<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exception for IAM policy in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/exception-for-iam-policy/m-p/557975#M1040</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a dev/PoC project that is testing some flows that create and delete VMs, so every week for a couple of hours we had some alerts for an IAM Policy "&lt;SPAN&gt;VM instance with data destruction permissions" when it is a permanente VM we ask to follow the recommendations.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How would I be able to except the specific project from this policy or I need to make a custom one?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Sep 2023 16:35:33 GMT</pubDate>
    <dc:creator>CLimachi1</dc:creator>
    <dc:date>2023-09-14T16:35:33Z</dc:date>
    <item>
      <title>Exception for IAM policy</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/exception-for-iam-policy/m-p/557975#M1040</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a dev/PoC project that is testing some flows that create and delete VMs, so every week for a couple of hours we had some alerts for an IAM Policy "&lt;SPAN&gt;VM instance with data destruction permissions" when it is a permanente VM we ask to follow the recommendations.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How would I be able to except the specific project from this policy or I need to make a custom one?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 16:35:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/exception-for-iam-policy/m-p/557975#M1040</guid>
      <dc:creator>CLimachi1</dc:creator>
      <dc:date>2023-09-14T16:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for IAM policy</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/exception-for-iam-policy/m-p/558042#M1042</link>
      <description>&lt;P&gt;Hello Climachi1,&lt;BR /&gt;&lt;BR /&gt;One way you could make an exception for that project from the policy would be by putting that policy in it's own standalone Alert Rule with only that policy selected, and excluding that specific project from the Alert Rule. Even if you were able to edit the policies RQL to ignore that project(which I don't think you can) the policy engine would ignore that input as Prisma Cloud is designed to ignore specific accounts/projects via Alert Rule configuration. If you do take that route , be mindful of removing that policy from any other Alert Rules or you will continue to get alerted for that project.&lt;BR /&gt;&lt;BR /&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 00:50:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/exception-for-iam-policy/m-p/558042#M1042</guid>
      <dc:creator>JScheel1</dc:creator>
      <dc:date>2023-09-15T00:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Exception for IAM policy</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/exception-for-iam-policy/m-p/558129#M1043</link>
      <description>&lt;P&gt;To add to what JScheel1 said:&lt;/P&gt;
&lt;P&gt;It seems you are using overly permissive IAM policy to spin up VMs, even if they are temporary. Please consider the possibility of someone breaking into your temporary VM and from there deleting all data / storage your policy has access to.&lt;/P&gt;
&lt;P&gt;With that said, you can adjust your reporting to only look / enforce your production account&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-rql-reference/rql-reference/iam-query/iam-query-attributes" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-rql-reference/rql-reference/iam-query/iam-query-attributes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 13:24:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/exception-for-iam-policy/m-p/558129#M1043</guid>
      <dc:creator>JNeytchev</dc:creator>
      <dc:date>2023-09-15T13:24:41Z</dc:date>
    </item>
  </channel>
</rss>

