Features Introduced in February 2026
Learn what’s new in the Prisma® Cloud February (26.2.1) 2026 release.
Enhancements
Feature
Description
Debian 13 Support
Secure the Runtime
Debian 13 (Trixie), the current stable distribution of Linux is now supported.
Support for TLS 1.3
Secure the Runtime
TLS 1.3, the latest version of the Transport Layer Security protocol is now supported.
CIS Bottlerocket Benchmark Support
Secure the Runtime
CIS Bottlerocket Benchmark control, that gauges the compliance of the Bottlerocket container hosting operating system is now supported. Coverage for controls 1.3.1, 1.4.3, and 1.4.4 are included.
GCP Cloud Function Gen 2 support via Cloud Run Admin API
Secure the Runtime
Serverless scanning now discovers and protects Gen 2 Cloud Functions created through the Cloud Run Admin API, ensuring full coverage of your GCP serverless workloads.
Nftables support for Cloud Native Network Firewall
Secure the Runtime
Defenders now support Nftables for Cloud Native Network Firewall (CNNF), enabling network protection on modern Linux systems that use NFTables instead of iptables.
Faster CVE loading in vulnerability evaluator
Secure the Runtime
Optimized CVE data loading for improved performance when analyzing vulnerabilities.
Agentless scanning stability enhancements
Secure the Runtime
Multiple improvements to agentless scanning reliability, reducing scan failures and improving consistency across cloud environments.
Changes in Existing Behavior
Feature
Description
Azure Storage Accounts Read Scope Lock
Updates to Prisma Cloud include a fix to address the handling of Azure Storage accounts restricted by a read scope lock. Prisma now classifies read scope locks as an Authorization limitation. Resources affected by a read scope lock can no longer be ingested. Any previously ingested resources that later become scope locked will automatically be marked as deleted.
API Ingestions
Service
API Details
AWS Service Catalog
aws-servicecatalog-provisioned-product
Additional permission required:
servicecatalog:SearchProvisionedProducts
The Security audit role does not include the permission. A custom role is required.
Amazon Pinpoint
aws-pinpoint-apns-sandbox-channel
Additional permissions required:
mobiletargeting:GetApnsSandboxChannelmobiletargeting:GetApps
The Security audit role does not include the permissions.
Amazon Pinpoint
aws-pinpoint-gcm-channel
Additional permissions required:
mobiletargeting:GetGcmChannelmobiletargeting:GetApps
The Security audit role does not include the permissions.
Amazon SageMaker
aws-sagemaker-flow-definition
Additional permissions required:
sagemaker:ListFlowDefinitionssagemaker:DescribeFlowDefinitionsagemaker:ListTags
The Security audit role includes the permissions.
Amazon Pinpoint
aws-pinpoint-app
Additional permission required:
mobiletargeting:GetApps
The Security audit role does not include the permission.
Amazon Pinpoint
aws-pinpoint-apns-channel
Additional permissions required:
mobiletargeting:GetApnsChannelmobiletargeting:GetApps
The Security audit role does not include the permissions.
Amazon DocumentDB
aws-docdb-db-cluster-snapshot
Additional permissions required:
rds:DescribeDBClusterSnapshotsrds:ListTagsForResource
The Security audit role includes the permissions.
AWS X-Ray
aws-xray-sampling-rule
Additional permission required:
xray:GetSamplingRules
The Security audit role includes the permission.
AWS X-Ray
aws-xray-group
Additional permission required:
xray:GetGroups
The Security audit role includes the permission.
Amazon Redshift
aws-redshift-endpoint-access
Additional permission required:
redshift:DescribeEndpointAccess
The Security audit role includes the permission.
AWS CodeDeploy
aws-code-deploy-application-deployment-group
Additional permissions required:
codedeploy:ListApplicationscodedeploy:ListDeploymentGroupscodedeploy:GetDeploymentGroupcodedeploy:ListTagsForResource
The Security audit role includes the permissions.
Amazon DocumentDB
aws-docdb-subnet-group
Additional permissions required:
rds:DescribeDBSubnetGroupsrds:ListTagsForResource
The Security audit role includes the permissions.
Amazon GuardDuty
aws-guardduty-publishing-destination
Additional permissions required:
guardduty:ListDetectorsguardduty:ListPublishingDestinationsguardduty:DescribePublishingDestination
The Security audit role includes the permissions.
Amazon DocumentDB
aws-docdb-db-global-cluster
Additional permissions required:
rds:DescribeGlobalClustersrds:ListTagsForResource
The Security audit role includes the permissions.
Amazon RDS Update
aws-rds-db-subnet-group
Existing API is updated, JSON values SupportedNetworkTypes and tags.TagList.Tag are converted from object to array.
No additional permission is required.
AWS X-Ray Update
aws-xray-encryption-config
Updated the existing API to include regionId key:value to the ingested resource.
No additional permission is required.
AWS Service Catalog Update
aws-servicecatalog-portfolios
The API now ingests the following additional attributes:
TagOptionsTags
The servicecatalog:DescribePortfolio permission is required for this attribute to be ingested.
Amazon Glue Update
aws-glue-dev-endpoint
Updated the existing API to include regionId key:value to the ingested resource.
No additional permission is required.
Amazon VPC Update
aws-vpc-nat-gateway
Updated the existing API to include regionId key:value to the ingested resource.
No additional permission is required.
Amazon VPC Update
aws-ec2-describe-network-acls
Updated the existing API to include regionId key:value to the ingested resource.
No additional permission is required.
Amazon VPC Network Access Control Lists Update
aws-ec2-describe-internet-gateways
Updated the existing API to include regionId key:value to the ingested resource.
No additional permission is required.
Amazon EC2 DescribeFlowLogs Update
aws-ec2-describe-flow-logs
Updated the existing API to include regionId key:value to the ingested resource.
No additional permission is required.
Amazon Glue Job Update
aws-glue-job
Updated the existing API to include regionId key:value to the ingested resource.
No additional permission is required.
Google Dataform
gcloud-dataform-repository-workspace
Additional permissions needed:
dataform.repositories.listdataform.workspaces.getIamPolicydataform.workspaces.list
The Viewer role includes the permissions.
Google Dataform
gcloud-dataform-repository
Additional permissions needed:
dataform.repositories.listdataform.repositories.getIamPolicydataform.compilationResults.listdataform.releaseConfigs.listdataform.workflowInvocations.list
The Viewer role includes the permissions.
Google Dataform
gcloud-dataform-configuration
Additional permissions needed:
dataform.locations.listdataform.config.get
The Viewer role includes the permissions.
Google NetApp
gcloud-conversational-insights-analysis-rule
Additional permission needed:
contactcenterinsights.analysisRules.list
The Viewer role includes the permission.
Google NetApp
gcloud-netapp-active-directory
Additional permission needed:
netapp.activeDirectories.list
The Viewer role includes the permission.
Google NetApp
gcloud-netapp-backup
Additional permissions needed:
netapp.backups.listnetapp.backupVaults.list
The Viewer role includes the permissions.
Google NetApp
gcloud-netapp-backup-vault
Additional permission needed:
netapp.backupVaults.list
The Viewer role includes the permission.
Google NetApp
gcloud-netapp-kms-config
Additional permission needed:
netapp.kmsConfigs.list
The Viewer role includes the permission.
Google NetApp
gcloud-netapp-storage-pool
Additional permission needed:
netapp.storagePools.list
The Viewer role includes the permission.
Google NetApp
gcloud-netapp-volume
Additional permission needed:
netapp.volumes.list
The Viewer role includes the permission.
Google Dataplex
gcloud-dataplex-glossary
Additional permissions needed:
dataplex.glossaries.listdataplex.glossaries.getIamPolicy
The Viewer role includes the permissions.
Policy Updates
Policy Updates
Description
Policy Updates—RQL
Azure Storage account diagnostic setting for blob is disabled
Changes– The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Low
Impact– Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.
Azure Storage account diagnostic setting for file is disabled
Changes– The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Low
Impact– Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.
Azure Storage account diagnostic setting for table is disabled
Changes– The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Low
Impact– Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.
Azure Storage account diagnostic setting for queue is disabled
Changes– The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Low
Impact– Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.
AWS Application Load Balancer (ALB) is not using the latest predefined security policy
Changes– The policy RQL is updated with the latest recommended security policy.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Low
Impact– Low. Open alerts where the latest policy is configured will be resolved. A new alert will be triggered where the load balancer is not configured with the latest security policy.
AWS Network Load Balancer (NLB) is not using the latest predefined security policy
Changes– The policy RQL is updated with the latest recommended security policy.
Current RQL–
Proposed RQL–
Policy Type– Config
Policy Severity– Low
Impact– Low. Open alerts where the latest policy is configured will be resolved. A new alert will be triggered where the load balancer is not configured with the latest security policy.
Policy Updates—Metadata
Azure VM disk configured with overly permissive network access
Updated Description– Policy description is updated to convey the "defense-in-depth" perspective.
Azure Virtual Machine disks configured with public network access pose a secondary security risk in the event of a host-level breach. While disk access is restricted by identity, enabling a public network access creates a reachable path that can be exploited if the attached Virtual Machine is also compromised.
Azure Virtual Machine disks are storage resources attached to Virtual Machines. When disk public network access is enabled, it provides an internet-routable access for the disk data. If an attacker successfully compromises the attached VM or its associated credentials, this public configuration allows them to bypass internal network perimeters and exfiltrate or manipulate disk data directly from the internet.
The impact of this configuration includes simplified data exfiltration and unauthorized modification following a system compromise. By restricting access to private or trusted networks, you ensure that even if a VM is breached, the data remains shielded from the public internet. This best practice enforces a layered 'defense-in-depth' strategy.
To mitigate this risk, disable public network access for all Azure Virtual Machine disks. Utilize Azure Private Link or restricted Disk Access settings to ensure that storage traffic remains within the private network. Regularly review and audit network configurations to identify and remediate any disks that remain exposed to public routing.
Policy Deletions
Policy Updates
Description
Azure Policy Deletions
Changes– The following Azure policies will be removed from Prisma Cloud because the database services Azure Database for MySQL - Single Server, Azure Database for PostgreSQL - Single Server, and Azure Database for MariaDB have been retired by the cloud service provider (CSP).
List of deleted policies:
Azure Database for MySQL server not configured with private endpoint
Azure MySQL Database Server using insecure TLS version
Azure MySQL Database Server SSL connection is disabled
Azure PostgreSQL database server with log duration parameter disabled
Azure PostgreSQL database server with SSL connection disabled
Azure PostgreSQL database server with log checkpoints parameter disabled
Azure PostgreSQL Database Server 'Allow access to Azure services' enabled
Azure PostgreSQL database server with connection throttling parameter is disabled
Azure PostgreSQL servers not configured with private endpoint
Azure PostgreSQL database server log retention days is less than or equals to 3 days
Azure PostgreSQL database server Infrastructure double encryption is disabled
Azure PostgreSQL database server deny public network access setting is not set
Azure PostgreSQL Database Server Firewall rule allow access to all IPV4 address
Azure PostgreSQL database server with log disconnections parameter disabled
Azure PostgreSQL database server with log connections parameter disabled
Azure MariaDB database server not using latest TLS version
Azure Database for MariaDB not configured with private endpoint
Azure MariaDB database server with SSL connection disabled
Impact– Existing alerts will be resolved as Policy_Deleted.
Last updated
Was this helpful?

