> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2026/features-introduced-in-june-2026.md).

# Features Introduced in June 2026

Learn what’s new in the Prisma® Cloud June 2026 release.

* [API Ingestions](#api-ingestions)
* [Policy Updates](#policy-updates)

## API Ingestions

| **Service**                                  | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| -------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Amazon Bedrock AgentCore**                 | <p><code>aws-bedrock-agentcore-agent-runtime-endpoint</code></p><p>Additional permissions required:</p><ul><li><code>bedrock-agentcore:ListAgentRuntimes</code></li><li><code>bedrock-agentcore:ListAgentRuntimeEndpoints</code></li><li><code>bedrock-agentcore:GetAgentRuntimeEndpoint</code></li><li><code>bedrock-agentcore:ListTagsForResource</code></li></ul><p>You must add these permissions to a custom role. These permissions are not included in the Security Audit policy.</p> |
| **Amazon Bedrock AgentCore**                 | <p><code>aws-bedrock-agentcore-memory</code></p><p>Additional permissions required:</p><ul><li><code>bedrock-agentcore:ListMemories</code></li><li><code>bedrock-agentcore:GetMemory</code></li><li><code>bedrock-agentcore:ListTagsForResource</code></li></ul><p>You must add these permissions to a custom role. These permissions are not included in the Security Audit policy.</p>                                                                                                     |
| **Amazon Bedrock AgentCore**                 | <p><code>aws-bedrock-agentcore-policy</code></p><p>Additional permissions required:</p><ul><li><code>bedrock-agentcore:ListPolicyEngines</code></li><li><code>bedrock-agentcore:ListPolicies</code></li><li><code>bedrock-agentcore:GetPolicy</code></li></ul><p>You must add these permissions to a custom role. These permissions are not included in the Security Audit policy.</p>                                                                                                       |
| **Amazon Bedrock AgentCore**                 | <p><code>aws-bedrock-agentcore-gateway</code></p><p>Additional permissions required:</p><ul><li><code>bedrock-agentcore:ListGateways</code></li><li><code>bedrock-agentcore:GetGateway</code></li><li><code>bedrock-agentcore:ListTagsForResource</code></li></ul><p>You must add these permissions to a custom role. These permissions are not included in the Security Audit policy.</p>                                                                                                   |
| **Amazon Bedrock AgentCore**                 | <p><code>aws-bedrock-agentcore-agent-runtime</code></p><p>Additional permissions required:</p><ul><li><code>bedrock-agentcore:ListAgentRuntimes</code></li><li><code>bedrock-agentcore:GetAgentRuntime</code></li><li><code>bedrock-agentcore:ListTagsForResource</code></li></ul><p>You must add these permissions to a custom role. These permissions are not included in the Security Audit policy.</p>                                                                                   |
| **Amazon Athena**                            | <p><code>aws-athena-prepared-statement</code></p><p>Additional permissions required:</p><ul><li><code>athena:ListWorkGroups</code></li><li><code>athena:ListPreparedStatements</code></li><li><code>athena:GetPreparedStatement</code></li></ul><p>You must add these permissions to a custom role. These permissions are not included in the Security Audit policy.</p>                                                                                                                     |
| **Amazon ECR (Elastic Container Registry)**  | <p><code>aws-ecr-repository-creation-template</code></p><p>Additional permissions required:</p><ul><li><code>ecr:DescribeRepositoryCreationTemplates</code></li></ul><p>You must add this permission to a custom role. This permission is not included in the Security Audit policy.</p>                                                                                                                                                                                                     |
| **Amazon Elasticsearch Service**             | <p><code>aws-opensearch-vpc-endpoint</code></p><p>Additional permissions required:</p><ul><li><code>es:ListVpcEndpoints</code></li><li><code>es:DescribeVpcEndpoints</code></li></ul><p>You must add these permissions to a custom role. These permissions are not included in the Security Audit policy.</p>                                                                                                                                                                                |
| **Google Cloud Network Connectivity Center** | <p><code>gcloud-network-connectivity-policy-based-route</code></p><p>Additional permissions required:</p><ul><li><code>networkconnectivity.policyBasedRoutes.list</code></li></ul><p>The Viewer role includes this permission.</p>                                                                                                                                                                                                                                                           |
| **Google Backup For GKE**                    | <p><code>gcloud-gke-backup-backup-channel</code></p><p>Additional permissions required:</p><ul><li><code>gkebackup.backupChannels.list</code></li></ul><p>The Viewer role includes this permission.</p>                                                                                                                                                                                                                                                                                      |
| **Google Backup For GKE**                    | <p><code>gcloud-gke-backup-restore-channel</code></p><p>Additional permissions required:</p><ul><li><code>gkebackup.restoreChannels.list</code></li></ul><p>The Viewer role includes this permission.</p>                                                                                                                                                                                                                                                                                    |
| **Google Managed Kafka Clusters ACL**        | <p><code>gcloud-managed-kafka-clusters-acl</code></p><p>Additional permissions required:</p><ul><li><code>managedkafka.acls.list</code></li><li>\`managedkafka.clusters.list</li></ul><p>The Viewer role includes this permission.</p>                                                                                                                                                                                                                                                       |
| **Google Managed Kafka Connect Cluster**     | <p><code>gcloud-gcp-managed-kafka-connect-cluster</code></p><p>Additional permissions required:</p><ul><li><code>managedkafka.connectClusters.list</code></li></ul><p>The Viewer role includes this permission.</p>                                                                                                                                                                                                                                                                          |
| **Google Vertex AI AIPlatform**              | <p><code>gcloud-vertex-ai-aiplatform-reasoning-engine</code></p><p>Additional permissions required:</p><ul><li><code>aiplatform.reasoningEngines.list</code></li></ul><p>The Viewer role includes this permission.</p>                                                                                                                                                                                                                                                                       |

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Name</strong></td><td><strong>Details</strong></td></tr><tr><td><strong>Azure Cosmos DB allows traffic from public Azure datacenters</strong></td><td><p><strong>Changes:</strong> RQL update to fix false negatives when <code>0.0.0.0</code> appears in the middle of the <code>ipRangeFilter</code> list.</p><p><strong>Current RQL:</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-cosmos-db' AND json.rule = properties.provisioningState equals Succeeded and properties.ipRangeFilter is not empty and properties.ipRangeFilter startsWith 0.0.0.0 or properties.ipRangeFilter endsWith 0.0.0.0
</code></pre><p><strong>Updated RQL:</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-cosmos-db' AND json.rule = properties.provisioningState equals Succeeded and properties.ipRangeFilter is not empty and (properties.ipRangeFilter equals "0.0.0.0" or properties.ipRangeFilter startsWith "0.0.0.0," or properties.ipRangeFilter endsWith ",0.0.0.0" or properties.ipRangeFilter contains ",0.0.0.0,")
</code></pre><p><strong>Updated Recommendation</strong>: 1. Log in to the Azure Portal. 2. Navigate to the Azure Cosmos DB service. 3. Select the reported Azure Cosmos DB account. 4. Click on <strong>Networking</strong> under <strong>Settings</strong>. 5. Under <strong>Firewall</strong> section in <strong>IPs (Single IPv4 or CIDR range)</strong> list, delete the entry exist for '0.0.0.0'. 6. Click <strong>Save</strong>.</p><p><strong>Impact:</strong> Low-Medium. New alert may be generated for missed alerts where 0.0.0.0 is positioned in the middle of the comma-separated ipRangeFilter list.</p></td></tr><tr><td><strong>AWS API gateway request authorisation is not set</strong></td><td><p><strong>Changes:</strong> RQL update to exclude <code>OPTIONS</code> HTTP methods from authorization checks. OPTIONS requests are standard for CORS preflights and typically do not require authorization.</p><p><strong>Current RQL:</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-apigateway-method' AND json.rule = authorizationType contains NONE
</code></pre><p><strong>Updated RQL:</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-apigateway-method' AND json.rule = authorizationType contains NONE AND httpMethod does not equal "OPTIONS"
</code></pre><p><strong>Impact:</strong> Low. This update resolves the already-generated alert with the aws-apigateway-method configured with the OPTIONS method.</p></td></tr><tr><td><strong>AWS EBS volume region with encryption is disabled</strong></td><td><p><strong>Changes:</strong> Recommendation update to fix outdated AWS documentation link.</p><p><strong>Updated Recommendation:</strong> The remediation link now points to the current <a href="https://docs.aws.amazon.com/ebs/latest/userguide/encryption-by-default.html">AWS documentation</a>.</p><p><strong>Impact:</strong> Users can now access valid remediation instructions directly from the policy recommendation.</p></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2026/features-introduced-in-june-2026.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
