<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GCP Agentless Scanning Setup in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525301#M861</link>
    <description>&lt;P&gt;Hi Umer - Thanks for your reply. I followed the same documentation but during the setup page on Prisma it looks for the service account and API Token but the service account keys are in json format which is where we got stuck.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Dec 2022 03:01:59 GMT</pubDate>
    <dc:creator>SKodi</dc:creator>
    <dc:date>2022-12-28T03:01:59Z</dc:date>
    <item>
      <title>GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525293#M859</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Has anyone tried onboarding GCP account for agentless scanning? During the setup it is asking for GCP Service account and API token details but we can only generate json keys for service accounts. Any idea how to get this setup done?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 00:21:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525293#M859</guid>
      <dc:creator>SKodi</dc:creator>
      <dc:date>2022-12-28T00:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525294#M860</link>
      <description>&lt;P&gt;Hi SKodi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can onboard gcp account for agentless scanning using the following docs:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-06/prisma-cloud-compute-edition-admin/configure/configure-agentless-scanning#_configure_agentless_scanning__individual-account" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-06/prisma-cloud-compute-edition-admin/configure/configure-agentless-scanning#_configure_agentless_scanning__individual-account&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please search for "Onboard GCP Accounts for Agentless Scanning".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create a service account key using the following GCP documentation:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://cloud.google.com/iam/docs/creating-managing-service-account-keys" target="_blank"&gt;https://cloud.google.com/iam/docs/creating-managing-service-account-keys&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helped!&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;</description>
      <pubDate>Wed, 28 Dec 2022 00:35:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525294#M860</guid>
      <dc:creator>USheikh</dc:creator>
      <dc:date>2022-12-28T00:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525301#M861</link>
      <description>&lt;P&gt;Hi Umer - Thanks for your reply. I followed the same documentation but during the setup page on Prisma it looks for the service account and API Token but the service account keys are in json format which is where we got stuck.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 03:01:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525301#M861</guid>
      <dc:creator>SKodi</dc:creator>
      <dc:date>2022-12-28T03:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525308#M862</link>
      <description>&lt;P&gt;Hi SKodi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The content of the service account JSON file will be entered the service account field in Prisma Cloud Compute Console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;API token field should be left empty.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please save the settings, and try to perform the agentless scan.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 03:33:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525308#M862</guid>
      <dc:creator>USheikh</dc:creator>
      <dc:date>2022-12-28T03:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525317#M863</link>
      <description>&lt;P&gt;Thanks again, this time we made some progress. JSON worked and downloaded the permissions template as well. When I tried to initiate the scan it threw the following error:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;failed to create account clients for permissions check. target:"&amp;lt;credential_name&amp;gt;" hub:"" region: us-central1. failed to initialize the target account client for credential &amp;lt;credential_name&amp;gt;: googleapi: Error 403: Required 'compute.zones.list' permission for 'projects/&amp;lt;project_id&amp;gt;', forbidden&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do I need to apply the downloaded template? And how they are used?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 04:07:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525317#M863</guid>
      <dc:creator>SKodi</dc:creator>
      <dc:date>2022-12-28T04:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525318#M864</link>
      <description>&lt;P&gt;Hi SKodi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on the error, it looks like the account does not have sufficient permissions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you verify using the downloaded the permission template if the account has the permission?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To understand more about the downloaded template files and how they are used, refer to&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-06/prisma-cloud-compute-edition-admin/configure/permissions" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-06/prisma-cloud-compute-edition-admin/configure/permissions&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 05:08:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525318#M864</guid>
      <dc:creator>USheikh</dc:creator>
      <dc:date>2022-12-28T05:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525374#M865</link>
      <description>&lt;P&gt;Hi Umer,&lt;/P&gt;
&lt;P&gt;compute.zones.list is mentioned in the included permissions on the downloaded permission template.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 15:33:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525374#M865</guid>
      <dc:creator>SKodi</dc:creator>
      <dc:date>2022-12-28T15:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525391#M866</link>
      <description>&lt;P&gt;Hi SKodi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you are doing well. As the scope of this issue is going beyond the chat messages, can you please open a support ticket and one of the TAC Engineers will be able to assist you?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 19:42:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/525391#M866</guid>
      <dc:creator>musiddiqui</dc:creator>
      <dc:date>2022-12-28T19:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/526547#M874</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Hi SKodi,&lt;/FONT&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;It appears to be&amp;nbsp;related to missing permissions for&amp;nbsp;Google managed service accounts. Can you please check IAM policies for your project &lt;FONT color="#000000"&gt;&lt;SPAN&gt;and verify if the&lt;/SPAN&gt;&amp;nbsp;&lt;/FONT&gt;permissions are listed?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 16:02:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/526547#M874</guid>
      <dc:creator>kfirdaus</dc:creator>
      <dc:date>2023-01-10T16:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/526684#M876</link>
      <description>&lt;P&gt;Hi SKodi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;I hope you are doing well. To answer your question about the template,&amp;nbsp;&lt;SPAN&gt;Prisma Cloud validates the specified credentials and the download raises an error if the credentials are incorrect. To understand more about the downloaded template files and how they are used, refer to the&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-06/prisma-cloud-compute-edition-admin/configure/permissions" target="_self"&gt;permission templates&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please let me know if you have any other questions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 18:45:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/526684#M876</guid>
      <dc:creator>musiddiqui</dc:creator>
      <dc:date>2023-01-11T18:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Agentless Scanning Setup</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/529362#M892</link>
      <description>&lt;P&gt;Hello SKodi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A suggestion would be to create a role in GCP that includes the permissions listed in the attached screenshot. Make sure that the role is created in the GCP Project you are looking to scan. The document titled 'Permissions by feature' has the complete list that the screenshot is based from.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-12/prisma-cloud-compute-edition-admin/configure/permissions" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-12/prisma-cloud-compute-edition-admin/configure/permissions&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scroll down to the GCP section, then look for the Agentless scanning section. Then, associate the role to a service account. Then create a new JSON file for the specific project. Before going back to the console to on-board the account, double check that the contents of the JSON file reference the project you want scanned.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This suggestion is based on the 'Same Account' setting in the onboarding process in the console.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 20:50:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-agentless-scanning-setup/m-p/529362#M892</guid>
      <dc:creator>JJean-Claude</dc:creator>
      <dc:date>2023-01-31T20:50:21Z</dc:date>
    </item>
  </channel>
</rss>

