Focus

New Features - Device Security - July 2026


Application Metadata Collection for Device Security

Release Date: July 2026 | Last Updated: July 2026

You can now apply a metadata profile to each zone on your NGFW to filter the log fields forwarded to Device Security . When you specify a metadata profile, PAN-OS only forwards log data based on the cloud services enabled on your NGFW . This helps bandwidth-constrained sites, such as remote facilities or OT environments, as they only forward log data required by the cloud services instead of excess logs.

Metadata profiles map log fields to the cloud services that need them. You assign a profile to a zone with a single setting, which replaces the multi-step Log Forwarding Profile configuration previously attached to each firewall policy.

This gives you a simpler way to send the right metadata to Device Security and reduces the volume of data your firewalls push to the cloud at sites where bandwidth is limited. Existing log forwarding configurations continue to work after upgrade, so you can adopt metadata profiles on a zone-by-zone basis.

Custom Reports Usability Enhancements for Device Security

Release Date: July 2026 | Last Updated: August 2026

Report templates, built from dashboards, let you build and manage custom reports in Device Security through a single guided workflow. With report templates, you can generate reports on demand or on a schedule, and manage your report templates and run histories without switching between the dashboard and reports page.

From the Report History page, you see the real-time status of each report as it moves from in progress to complete, so you know when it's ready to download. If a report fails, you can retry it directly from the same view, and report names now include the template they were generated from so you can identify them at a glance.

You can edit or overwrite an existing template and preserves its scheduled reports and subscribers, so you can refine templates without accumulating near-duplicate entries. You can also delete individual reports or remove multiple reports at once from Report History to keep the list focused as your reporting practice grows.

Data Source Prioritization for Device Security Device Attributes

Release Date: July 2026 | Last Updated: August 2026

When your Device Security asset inventory draws attribute data from multiple sources, such as EDR agents, MDM systems, and network traffic, Device Security uses source-based prioritization to make sure the OS version, model, serial number, hostname, and network attributes for a device come from the most trustworthy source, instead of whichever source reported the value most recently. Values you enter manually always take priority over any network traffic or integration source.

With more reliable data on display, your CVE matching, security policies, and reporting become more accurate for the assets your team owns. The device details page continues to show all values from every source that reported the attribute, so you can still see and query on data from any specific integration when you need to.

Device Profiling Without MAC Address Visibility for Device Security

Release Date: July 2026 | Last Updated: August 2026

Device Security can now profile and classify OT devices even when a MAC address is not visible, so devices that sit behind routers or firewalls in restricted networks no longer appear as bare IP addresses in your inventory.

For static-IP devices, Device Security evaluates a curated set of profiling rules that identify the device vendor from protocol-level signals and application-layer identifiers. When multiple rules match, Device Security uses the highest-confidence match. Classification for devices with a visible MAC address continues to work as it does today.

Device Security Integration with BMC Helix

Release Date: July 2026 | Last Updated: August 2026

You can now integrate Device Security with BMC Helix ITSM to import asset and configuration records from your CMDB into your assets inventory, so Device Security reflects the same identity and ownership context that your IT service management team already tracks.

When you connect the integration, Device Security pulls device attributes such as MAC address, IP address, operating system, owner, site, serial number, and asset status from your BMC Helix CMDB and applies them to matching devices. You can schedule a recurring sync, so that your Device Security records stay aligned with your BMC Helix inventory as it changes.

Aligning your Device Security inventory with BMC Helix ITSM closes the gap between the assets your security team monitors and the records your IT operations team owns. With shared identity and ownership context, you can triage incidents against accurate asset data, hold clear accountability for each device, and stop reconciling two source-of-truth systems by hand.

Device Security Integration with Omnissa Workspace ONE UEM

Release Date: July 2026 | Last Updated: August 2026

You can integrate Device Security with Omnissa Workspace ONE UEM to import managed device details from your UEM console into your Device Security inventory, so you can see attributes that network traffic alone cannot reveal and identify managed devices.

When you integrate with Workspace ONE, Device Security ingests device attributes such as hostname, model, OS, serial number, compliance status, enrollment status, and last-seen timestamps. You can also import the list of installed applications for each managed device.

Bringing Workspace ONE data into Device Security gives your security team a more complete view of every managed endpoint. With richer device context, you can improve risk scoring, tighten policy decisions, and act on an accurate inventory without cross-referencing two consoles by hand.

Inbound Policy Rule Recommendations for Device Security

Release Date: July 2026 | Last Updated: July 2026

( September 2025 ) Introduced in PAN-OS 11.1.11.

Device Security enables you to secure your connected device environments with both inbound and outbound policy recommendations. While PAN-OS and Panorama initially supported only outbound policy recommendations, the addition of inbound policy recommendations lets you create a more comprehensive security posture for your IT and IoT devices. Creating policy rule recommendations based on both outbound and inbound profile behaviors helps prevent vulnerability exploitation, lateral movement, and other security risks that outbound policies alone cannot address.

You can now view both inbound and outbound behaviors for device profiles in the UI and create security policies accordingly. For outbound behaviors, the source is the IT/IoT device profile, while the destination can be any . For inbound behaviors, you can now set the source as any, and the destination is the IT/IoT device profile. This symmetrical approach lets you control both what your IT/IoT devices can access, as well as what other enterprise sources can access your IT/IoT devices, implementing a true Zero Trust security model.

The policy recommendation workflow supports both per-device and per-profile levels, giving you flexibility in how you implement security policies. When creating policies, you can specify source and destination attributes including device profiles, IP addresses, and FQDNs. The naming convention for policies intelligently selects the appropriate profile name (whether in source or destination) to ensure clarity in your policy set. For policy rule recommendations based on inbound profile behaviors, the name has "-inbound" appended.

By leveraging both inbound and outbound policy recommendations, you can significantly reduce your attack surface by allowing only trusted behaviors for your IT/IoT devices. This is particularly valuable for securing critical infrastructure and sensitive device deployments where you need to control both inbound and outbound traffic.

Infoblox Outbound API Support for Device Security

Release Date: July 2026 | Last Updated: August 2026

You can configure your Device Security integration with Infoblox IPAM to receive IPv4 network change events over the Infoblox Outbound API, so Infoblox updates appear in Device Security in near real time instead of waiting for the next scheduled bulk read. Reducing the lag between a network change and its reflection in Device Security gives your security team accurate network context when they investigate alerts.

When Infoblox creates or modifies an IPv4 network, it sends the change to Device Security through the outbound endpoint you configure. Device Security then updates the affected network attributes, including network ranges and extended attributes such as Site and VLAN, from the incoming event instead of resynchronizing the full inventory. You continue to use bulk reads for the initial synchronization and as a periodic safety net.

Insights Center Enhancements for Device Security

Release Date: July 2026 | Last Updated: August 2026

The Device Security Insights Center now delivers a more focused view of your risk posture through scoped dashboards and recommendation management that surface only the insights and actions relevant to your team. Instead of a global fleet view with generic recommendations, you can filter the view so that you only see the devices your team owns and the actions you still need to take.

You can scope the Insights Center to any subset of your inventory using ad hoc or saved queries, so the charts and topology visualizations reflect the assets you selected. Recommendations also update as you drill down in the visualizations, so the recommendations you see match the assets you're viewing. You can also manage individual recommendations: view, dismiss, or snooze recommendations. Filter the recommendation list by active, dismissed, or snoozed state to keep your working view focused on items you still need to address.

The recommendation engine also accounts for compensating controls now. If you have applied a compensating control, the Insights Center no longer surfaces a recommendation for that risk. Along with the filterable view and recommendation management, the Insights Center now reflects what you choose to see, and the information relevant to that scope.

Integration Recommendations for Device Security

Release Date: July 2026 | Last Updated: August 2026

Device Security now automatically recommends third-party integrations based on the tools it already detects on your network, so you can identify integrations that would enrich your device data without auditing your security stack by hand.

Device Security looks for network signals associated with supported third-party tools, such as App-ID traffic, HTTP user agents, and device fingerprints. When it detects a tool that you haven't yet connected, it surfaces a recommendation on the deployment checklist. Recommendations refresh daily and cover supported integrations.

Multi-vsys Support for Device-ID in Device Security

Release Date: July 2026 | Last Updated: July 2026

When the same IP block is reused across sites or virtual systems, Device Security can misidentify devices, mix device behavior across locations, and deliver incorrect Device-ID verdicts to your firewalls — breaking policy enforcement for every affected segment. Multi-vsys support for device identification and Device-ID solves this by letting you define named network segments in PAN-OS and associate each virtual system with a specific segment, so Device Security tracks and delivers device context separately for each logical partition of your network.

Network segments can be configured in Panorama as shared objects and pushed to firewalls through templates, the same way other Panorama -managed features work. Once a virtual system is assigned to a segment, Device Security receives the vsys-to-segment mapping from PAN-OS and generates a unique segment ID for each network segment. That ID travels with every verdict, so Edge delivers device context only to the firewalls that belong to the corresponding segment. For devices in non-overlapping IP space, Restrict Context Sharing gives you control over whether device context learned in one segment is visible to firewalls in other segments, or kept private to the segment where the device was discovered.

If your organization currently uses the Device Security -managed network segment configuration from an earlier release, you can migrate to PAN-OS device security segments through the Device Security portal. After migration, segment definitions are owned entirely by Panorama, and the portal displays them in read-only mode. Devices already learned through existing segments are preserved in your asset inventory — only the management of segment definitions moves to Panorama. Devices in shared IP blocks always receive scoped verdicts regardless of the context sharing setting, preserving isolation between segments that operate on overlapping address space.

Polling Integration Protocol Support for Device Security

Release Date: July 2026 | Last Updated: August 2026

( July 2026 ) The Device Security polling integration with Cortex XSOAR now supports the following protocols for polling:

  • OPC UA

  • ABB PLC

Additionally, you can now authenticate Axis devices with certificates and retrieve extended device attributes. SNMP polling now provides improved device identification.

( January 2026 ) The Device Security polling integration with Cortex XSOAR now supports the following protocols for polling:

  • GE CARESCAPE Gateway

  • Ping/ICMP Connection Test and ICMP Traffic

  • Hikvision for custom OID

  • Axis Communications for older devices

( October 2025 ) The Device Security polling integration with Cortex XSOAR now supports the following protocols for polling:

  • Beckhoff TwinCAT UDP

  • Codesys TCP

  • Siemens PLC HTTP/HTTPS

( August 2025 ) The Device Security polling integration with Cortex XSOAR now supports the following protocols for polling:

  • HTTP / HTTPS banner extraction

  • GE-SRTP

  • Beckhoff TwinCAT

( April 2025 ) The Device Security polling integration with Cortex XSOAR now supports the following protocols for polling:

  • Axis Communications

  • FTP Banner

Additionally, you can now provide a DNS server when configuring polling with reverse DNS to get device hostnames.

( January 2025 ) The Device Security polling integration with Cortex XSOAR now supports the following protocols for polling:

  • Cognex Discovery

  • EPM

  • Moxa

  • Niagara Fox

Protocol Support and Troubleshooting CLI for the Network Discovery Plugin

Release Date: July 2026 | Last Updated: August 2026

The Network Discovery plugin 2.4.0 and 3.2.0 releases add expanded polling protocol support and on-demand troubleshooting CLI commands to discover a broader range of devices on your network and investigate plugin issues more in-depth before escalating.

SNMPv3 polling now supports the SHA-224, SHA-256, SHA-384, and SHA-512 authentication protocols and the AES-192, AES-256, and 3DES privacy protocols, so you can align polling with stricter cryptographic standards. OT polling adds Beckhoff (UDP), Siemens Webserver, Codesys (TCP), and GE Carescape patient monitors, so you can discover a broader range of industrial and medical devices on your network.

The CLI commands let you selectively enable verbose logging by component, list operational files so they are captured in the Technical Support File (TSF), run a diagnostic playbook against a specific IP address, test SNMP and OT polling queries, and check the health of the asset polling, neighbor discovery, and data refreshment daemons.

Virtual Patching Policy Workflow from Vulnerability Details in Device Security

Release Date: July 2026 | Last Updated: August 2026

You can now create Virtual Patching policies directly from the Vulnerability Details page in Device Security, so your vulnerability management teams can act on a specific CVE without switching to the Profile Behavior page or Insights Center to start a policy workflow. This option is available only for CVEs that are covered by Threat Prevention signatures.