Is PaloAlto Prisma Cloud trash (compared to Azures features)?
Palo Alto WAAS
Palo Alto Networks - Global Protect Cloud Service (GPCS) - rebranded to Prisma Access
Palo Alto vs Wiz vs Aqua Security
I started a new role at a large enterprise. They use AWS and Azure as well. Today I talked to a team managing a "Prisma Cloud" from PaloAlto and enforcing several "policies" with it for our cloud resources. Those policies get monitored and if some are violated, a ticket and alert is created. Okay. They also have some kind of agent, that can be installed on VMs and could then monitor the OS and trigger on e.g. open ports and stuff. They are also scanning "images", be it VM images or containers, but only at push, not during runtime.
While I was hearing that I was thinking to myself: could that not be achieved with Azure Security center, Microsoft Defender solutions as well as Azure policies?? And with much better quality and integration?!
I did some more research and my understanding by now is that PrismaCloud basically rebuilds some policy rules, maybe adds some new ones and try to push security agents on VMs and processes into containers. For me, that rebuilding means, they will always lack behind Azure features. Also the handling seems to be way more cumbersome. In Azure I can get Defender installed on VMs and get container images scanned at rest and during runtime with no manual steps. With Azure policies I have pre-configured compliance-sets and each and every resource has policies already during public preview.
So, is Prisma Cloud as much snake oil as it sounds or is there a real benefit I cannot achieve with Azure (or even AWS Security Hub in AWS world) much easier and much better integrated?