New Features in December 2025
Focus
Focus
Device Security

New Features in December 2025

Table of Contents

New Features in December 2025

Review the new features introduced in Device Security in December 2025.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription for an advanced Device Security product (Enterprise, OT, or Medical)
  • Device Security X subscription
The following new features and enhancements were introduced for Device Security in December 2025.
New Features
Vulnerability signatures
The Device Security Research team added detections for 645 vulnerabilities this month. Of the 645 vulnerabilities, 80 of them had a critical CVSS score. You can see a complete list of the CVEs for which detections have been added at Vulnerability Signatures in 2025.
Dictionary file updates
There were three dictionary file updates in December 2025. The following summarizes what was added in each update:
  • December 03 update – 8 new profiles and 46 new models
  • December 10 update – 13 new profiles, 1 new OS family, and 22 new models
  • December 18 update – 13 new profiles, 1 new OS family, and 104 new models

Device Security Landing Dashboard

Device Security's new landing dashboard in Strata Cloud Manager presents a centralized, real-time view of your device landscape and critical risk factor insights, enabling proactive risk management and rapid incident response. The landing dashboard unifies discovery, security posture, risk analysis, and remediation workflows, so you can get a high-level overview of all devices in your network, see where risks from vulnerabilities and threats appear, and quickly take action on insights and recommended policies.

Queries for Time-Based Attributes from Third-Parties

You can now query time-based attributes from third-party integrations. Time-based attribute querying makes it easier to identify and manage devices based on their temporal activity in your network. You can query using predefined time values (e.g. 1 month) or custom values, which can be explicit date ranges (e.g. January 5, 2026) or relative time operators (e.g. last 10 days). Querying on time-based attributes uses the existing process for Query Creation and Management.

NetBox IPAM and DCIM Integration

Device Security supports integrating with NetBox functionalities for IP Address Management (IPAM) and Data Center Infrastructure Management (DCIM). By integrating with NetBox, Device Security can learn about endpoints and IP address use, including static IP addresses and DHCP leases. Device Security uses that information to enrich the Device Security asset inventory, including creating new assets for devices learned through the NetBox integration.

Enhancements for the Cisco Meraki Integration

December 2025 enhancement Device Security can now learn network details when integrating with Cisco Meraki. The network details include information about subnets, VLANs, static IP addresses, and DHCP leases. Device Security and Cortex XSOARuse a new playbook, Import Cisco Meraki Networks to Device Security, to get the network information. The Cisco Meraki integration instance in Cortex XSOAR also includes a new field, Networks, to specify which networks to learn network information for. To pull the network information from your Cisco Meraki solution to Device Security, update your Cisco Meraki integration instance and configure a new Cortex XSOAR job with the new playbook.
Device Security integrates with Cisco Meraki Cloud through Cortex XSOAR to enrich your asset inventory with detailed data about devices accessing your network through Cisco switches and wireless access points. This integration enables you to import device attributes, such as MAC and IP addresses, VLANs, and OS details, directly into Device Security. For wired clients, you gain visibility into the connecting switch, while wireless client data includes the associated access point. Use this feature to correlate network-layer data with traffic logs from next-generation firewalls. This integratio helps you maintain visibility of both online and recently offline devices, so you can base your security policy decisions on the most current context available.

Enhancement for the Infoblox IPAM Integration

December 2025 enhancement Device Security can now learn about static IP addresses and DHCP leases when integrating with Infoblox IPAM.
Integrate Device Security with Infoblox IPAM to retrieve IP blocks and subnets (called containers and networks by Infoblox) plus related data about sites, VLANs, and descriptions. For more information, see Integrate Device Security with Infoblox IPAM.

Enhancements for the Microsoft DHCP Servers Integration

December 2025 enhancement Device Security can now learn about static IP addresses and DHCP leases when integrating with Microsoft DHCP Servers.
Device Security supports integrating with Microsoft DHCP Servers to learn about DHCP clients from the servers. Device Security can retrieve information such as multi-interface configurations, installed software, DHCP reserved IP addresses, and BitLocker status, and Device Security uses that information to enrich its inventories.

FedRAMP High Authorization

December 2025 enhancement Prisma Access attached Device Security is now authorized for FedRAMP High.
June 2024 enhancement Device Security now uses the PAN-OS Edge Services to support policy recommendations and Device-ID based automated Zero Trust Enforcement for all next-generation firewalls and Prisma Access. The Device Security solution deployed in a FedRAMP moderate environment works with next-generation firewalls in either FIPS mode or in a commercial environment.
Device Security is authorized for use in a FedRAMP environment. To learn more about FedRAMP authorization at Palo Alto Networks, see Palo Alto Networks and FedRAMP Authorization.