For the complete documentation index, see llms.txt. This page is also available as Markdown.

Features Introduced in February 2026

Learn what’s new in the Prisma® Cloud February (26.2.1) 2026 release.

Enhancements

Feature

Description

Debian 13 Support

Secure the Runtime

Debian 13 (Trixie), the current stable distribution of Linux is now supported.

Support for TLS 1.3

Secure the Runtime

TLS 1.3, the latest version of the Transport Layer Security protocol is now supported.

CIS Bottlerocket Benchmark Support

Secure the Runtime

CIS Bottlerocket Benchmark control, that gauges the compliance of the Bottlerocket container hosting operating system is now supported. Coverage for controls 1.3.1, 1.4.3, and 1.4.4 are included.

GCP Cloud Function Gen 2 support via Cloud Run Admin API

Secure the Runtime

Serverless scanning now discovers and protects Gen 2 Cloud Functions created through the Cloud Run Admin API, ensuring full coverage of your GCP serverless workloads.

Nftables support for Cloud Native Network Firewall

Secure the Runtime

Defenders now support Nftables for Cloud Native Network Firewall (CNNF), enabling network protection on modern Linux systems that use NFTables instead of iptables.

Faster CVE loading in vulnerability evaluator

Secure the Runtime

Optimized CVE data loading for improved performance when analyzing vulnerabilities.

Agentless scanning stability enhancements

Secure the Runtime

Multiple improvements to agentless scanning reliability, reducing scan failures and improving consistency across cloud environments.

Changes in Existing Behavior

Feature

Description

Azure Storage Accounts Read Scope Lock

Updates to Prisma Cloud include a fix to address the handling of Azure Storage accounts restricted by a read scope lock. Prisma now classifies read scope locks as an Authorization limitation. Resources affected by a read scope lock can no longer be ingested. Any previously ingested resources that later become scope locked will automatically be marked as deleted.

API Ingestions

Service

API Details

AWS Service Catalog

aws-servicecatalog-provisioned-product

Additional permission required:

  • servicecatalog:SearchProvisionedProducts

The Security audit role does not include the permission. A custom role is required.

Amazon Pinpoint

aws-pinpoint-apns-sandbox-channel

Additional permissions required:

  • mobiletargeting:GetApnsSandboxChannel

  • mobiletargeting:GetApps

The Security audit role does not include the permissions.

Amazon Pinpoint

aws-pinpoint-gcm-channel

Additional permissions required:

  • mobiletargeting:GetGcmChannel

  • mobiletargeting:GetApps

The Security audit role does not include the permissions.

Amazon SageMaker

aws-sagemaker-flow-definition

Additional permissions required:

  • sagemaker:ListFlowDefinitions

  • sagemaker:DescribeFlowDefinition

  • sagemaker:ListTags

The Security audit role includes the permissions.

Amazon Pinpoint

aws-pinpoint-app

Additional permission required:

  • mobiletargeting:GetApps

The Security audit role does not include the permission.

Amazon Pinpoint

aws-pinpoint-apns-channel

Additional permissions required:

  • mobiletargeting:GetApnsChannel

  • mobiletargeting:GetApps

The Security audit role does not include the permissions.

Amazon DocumentDB

aws-docdb-db-cluster-snapshot

Additional permissions required:

  • rds:DescribeDBClusterSnapshots

  • rds:ListTagsForResource

The Security audit role includes the permissions.

AWS X-Ray

aws-xray-sampling-rule

Additional permission required:

  • xray:GetSamplingRules

The Security audit role includes the permission.

AWS X-Ray

aws-xray-group

Additional permission required:

  • xray:GetGroups

The Security audit role includes the permission.

Amazon Redshift

aws-redshift-endpoint-access

Additional permission required:

  • redshift:DescribeEndpointAccess

The Security audit role includes the permission.

AWS CodeDeploy

aws-code-deploy-application-deployment-group

Additional permissions required:

  • codedeploy:ListApplications

  • codedeploy:ListDeploymentGroups

  • codedeploy:GetDeploymentGroup

  • codedeploy:ListTagsForResource

The Security audit role includes the permissions.

Amazon DocumentDB

aws-docdb-subnet-group

Additional permissions required:

  • rds:DescribeDBSubnetGroups

  • rds:ListTagsForResource

The Security audit role includes the permissions.

Amazon GuardDuty

aws-guardduty-publishing-destination

Additional permissions required:

  • guardduty:ListDetectors

  • guardduty:ListPublishingDestinations

  • guardduty:DescribePublishingDestination

The Security audit role includes the permissions.

Amazon DocumentDB

aws-docdb-db-global-cluster

Additional permissions required:

  • rds:DescribeGlobalClusters

  • rds:ListTagsForResource

The Security audit role includes the permissions.

Amazon RDS Update

aws-rds-db-subnet-group

Existing API is updated, JSON values SupportedNetworkTypes and tags.TagList.Tag are converted from object to array.

No additional permission is required.

AWS X-Ray Update

aws-xray-encryption-config

Updated the existing API to include regionId key:value to the ingested resource.

No additional permission is required.

AWS Service Catalog Update

aws-servicecatalog-portfolios

The API now ingests the following additional attributes:

  • TagOptions

  • Tags

The servicecatalog:DescribePortfolio permission is required for this attribute to be ingested.

Amazon Glue Update

aws-glue-dev-endpoint

Updated the existing API to include regionId key:value to the ingested resource.

No additional permission is required.

Amazon VPC Update

aws-vpc-nat-gateway

Updated the existing API to include regionId key:value to the ingested resource.

No additional permission is required.

Amazon VPC Update

aws-ec2-describe-network-acls

Updated the existing API to include regionId key:value to the ingested resource.

No additional permission is required.

Amazon VPC Network Access Control Lists Update

aws-ec2-describe-internet-gateways

Updated the existing API to include regionId key:value to the ingested resource.

No additional permission is required.

Amazon EC2 DescribeFlowLogs Update

aws-ec2-describe-flow-logs

Updated the existing API to include regionId key:value to the ingested resource.

No additional permission is required.

Amazon Glue Job Update

aws-glue-job

Updated the existing API to include regionId key:value to the ingested resource.

No additional permission is required.

Google Dataform

gcloud-dataform-repository-workspace

Additional permissions needed:

  • dataform.repositories.list

  • dataform.workspaces.getIamPolicy

  • dataform.workspaces.list

The Viewer role includes the permissions.

Google Dataform

gcloud-dataform-repository

Additional permissions needed:

  • dataform.repositories.list

  • dataform.repositories.getIamPolicy

  • dataform.compilationResults.list

  • dataform.releaseConfigs.list

  • dataform.workflowInvocations.list

The Viewer role includes the permissions.

Google Dataform

gcloud-dataform-configuration

Additional permissions needed:

  • dataform.locations.list

  • dataform.config.get

The Viewer role includes the permissions.

Google NetApp

gcloud-conversational-insights-analysis-rule

Additional permission needed:

  • contactcenterinsights.analysisRules.list

The Viewer role includes the permission.

Google NetApp

gcloud-netapp-active-directory

Additional permission needed:

  • netapp.activeDirectories.list

The Viewer role includes the permission.

Google NetApp

gcloud-netapp-backup

Additional permissions needed:

  • netapp.backups.list

  • netapp.backupVaults.list

The Viewer role includes the permissions.

Google NetApp

gcloud-netapp-backup-vault

Additional permission needed:

  • netapp.backupVaults.list

The Viewer role includes the permission.

Google NetApp

gcloud-netapp-kms-config

Additional permission needed:

  • netapp.kmsConfigs.list

The Viewer role includes the permission.

Google NetApp

gcloud-netapp-storage-pool

Additional permission needed:

  • netapp.storagePools.list

The Viewer role includes the permission.

Google NetApp

gcloud-netapp-volume

Additional permission needed:

  • netapp.volumes.list

The Viewer role includes the permission.

Google Dataplex

gcloud-dataplex-glossary

Additional permissions needed:

  • dataplex.glossaries.list

  • dataplex.glossaries.getIamPolicy

The Viewer role includes the permissions.

Policy Updates

Policy Updates

Description

Policy Updates—RQL

Azure Storage account diagnostic setting for blob is disabled

Changes– The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Low

Impact– Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.

Azure Storage account diagnostic setting for file is disabled

Changes– The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Low

Impact– Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.

Azure Storage account diagnostic setting for table is disabled

Changes– The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Low

Impact– Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.

Azure Storage account diagnostic setting for queue is disabled

Changes– The policy RQL is updated to exclude irrelevant resources, helping reduce false positives.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Low

Impact– Low. Open alerts will be resolved for storage accounts where diagnostic settings are not applicable.

AWS Application Load Balancer (ALB) is not using the latest predefined security policy

Changes– The policy RQL is updated with the latest recommended security policy.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Low

Impact– Low. Open alerts where the latest policy is configured will be resolved. A new alert will be triggered where the load balancer is not configured with the latest security policy.

AWS Network Load Balancer (NLB) is not using the latest predefined security policy

Changes– The policy RQL is updated with the latest recommended security policy.

Current RQL–

Proposed RQL–

Policy Type– Config

Policy Severity– Low

Impact– Low. Open alerts where the latest policy is configured will be resolved. A new alert will be triggered where the load balancer is not configured with the latest security policy.

Policy Updates—Metadata

Azure VM disk configured with overly permissive network access

Updated Description– Policy description is updated to convey the "defense-in-depth" perspective.

Azure Virtual Machine disks configured with public network access pose a secondary security risk in the event of a host-level breach. While disk access is restricted by identity, enabling a public network access creates a reachable path that can be exploited if the attached Virtual Machine is also compromised.

Azure Virtual Machine disks are storage resources attached to Virtual Machines. When disk public network access is enabled, it provides an internet-routable access for the disk data. If an attacker successfully compromises the attached VM or its associated credentials, this public configuration allows them to bypass internal network perimeters and exfiltrate or manipulate disk data directly from the internet.

The impact of this configuration includes simplified data exfiltration and unauthorized modification following a system compromise. By restricting access to private or trusted networks, you ensure that even if a VM is breached, the data remains shielded from the public internet. This best practice enforces a layered 'defense-in-depth' strategy.

To mitigate this risk, disable public network access for all Azure Virtual Machine disks. Utilize Azure Private Link or restricted Disk Access settings to ensure that storage traffic remains within the private network. Regularly review and audit network configurations to identify and remediate any disks that remain exposed to public routing.

Policy Deletions

Policy Updates

Description

Azure Policy Deletions

Changes– The following Azure policies will be removed from Prisma Cloud because the database services Azure Database for MySQL - Single Server, Azure Database for PostgreSQL - Single Server, and Azure Database for MariaDB have been retired by the cloud service provider (CSP).

List of deleted policies:

  1. Azure Database for MySQL server not configured with private endpoint

  2. Azure MySQL Database Server using insecure TLS version

  3. Azure MySQL Database Server SSL connection is disabled

  4. Azure PostgreSQL database server with log duration parameter disabled

  5. Azure PostgreSQL database server with SSL connection disabled

  6. Azure PostgreSQL database server with log checkpoints parameter disabled

  7. Azure PostgreSQL Database Server 'Allow access to Azure services' enabled

  8. Azure PostgreSQL database server with connection throttling parameter is disabled

  9. Azure PostgreSQL servers not configured with private endpoint

  10. Azure PostgreSQL database server log retention days is less than or equals to 3 days

  11. Azure PostgreSQL database server Infrastructure double encryption is disabled

  12. Azure PostgreSQL database server deny public network access setting is not set

  13. Azure PostgreSQL Database Server Firewall rule allow access to all IPV4 address

  14. Azure PostgreSQL database server with log disconnections parameter disabled

  15. Azure PostgreSQL database server with log connections parameter disabled

  16. Azure MariaDB database server not using latest TLS version

  17. Azure Database for MariaDB not configured with private endpoint

  18. Azure MariaDB database server with SSL connection disabled

Impact– Existing alerts will be resolved as Policy_Deleted.

Last updated

Was this helpful?