STIGQter STIGQter: STIG Summary: Palo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Apr 2026:

All Prisma Cloud Compute users must have a unique, individual account.

DISA Rule

SV-253535r1051115_rule

Vulnerability Number

V-253535

Group Title

SRG-APP-000148-CTR-000335

Rule Version

CNTR-PC-000510

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> Users tab.

Ensure only the break glass administrator account is a "local" account.

Delete all other local accounts and use the SAML identity provider for all authentication and authorization to the Prisma Cloud Compute Console.

Check Contents

Confirm there is only one "break glass" local administrative account.

Navigate to Prisma Cloud Compute Console's Manage >> Authentication >> Users tab.

Only the administrative break glass account is allowed to have Authentication Method = Local.

For all other accounts, Authentication Method = SAML.

If any local account, except the administrative break glass account, has Authentication Method set to other than "SAML", this is a finding.

Vulnerability Number

V-253535

Documentable

False

Rule Version

CNTR-PC-000510

Severity Override Guidance

Confirm there is only one "break glass" local administrative account.

Navigate to Prisma Cloud Compute Console's Manage >> Authentication >> Users tab.

Only the administrative break glass account is allowed to have Authentication Method = Local.

For all other accounts, Authentication Method = SAML.

If any local account, except the administrative break glass account, has Authentication Method set to other than "SAML", this is a finding.

Check Content Reference

M

Target Key

5473