolver:ListResolverEndpointIpAddresses

The Security Audit role includes the permission.

Amazon S3

Update

aws-s3api-get-bucket-acl

The API now ingests an additional field BucketArn related to the S3 bucket resource.

AWS Secrets Manager

Update

aws-secretsmanager-describe-secret

The API now ingests additional attribute replicationStatus.

Additional permission required:

  • secretsmanager:DescribeSecret

The Security Audit role includes the permission.

Azure App Service

Update

azure-app-service and azure-app-service-deployment-slots

The APIs have been updated with permission changes for App Service and App Service Deployment Slots ingestion.

Azure Storage Account Access Key

Update

azure-storage-account-access-key

The API now ingests additional parameter allowSharedKeyAccess.

Azure App Service

Update

azure-app-service-deployment-slots

The API now ingests Slot Configuration fields for Azure App Service Deployment Slots. The following additional JSON fields are now available:

  • config.storageType

  • config.http20Enabled

  • config.loadBalancing

  • config.minTlsVersion

  • config.ftpsState

The List Slot Configuration response is now stitched into the API response.

API Deprecations

Azure Orbital and Mixed Reality

Deprecation

The following Azure APIs have been deprecated as the underlying Azure services were retired:

  • azure-orbital-spacecrafts - Azure Orbital Ground Station was retired by Microsoft.

  • azure-mixed-reality-object-anchors-accounts - Azure Object Anchors (AOA) was retired by Microsoft.

These APIs will no longer ingest data.

GCP Data Catalog

Deprecation

GCP Data Catalog is deprecated and will be discontinued. The following Data Catalog APIs are deprecated on Prisma Cloud:

  • gcloud-data-catalog-taxonomy

  • gcloud-data-catalog-entry-group

  • gcloud-data-catalog-tag-template

Policy Updates

Policy Name

Details

Azure VM disk configured with overly permissive network access

Severity: Medium

Changes: The policy RQL has been updated to exclude Azure VM disks created for Prisma Cloud Azure agentless scanning (tagged with 'prismacloud-agentless-scan').

Current RQL:

Updated RQL:

Impact: Medium - Previously reported disks tagged with 'prismacloud-agentless-scan' will be resolved as Policy Updated.

Azure VM OS disk is encrypted with the default encryption key instead of ADE/CMK

Severity: Informational

Changes: The policy RQL has been updated to remove the legacy encryptionSettings attribute check.

Current RQL:

Updated RQL:

Impact: Low

GCP Dataproc Cluster on GKE is using default network

Severity: Medium

Changes: Policy RQL has been updated to cover Dataproc clusters using zonal GKE clusters.

Current RQL:

Updated RQL:

Impact: Low - New alerts will be generated as per new RQL.

GCP Dataproc Cluster on Compute Engine is using default network

Severity: Medium

Changes: Policy RQL has been updated to match GCP API.

Current RQL:

Updated RQL:

Impact: Low - New alerts will be generated as per new RQL.

Policy Deletions

Policy Updates

Description

AutoFocus Policy Deletions

Changes– Palo Alto Networks' AutoFocus product has reached its End of Life (EOL) date. As a result, the following AutoFocus Anomaly policies will be removed from Prisma Cloud. Learn more about AutoFocus EOL.

  • Traffic to a suspicious IP address associated with Loader activity

  • Traffic from a suspicious IP address associated with File Infector activity

  • Traffic to a suspicious IP address associated with File Infector activity

  • Traffic from a suspicious IP address associated with Dropper activity

  • Traffic to a suspicious IP address associated with Ransomware activity

  • Traffic to a suspicious IP address associated with Backdoor activity

  • Traffic to a suspicious IP address associated with Cryptominer activity

  • Traffic from a suspicious IP address associated with Botnet activity

  • Traffic from a suspicious IP address associated with Cryptominer activity

  • Traffic from a suspicious IP address associated with Ransomware activity

  • Traffic to a suspicious IP address associated with Linux Malware activity

  • Traffic to a suspicious IP address associated with Botnet activity

  • Traffic from a suspicious IP address associated with Backdoor activity

  • Traffic from a suspicious IP address associated with Linux Malware activity

  • Traffic from a suspicious IP address associated with Remote Access Trojan activity

  • Traffic to a suspicious IP address associated with Remote Access Trojan activity

  • Traffic from a suspicious IP address associated with DDoS activity

  • Traffic from a suspicious IP address associated with InfoStealer activity

  • Traffic to a suspicious IP address associated with DDoS activity

  • Traffic to a suspicious IP address associated with InfoStealer activity

  • Traffic from a suspicious IP address associated with Wiper activity

  • Traffic to a suspicious IP address associated with Wiper activity

  • Traffic to a suspicious IP address associated with Dropper activity

  • Traffic from a suspicious IP address associated with Loader activity

  • Traffic from a suspicious IP address associated with Rootkit activity

  • Traffic to a suspicious IP address associated with Webshell activity

  • Traffic from a suspicious IP address associated with Webshell activity

  • Traffic to a suspicious IP address associated with Rootkit activity

  • Traffic to a suspicious IP address associated with Exploit Kit activity

  • Traffic from a suspicious IP address associated with Exploit Kit activity

  • Traffic to a suspicious IP address associated with Hacking Tool activity

  • Traffic from a suspicious IP address associated with Hacking Tool activity

  • Traffic from a suspicious IP address associated with Worm activity

  • Traffic to a suspicious IP address associated with Worm activity

  • Traffic from a suspicious IP address associated with Downloader activity

  • Traffic to a suspicious IP address associated with Downloader activity

Impact– Keep in mind the following potential effects of this change: * Existing alerts will be resolved as Policy_Deleted. * All policies related to AutoFocus will be deprecated. * Attack Path policies associated with AutoFocus will be deprecated. * RQL support for AutoFocus suggestions will be removed. * The ability to add trusted IP addresses to AutoFocus anomaly polices will be deprecated. * Any custom policies that use AutoFocus attributes will also be impacted.

Compliance Updates

Compliance Standard

Details

CIS Amazon Web Services Foundations Benchmark v6.0.0

Prisma Cloud now supports CIS Amazon Web Services Foundations Benchmark v6.0.0 Level 1 and Level 2.

Level 1 defines a set of fundamental, broadly applicable security best practices that harden core AWS services while minimizing impact on usability and operations for most environments.

Level 2 builds on this with more stringent, defense-in-depth requirements intended for organizations with elevated risk or regulatory needs.

You can view this built-in standard and the associated policies on the Compliance > Standards page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.

CIS Microsoft Azure Foundations Benchmark v5.0.0

Prisma Cloud now supports CIS Microsoft Azure Foundations Benchmark v5.0.0 Level 1 and Level 2.

Level 1 provides baseline, broadly applicable security controls designed to strengthen an Azure environment without causing significant disruption to usability or operations.

Level 2 introduces more stringent, defense-in-depth controls intended for organizations with heightened security or regulatory requirements.

You can view this built-in standard and the associated policies on the Compliance > Standards page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.

Last updated

Was this helpful?