> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2026/features-introduced-in-february-2026.md).

# Features Introduced in February 2026

Learn what’s new in the Prisma® Cloud February 2026 release.

* [Enhancements](#enhancements)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [API Ingestions](#api-ingestions)
* [Policy Updates](#policy-updates)
* [Policy Deletions](#policy-deletions)

## Enhancements

| **Feature**                                                                                                                                             | **Description**                                                                                                                                                                                     |
| ------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Debian 13 Support</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                        | Debian 13 (Trixie), the current stable distribution of Linux is now supported.                                                                                                                      |
| <p><strong>Support for TLS 1.3</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                      | TLS 1.3, the latest version of the Transport Layer Security protocol is now supported.                                                                                                              |
| <p><strong>CIS Bottlerocket Benchmark Support</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                       | CIS Bottlerocket Benchmark control, that gauges the compliance of the Bottlerocket container hosting operating system is now supported. Coverage for controls 1.3.1, 1.4.3, and 1.4.4 are included. |
| <p><strong>GCP Cloud Function Gen 2 support via Cloud Run Admin API</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p> | Serverless scanning now discovers and protects Gen 2 Cloud Functions created through the Cloud Run Admin API, ensuring full coverage of your GCP serverless workloads.                              |
| <p><strong>Nftables support for Cloud Native Network Firewall</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>       | Defenders now support Nftables for Cloud Native Network Firewall (CNNF), enabling network protection on modern Linux systems that use NFTables instead of iptables.                                 |
| <p><strong>Faster CVE loading in vulnerability evaluator</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>            | Optimized CVE data loading for improved performance when analyzing vulnerabilities.                                                                                                                 |
| <p><strong>Agentless scanning stability enhancements</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                | Multiple improvements to agentless scanning reliability, reducing scan failures and improving consistency across cloud environments.                                                                |

## Changes in Existing Behavior

| **Feature**                                | **Description**                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Azure Storage Accounts Read Scope Lock** | Updates to Prisma Cloud include a fix to address the handling of Azure Storage accounts restricted by a read scope lock. Prisma now classifies read scope locks as an **Authorization limitation**. Resources affected by a read scope lock can no longer be ingested. Any previously ingested resources that later become scope locked will automatically be marked as deleted. |

## API Ingestions

| **Service**                                                                                      | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                         |
| ------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **AWS Service Catalog**                                                                          | <p><strong>aws-servicecatalog-provisioned-product</strong></p><p>Additional permission required:</p><ul><li><code>servicecatalog:SearchProvisionedProducts</code></li></ul><p>The Security audit role does not include the permission. A custom role is required.</p>                                                                                                                                                   |
| **Amazon Pinpoint**                                                                              | <p><strong>aws-pinpoint-apns-sandbox-channel</strong></p><p>Additional permissions required:</p><ul><li><code>mobiletargeting:GetApnsSandboxChannel</code></li><li><code>mobiletargeting:GetApps</code></li></ul><p>The Security audit role does not include the permissions.</p>                                                                                                                                       |
| **Amazon Pinpoint**                                                                              | <p><strong>aws-pinpoint-gcm-channel</strong></p><p>Additional permissions required:</p><ul><li><code>mobiletargeting:GetGcmChannel</code></li><li><code>mobiletargeting:GetApps</code></li></ul><p>The Security audit role does not include the permissions.</p>                                                                                                                                                        |
| **Amazon SageMaker**                                                                             | <p><strong>aws-sagemaker-flow-definition</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListFlowDefinitions</code></li><li><code>sagemaker:DescribeFlowDefinition</code></li><li><code>sagemaker:ListTags</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                          |
| **Amazon Pinpoint**                                                                              | <p><strong>aws-pinpoint-app</strong></p><p>Additional permission required:</p><ul><li><code>mobiletargeting:GetApps</code></li></ul><p>The Security audit role does not include the permission.</p>                                                                                                                                                                                                                     |
| **Amazon Pinpoint**                                                                              | <p><strong>aws-pinpoint-apns-channel</strong></p><p>Additional permissions required:</p><ul><li><code>mobiletargeting:GetApnsChannel</code></li><li><code>mobiletargeting:GetApps</code></li></ul><p>The Security audit role does not include the permissions.</p>                                                                                                                                                      |
| **Amazon DocumentDB**                                                                            | <p><strong>aws-docdb-db-cluster-snapshot</strong></p><p>Additional permissions required:</p><ul><li><code>rds:DescribeDBClusterSnapshots</code></li><li><code>rds:ListTagsForResource</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                          |
| **AWS X-Ray**                                                                                    | <p><strong>aws-xray-sampling-rule</strong></p><p>Additional permission required:</p><ul><li><code>xray:GetSamplingRules</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                                         |
| **AWS X-Ray**                                                                                    | <p><strong>aws-xray-group</strong></p><p>Additional permission required:</p><ul><li><code>xray:GetGroups</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                                                        |
| **Amazon Redshift**                                                                              | <p><strong>aws-redshift-endpoint-access</strong></p><p>Additional permission required:</p><ul><li><code>redshift:DescribeEndpointAccess</code></li></ul><p>The Security audit role includes the permission.</p>                                                                                                                                                                                                         |
| **AWS CodeDeploy**                                                                               | <p><strong>aws-code-deploy-application-deployment-group</strong></p><p>Additional permissions required:</p><ul><li><code>codedeploy:ListApplications</code></li><li><code>codedeploy:ListDeploymentGroups</code></li><li><code>codedeploy:GetDeploymentGroup</code></li><li><code>codedeploy:ListTagsForResource</code></li></ul><p>The Security audit role includes the permissions.</p>                               |
| **Amazon DocumentDB**                                                                            | <p><strong>aws-docdb-subnet-group</strong></p><p>Additional permissions required:</p><ul><li><code>rds:DescribeDBSubnetGroups</code></li><li><code>rds:ListTagsForResource</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                                     |
| **Amazon GuardDuty**                                                                             | <p><strong>aws-guardduty-publishing-destination</strong></p><p>Additional permissions required:</p><ul><li><code>guardduty:ListDetectors</code></li><li><code>guardduty:ListPublishingDestinations</code></li><li><code>guardduty:DescribePublishingDestination</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                |
| **Amazon DocumentDB**                                                                            | <p><strong>aws-docdb-db-global-cluster</strong></p><p>Additional permissions required:</p><ul><li><code>rds:DescribeGlobalClusters</code></li><li><code>rds:ListTagsForResource</code></li></ul><p>The Security audit role includes the permissions.</p>                                                                                                                                                                |
| **Amazon RDS** <mark style="background-color:orange;">Update</mark>                              | <p><strong>aws-rds-db-subnet-group</strong></p><p>Existing API is updated, JSON values <code>SupportedNetworkTypes</code> and <code>tags.TagList.Tag</code> are converted from object to array.</p><p>No additional permission is required.</p>                                                                                                                                                                         |
| **AWS X-Ray** <mark style="background-color:orange;">Update</mark>                               | <p><strong>aws-xray-encryption-config</strong></p><p>Updated the existing API to include regionId key:value to the ingested resource.</p><p>No additional permission is required.</p>                                                                                                                                                                                                                                   |
| **AWS Service Catalog** <mark style="background-color:orange;">Update</mark>                     | <p><strong>aws-servicecatalog-portfolios</strong></p><p>The API now ingests the following additional attributes:</p><ul><li><code>TagOptions</code></li><li><code>Tags</code></li></ul><p>The <code>servicecatalog:DescribePortfolio</code> permission is required for this attribute to be ingested.</p>                                                                                                               |
| **Amazon Glue** <mark style="background-color:orange;">Update</mark>                             | <p><strong>aws-glue-dev-endpoint</strong></p><p>Updated the existing API to include regionId key:value to the ingested resource.</p><p>No additional permission is required.</p>                                                                                                                                                                                                                                        |
| **Amazon VPC** <mark style="background-color:orange;">Update</mark>                              | <p><strong>aws-vpc-nat-gateway</strong></p><p>Updated the existing API to include regionId key:value to the ingested resource.</p><p>No additional permission is required.</p>                                                                                                                                                                                                                                          |
| **Amazon VPC** <mark style="background-color:orange;">Update</mark>                              | <p><strong>aws-ec2-describe-network-acls</strong></p><p>Updated the existing API to include regionId key:value to the ingested resource.</p><p>No additional permission is required.</p>                                                                                                                                                                                                                                |
| **Amazon VPC Network Access Control Lists** <mark style="background-color:orange;">Update</mark> | <p><strong>aws-ec2-describe-internet-gateways</strong></p><p>Updated the existing API to include regionId key:value to the ingested resource.</p><p>No additional permission is required.</p>                                                                                                                                                                                                                           |
| **Amazon EC2 DescribeFlowLogs** <mark style="background-color:orange;">Update</mark>             | <p><strong>aws-ec2-describe-flow-logs</strong></p><p>Updated the existing API to include regionId key:value to the ingested resource.</p><p>No additional permission is required.</p>                                                                                                                                                                                                                                   |
| **Amazon Glue Job** <mark style="background-color:orange;">Update</mark>                         | <p><strong>aws-glue-job</strong></p><p>Updated the existing API to include regionId key:value to the ingested resource.</p><p>No additional permission is required.</p>                                                                                                                                                                                                                                                 |
| **Google Dataform**                                                                              | <p><strong>gcloud-dataform-repository-workspace</strong></p><p>Additional permissions needed:</p><ul><li><code>dataform.repositories.list</code></li><li><code>dataform.workspaces.getIamPolicy</code></li><li><code>dataform.workspaces.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                          |
| **Google Dataform**                                                                              | <p><strong>gcloud-dataform-repository</strong></p><p>Additional permissions needed:</p><ul><li><code>dataform.repositories.list</code></li><li><code>dataform.repositories.getIamPolicy</code></li><li><code>dataform.compilationResults.list</code></li><li><code>dataform.releaseConfigs.list</code></li><li><code>dataform.workflowInvocations.list</code></li></ul><p>The Viewer role includes the permissions.</p> |
| **Google Dataform**                                                                              | <p><strong>gcloud-dataform-configuration</strong></p><p>Additional permissions needed:</p><ul><li><code>dataform.locations.list</code></li><li><code>dataform.config.get</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                               |
| **Google NetApp**                                                                                | <p><strong>gcloud-conversational-insights-analysis-rule</strong></p><p>Additional permission needed:</p><ul><li><code>contactcenterinsights.analysisRules.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                          |
| **Google NetApp**                                                                                | <p><strong>gcloud-netapp-active-directory</strong></p><p>Additional permission needed:</p><ul><li><code>netapp.activeDirectories.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                   |
| **Google NetApp**                                                                                | <p><strong>gcloud-netapp-backup</strong></p><p>Additional permissions needed:</p><ul><li><code>netapp.backups.list</code></li><li><code>netapp.backupVaults.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                       |
| **Google NetApp**                                                                                | <p><strong>gcloud-netapp-backup-vault</strong></p><p>Additional permission needed:</p><ul><li><code>netapp.backupVaults.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                            |
| **Google NetApp**                                                                                | <p><strong>gcloud-netapp-kms-config</strong></p><p>Additional permission needed:</p><ul><li><code>netapp.kmsConfigs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                |
| **Google NetApp**                                                                                | <p><strong>gcloud-netapp-storage-pool</strong></p><p>Additional permission needed:</p><ul><li><code>netapp.storagePools.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                            |
| **Google NetApp**                                                                                | <p><strong>gcloud-netapp-volume</strong></p><p>Additional permission needed:</p><ul><li><code>netapp.volumes.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                       |
| **Google Dataplex**                                                                              | <p><strong>gcloud-dataplex-glossary</strong></p><p>Additional permissions needed:</p><ul><li><code>dataplex.glossaries.list</code></li><li><code>dataplex.glossaries.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                      |

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>Azure Storage account diagnostic setting for blob is disabled</strong></td><td><p><strong>Changes–</strong> The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded as X; config from cloud.resource where api.name = 'azure-storage-account-blob-diagnostic-settings' AND json.rule = (properties.logs[?(@.categoryGroup)] exists and properties.logs[*].enabled any true) or (properties.logs[?(@.category)] exists and properties.logs[*].enabled all true) as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded and kind does not contain FileStorage as X; config from cloud.resource where api.name = 'azure-storage-account-blob-diagnostic-settings' AND json.rule = (properties.logs[?(@.categoryGroup)] exists and properties.logs[*].enabled any true) or (properties.logs[?(@.category)] exists and properties.logs[*].enabled all true) as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.</p></td></tr><tr><td><strong>Azure Storage account diagnostic setting for file is disabled</strong></td><td><p><strong>Changes–</strong> The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded as X; config from cloud.resource where api.name = 'azure-storage-account-file-diagnostic-settings' AND json.rule = properties.logs[*].enabled all true as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded and not(kind equal ignore case BlockBlobStorage or (kind equal ignore case StorageV2 and sku.tier equal ignore case Premium)) as X; config from cloud.resource where api.name = 'azure-storage-account-file-diagnostic-settings' AND json.rule = properties.logs[*].enabled all true as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.</p></td></tr><tr><td><strong>Azure Storage account diagnostic setting for table is disabled</strong></td><td><p><strong>Changes–</strong> The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded as X; config from cloud.resource where api.name = 'azure-storage-account-table-diagnostic-settings' AND json.rule = properties.logs[*].enabled all true as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded and not(sku.tier equal ignore case Premium or (kind equal ignore case FileStorage and sku.tier equal ignore case Standard)) as X; config from cloud.resource where api.name = 'azure-storage-account-table-diagnostic-settings' AND json.rule = properties.logs[*].enabled all true as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.</p></td></tr><tr><td><strong>Azure Storage account diagnostic setting for queue is disabled</strong></td><td><p><strong>Changes–</strong> The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded as X; config from cloud.resource where api.name = 'azure-storage-account-queue-diagnostic-settings' AND json.rule = properties.logs[*].enabled all true as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded and not(sku.tier equal ignore case Premium or (kind equal ignore case FileStorage and sku.tier equal ignore case Standard)) as X; config from cloud.resource where api.name = 'azure-storage-account-queue-diagnostic-settings' AND json.rule = properties.logs[*].enabled all true as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.</p></td></tr><tr><td><strong>AWS Application Load Balancer (ALB) is not using the latest predefined security policy</strong></td><td><p><strong>Changes–</strong> The policy RQL is updated with the latest recommended security policy.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and listeners[?any(protocol equals HTTPS and sslPolicy exists and sslPolicy is not member of ('ELBSecurityPolicy-TLS13-1-2-Res-2021-06','ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04'))] exists
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and listeners[?any(protocol equals HTTPS and sslPolicy exists and sslPolicy is not member of ('ELBSecurityPolicy-TLS13-1-2-Res-2021-06','ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09','ELBSecurityPolicy-TLS13-1-2-FIPS-PQ-2025-09'))] exists
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Open alerts where the latest policy is configured will be resolved. A new alert will be triggered where the load balancer is not configured with the latest security policy.</p></td></tr><tr><td><strong>AWS Network Load Balancer (NLB) is not using the latest predefined security policy</strong></td><td><p><strong>Changes–</strong> The policy RQL is updated with the latest recommended security policy.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = state.code equals "active" and type equals "network" and listeners[?any(protocol equals "TLS" and sslPolicy exists and sslPolicy is not member of ('ELBSecurityPolicy-TLS13-1-2-Res-2021-06','ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04'))] exists
</code></pre><p><strong>Proposed RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = state.code equals "active" and type equals "network" and listeners[?any(protocol equals "TLS" and sslPolicy exists and sslPolicy is not member of ('ELBSecurityPolicy-TLS13-1-2-Res-2021-06','ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09','ELBSecurityPolicy-TLS13-1-2-FIPS-PQ-2025-09'))] exists
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Open alerts where the latest policy is configured will be resolved. A new alert will be triggered where the load balancer is not configured with the latest security policy.</p></td></tr><tr><td><strong>Policy Updates—Metadata</strong></td><td></td></tr><tr><td><strong>Azure VM disk configured with overly permissive network access</strong></td><td><p><strong>Updated Description–</strong> Policy description is updated to convey the "defense-in-depth" perspective.</p><p>Azure Virtual Machine disks configured with public network access pose a secondary security risk in the event of a host-level breach. While disk access is restricted by identity, enabling a public network access creates a reachable path that can be exploited if the attached Virtual Machine is also compromised.</p><p>Azure Virtual Machine disks are storage resources attached to Virtual Machines. When disk public network access is enabled, it provides an internet-routable access for the disk data. If an attacker successfully compromises the attached VM or its associated credentials, this public configuration allows them to bypass internal network perimeters and exfiltrate or manipulate disk data directly from the internet.</p><p>The impact of this configuration includes simplified data exfiltration and unauthorized modification following a system compromise. By restricting access to private or trusted networks, you ensure that even if a VM is breached, the data remains shielded from the public internet. This best practice enforces a layered 'defense-in-depth' strategy.</p><p>To mitigate this risk, disable public network access for all Azure Virtual Machine disks. Utilize Azure Private Link or restricted Disk Access settings to ensure that storage traffic remains within the private network. Regularly review and audit network configurations to identify and remediate any disks that remain exposed to public routing.</p></td></tr></tbody></table>

## Policy Deletions

| **Policy Updates**         | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| -------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Azure Policy Deletions** | <p><strong>Changes–</strong> The following Azure policies will be removed from Prisma Cloud because the database services <strong>Azure Database for MySQL - Single Server</strong>, <strong>Azure Database for PostgreSQL - Single Server</strong>, and <strong>Azure Database for MariaDB</strong> have been retired by the cloud service provider (CSP).</p><p><strong>List of deleted policies:</strong></p><ol><li>Azure Database for MySQL server not configured with private endpoint</li><li>Azure MySQL Database Server using insecure TLS version</li><li>Azure MySQL Database Server SSL connection is disabled</li><li>Azure PostgreSQL database server with log duration parameter disabled</li><li>Azure PostgreSQL database server with SSL connection disabled</li><li>Azure PostgreSQL database server with log checkpoints parameter disabled</li><li>Azure PostgreSQL Database Server 'Allow access to Azure services' enabled</li><li>Azure PostgreSQL database server with connection throttling parameter is disabled</li><li>Azure PostgreSQL servers not configured with private endpoint</li><li>Azure PostgreSQL database server log retention days is less than or equals to 3 days</li><li>Azure PostgreSQL database server Infrastructure double encryption is disabled</li><li>Azure PostgreSQL database server deny public network access setting is not set</li><li>Azure PostgreSQL Database Server Firewall rule allow access to all IPV4 address</li><li>Azure PostgreSQL database server with log disconnections parameter disabled</li><li>Azure PostgreSQL database server with log connections parameter disabled</li><li>Azure MariaDB database server not using latest TLS version</li><li>Azure Database for MariaDB not configured with private endpoint</li><li>Azure MariaDB database server with SSL connection disabled</li></ol><p><strong>Impact–</strong> Existing alerts will be resolved as <code>Policy\_Deleted</code>.</p> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2026/features-introduced-in-february-2026.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
