Skip to content
Notifications
Clear all

Deployed Prisma Cloud across 200 AWS accounts - lessons learned

1 Posts
1 Users
0 Reactions
39 Views
(@davidr)
Honorable Member
Joined: 3 months ago
Posts: 373
Topic starter   [#3847]

After managing a multi-account Prisma Cloud deployment for the last 18 months, I can state definitively that the platform's power is matched only by the complexity of operating it correctly at scale. We rolled it out across 200 AWS accounts, a mix of production, staging, and development, and the operational lessons were expensive. The marketing promises "unified visibility," but the reality is a constant battle with configuration drift, API limits, and cost overruns.

The primary architectural hurdle is the Prisma Cloud Tenant structure. You have one Compute Console and one Cloud Security Posture Management (CSPM) console per tenant, but linking 200 accounts efficiently is not a point-and-click exercise. We automated onboarding with Terraform, which is non-negotiable at this scale. The critical mistake we made initially was using a single set of credentials for all AWS account integrations. This creates a massive single point of failure and a security nightmare for credential rotation.

Here is the Terraform structure we eventually settled on for AWS account onboarding, using AWS Organizations and a dedicated role per account:

```hcl
# prisma_cloud_aws_account.tf - Module per account
module "prisma_integration_account_123456789012" {
source = "./modules/prisma-aws-integration"

prisma_cloud_customer_name = var.customer_name
prisma_cloud_tenant_id = var.tenant_id
aws_account_id = "123456789012"
aws_account_name = "prod-app-core"
deployment_type = "aws_organization" # Uses AWS Org API for auto-add
}
```

The key lessons from the deployment and ongoing management:

* **Costs are non-linear and opaque.** CSPM costs are based on "resource units." A single AWS CloudTrail trail, replicated to every region, counts as multiple resources. Our bill ballooned by 40% in the second month until we built a custom dashboard to map Prisma's "unit" counts back to actual AWS resources. You must actively exclude development and transient resources via policies.
* **Real-time alert fatigue is immediate.** Out-of-the-box compliance alerting will generate thousands of violations daily. We had to spend two months refining and customizing policies before turning on enterprise-wide alerts. The default CIS benchmarks are a good start but are far too noisy for a mature environment.
* **API rate limits will break your automation.** The Prisma Cloud API has aggressive rate limiting. Any automation that polls for compliance data or resource inventories across 200 accounts must be built with exponential backoff and caching. We hit limits daily until we implemented a Redis cache for resource listings.
* **Agent-based Compute Security is a deployment marathon.** Deploying the Defender agents across diverse ECS, EKS, and ECSS environments requires a dedicated pipeline. Helm chart version drift across clusters will cause silent failures. Our monitoring found that 15% of agents were in a degraded state at any given time, requiring a dedicated runbook for triage.

The platform is powerful, particularly for compliance reporting and the breadth of its CSPM checks. However, treat it as a platform to build upon, not a turnkey solution. Your ROI is directly tied to the internal engineering effort dedicated to managing its complexity, customizing its policies, and continuously auditing its own health. Without a dedicated team of at least two engineers to curate policies, manage integrations, and monitor costs, the value rapidly dissipates into noise and expense.

—davidr


—davidr


   
Quote