BlogsCloudflareAccount Access Management & Permissions

Account Access Management & Permissions

Account Access Management & Permissions

235
posts
2013–2026

Cloudflare's account management and access control capabilities have evolved from basic identity-based rules to a comprehensive zero-trust platform, aligning with industry standards like NIST's Zero Trust Architecture (ZTA). This evolution now extends to securing SaaS applications by integrating with their SAML authentication flows, allowing for consistent security controls, consolidated logging, and the enforcement of device posture and Gateway protection. The acquisition of BastionZero further enables a new Agent Access Model (AAM) that shrinks the trust boundary from the application to the individual action, making authorization decisions at machine speed. AAM enforces short-lived, task-scoped, sender-constrained credentials, with enforcement in the harness and network, exceptional human oversight for approvals, grants reviewed from evidence, and capability state moving in one direction via a Trust Ratchet. This model addresses the challenges of ephemeral agents acting at machine speed, composing authority across hops, and the limitations of prompt-based security.

2026

The Agent Access Model

8/5/2026

This post introduces the Agent Access Model (AAM) as a new approach to enterprise security for software principals (agents). It contrasts AAM with the human-centric BeyondCorp model, highlighting the limitations of existing controls for agents due to their ephemeral nature, machine-speed actions, and ability to compose authority across hops. AAM's core principles include short-lived, task-scoped, sender-constrained credentials; enforcement in the harness and network; exceptional human oversight; grants reviewed from evidence; and unidirectional capability state reduction via a Trust Ratchet. A reference architecture is proposed with an Agent Identity Broker (using OAuth 2.0 Token Exchange and DPoP), a Task-Scoped Access Engine (extending BeyondCorp's ACE), and a Mediation Layer (harness and network).

Introducing the Cloudflare One stack- agent-powered deployment

6/17/2026

Introduces the Cloudflare One stack, a set of agent skills designed to automate the configuration, deployment, and management of Zero Trust environments. This includes skills for migrating from legacy vendors like Zscaler and Palo Alto Networks, network diagram interpretation and generation, vendor concept translation, and troubleshooting with the Digital Experience Monitoring (DEX) toolkit. The stack provides a typed interface to the Cloudflare API for agents via the MCP server, enabling them to query, inspect, and modify configurations.

Agents can now create Cloudflare accounts, buy domains, and deploy

4/30/2026

This post introduces a significant new capability for programmatic account creation, domain registration, and paid subscription management for Cloudflare, facilitated by agents and a new protocol co-designed with Stripe. This enables zero-friction deployment of applications by agents on behalf of users, removing the need for manual dashboard interactions, API token copying, or credit card entry for new users. It extends the concept of account access and management to automated agents, integrating with payment and identity providers like Stripe.

Securing non-human identities: automated revocation, OAuth, and scoped permissions

4/14/2026

This post introduces significant advancements in securing non-human identities by addressing three core pillars: principals, credentials, and policies. It introduces scannable API tokens with checksums to facilitate detection and automatic revocation by partners like GitHub, enhancing leaked token protection. For Cloudflare One customers, it extends this protection through Gateway, Email Security, and CASB, with real-time scanning of AI traffic via Cloudflare AI Gateway. The post also overhauls the OAuth consent experience, providing users with clear visibility into third-party application access, requested scopes, and the ability to manage connected applications and revoke access. Finally, it expands resource-scoped RBAC to new resources like Access Applications, Rules, and Workers KV, enabling finer-grained control over permissions for agents and scripts.

Managed OAuth for Access: make internal apps agent-ready in one click

4/14/2026

Introduced managed OAuth for Cloudflare Access, allowing agents to authenticate using OAuth 2.0 and RFC 9728. This enables agents to discover authorization servers, register as clients, and go through a PKCE authorization flow to obtain JWTs for accessing internal applications. This feature aims to make internal apps agent-ready without requiring code modifications.

How we built Organizations to help enterprises manage Cloudflare at scale

4/6/2026

Introduced the 'Organizations' feature, a new hierarchical layer for managing multiple Cloudflare accounts. This includes the 'Org Super Administrator' role, shared configuration policies (e.g., WAF, Gateway), and aggregated analytics dashboards. The underlying authorization system was refactored with significant code changes to support this, improving performance for permission checks on enumeration calls.

From legacy architecture to Cloudflare One

3/13/2026

This post details a methodology for migrating legacy applications to Cloudflare One (SASE) in partnership with CDW. It introduces a phased rollout strategy that prioritizes coexistence over replacement, including application categorization (Tier 0-3) based on migration effort and technical complexity. Key technical contributions include the 'wrapping' of legacy applications using Cloudflare Access and Tunnel to modernize their security posture without code rewrites, enabling outbound-only connections with SSO and MFA, and applying edge policies for enhanced security. The post also outlines pre-migration audit steps focusing on architectural readiness, identity providers, dependency mapping, firebreak establishment, and persistent session stress testing, leveraging Cloudflare's Dynamic Path MTU Discovery (PMTUD) for persistent edge sessions.

Complexity is a choice. SASE migrations shouldn’t take years.

3/9/2026

This post details how Cloudflare One, an agile SASE platform, is enabling partners to significantly reduce SASE migration timelines from 18 months to as little as six weeks. It highlights the technical advantages of Cloudflare One over legacy SASE products, including identity-first on-ramps, consolidated policy engines, and cloud-native connectors like `cloudflared`. The post also showcases the extensibility of the Cloudflare One architecture, demonstrated by a partner extending the client to support Arch Linux. Furthermore, it introduces the Cloudflare AI Security Suite, detailing features for securing workforce AI usage (Shadow AI visibility, AI confidence scores, DLP AI prompt protection) and AI-powered applications (Firewall for AI, LLM discovery, request validation, response scrubbing), as well as securing agentic AI with MCP server portals.

From the endpoint to the prompt: a unified data security vision in Cloudflare One

3/6/2026

This post introduces several new capabilities within Cloudflare One to enhance data security across the enterprise: browser-based RDP clipboard controls to precisely manage data transfer directionality and context, operation mapping extended to logs for richer visibility into SaaS application usage, on-device Endpoint DLP integrated into the Cloudflare One Client for consistent data protection on endpoints, and AI security scanning for Microsoft 365 Copilot via API CASB to analyze prompts, responses, and uploaded files for data security issues.

A QUICker SASE client: re-building Proxy Mode

3/5/2026

Re-built the Cloudflare One Client's proxy mode from the ground up, deprecating WireGuard for proxy mode in favor of QUIC. This involves leveraging MASQUE (part of QUIC) for proxying IP packets and using QUIC streams for direct L4 proxying via HTTP/3 with the CONNECT method. This architectural shift bypasses smoltcp, leverages native QUIC benefits for congestion and flow control, and allows for tuneable parameters, resulting in doubled download/upload speeds and decreased latency.

Mind the gap: new tools for continuous enforcement from boot to login

3/4/2026

Introduces two new tools for Cloudflare One: mandatory authentication for the Cloudflare One Client to enforce internet access policies from device boot-up, and an independent MFA layer that works alongside existing identity providers, offering biometrics, security keys, and TOTP as secondary authentication factors for enhanced security.

Defeating the deepfake: stopping laptop farms and insider threats

3/4/2026

This post introduces the integration of Nametag with Cloudflare Access as a new identity verification layer within the SASE platform, Cloudflare One. This integration allows for identity-verified onboarding and continuous identity assurance, addressing the threat of remote IT worker fraud and AI-powered impersonation. The technical implementation involves integrating Nametag via OpenID Connect (OIDC) as an IdP or an external evaluation factor alongside existing identity providers. The workflow includes user authentication via Nametag's Deepfake Defense™ technology, which verifies the user's liveness and identity using selfies and government-issued IDs. This complements existing insider threat protections like DLP and RBI by providing the missing link of identity assurance.

Moving from license plates to badges: the Gateway Authorization Proxy

3/4/2026

Introduced the Gateway Authorization Proxy and PAC File Hosting to enable clientless authentication and policy enforcement for unmanaged devices. The Authorization Proxy uses signed JWT cookies to track user identity across sessions and domains, integrating with Cloudflare Access for authentication. PAC File Hosting allows Cloudflare to host Proxy Auto-Configuration files, simplifying setup and management for administrators.

Stop reacting to breaches and start preventing them with User Risk Scoring

3/4/2026

Introduces User Risk Scores into Cloudflare One's SASE platform, allowing ZTNA policies to incorporate user behavior and risk levels. This involves continuous calculation of risk scores based on internal telemetry (Access, Gateway) and third-party integrations (CrowdStrike, SentinelOne). The system supports adaptive access policies that dynamically adjust user permissions based on their risk score, and enables sharing of risk signals back to Identity Providers like Okta via the Shared Signals Framework.

See risk, fix risk: introducing Remediation in Cloudflare CASB

3/3/2026

Introduces automated remediation capabilities for Cloudflare CASB, allowing users to fix risky file-sharing configurations in Microsoft 365 and Google Workspace directly from the Cloudflare One dashboard. This feature leverages Cloudflare Workers, Workflows, Queues, KV, Secrets Store, and Hyperdrive to execute remediation actions such as removing public links or organization-wide access. The system is designed for speed and durability, with average job completion times of 48 seconds (p50). Future plans include quarantine actions, custom webhook actions, autoremediation policies, custom CASB findings, bulk remediation, and extending to more SaaS integrations.

Beyond the blank slate: how Cloudflare accelerates your Zero Trust journey

3/2/2026

Introduced Project Helix, a system that codifies Cloudflare One expertise and automates the deployment of Zero Trust configurations. Project Helix leverages Terraform templates and a web-based UI hosted on Cloudflare Workers and Containers to allow users to quickly deploy baseline security policies across DNS, network, and HTTP protocols. This includes features like TLS inspection, QUIC/HTTP3 security, Remote Browser Isolation for risky domains, visibility and controls for AI applications, and tenant control policies for SaaS applications. It also optimizes traffic routing for real-time communication apps and handles captive portals. The system is internationalized and significantly reduces deployment time from weeks to minutes.

Modernizing with agile SASE: a Cloudflare One blog takeover

3/2/2026

This post announces innovations to Cloudflare One, positioning it as an agile and composable SASE platform. It details how Cloudflare One converges networking and security into a single, global connectivity cloud built on a global network. Key technical aspects include a single-pass architecture that runs security checks on every server simultaneously, eliminating service-chaining and enabling weightless security. The post outlines a week of technical deep-dives covering network foundation, identity evolution, AI for security, autonomous edge performance, and unified enterprise solutions. It highlights the composable and programmable nature of the platform, its integration with Cloudflare Workers for real-time security event interception, and immediate use cases such as remote access modernization, email phishing protection, DNS filtering, safe AI adoption, and simplified branch networking.

The truly programmable SASE platform

3/2/2026

This post details how Cloudflare's SASE platform (Cloudflare One) is becoming more programmable by integrating deeply with its Developer Platform (Cloudflare Workers). It introduces the concept of 'programmability' beyond basic APIs, focusing on the ability to intercept security events, enrich them with external context, and act on them in real time. The post highlights the ability to extend policy decisions with custom logic, such as calling external risk APIs, injecting dynamic headers, or validating browser attributes, all executed at the edge via Workers. It provides a concrete example of automated device session revocation using a scheduled Worker that queries the Devices API to revoke inactive registrations. The post also outlines future plans for custom actions in Cloudflare Gateway to support dynamic policy enforcement and request augmentation.

2025

Every Cloudflare feature, available to everyone

9/25/2025

This post announces a strategic shift to make nearly all Cloudflare features, previously restricted to enterprise plans, available to all customers. It begins with making Single Sign-On (SSO) for the dashboard available to any user, regardless of plan, and commits to a future where all new releases follow a self-service by default model. This includes revisiting pricing and metering for some features and removing friction in setup historically handled by solutions engineers. The goal is to democratize access to powerful tools and improve the overall customer experience.

Securing data in SaaS to SaaS applications

9/24/2025

Introduces a new proxy-based approach for securing SaaS-to-SaaS integrations, inspired by the Salesloft breach. This involves two deployment models: one for data owners using vanity hostnames to proxy traffic to SaaS applications, and another for SaaS vendors to proxy traffic to their own services. Both models leverage Cloudflare's reverse proxy network for visibility, anomaly detection, and access control. A key technical innovation is the use of 'key splitting' to cryptographically divide bearer tokens into two fragments, with one fragment stored at the edge and the other with the integration, preventing complete tokens from being stored and enabling rapid revocation.

Integrating CrowdStrike Falcon Fusion SOAR with Cloudflare’s SASE platform

9/15/2025

This post introduces the integration of Cloudflare One's Zero Trust Access and Email Security capabilities with CrowdStrike Falcon Fusion SOAR. It highlights two out-of-the-box integrations that allow Security Operations Centers (SOCs) to automate threat detection and remediation workflows, such as blocking phishing emails, revoking session tokens, and isolating compromised devices, thereby reducing manual effort and response times.

A deep dive into Cloudflare’s September 12, 2025 dashboard and API outage

9/13/2025

This post details a significant outage caused by a bug in the dashboard leading to excessive calls to the Tenant Service API, which is critical for API request authorization. It highlights the impact on both the dashboard and other APIs, the response taken to mitigate the issue, and crucial lessons learned regarding release management (Argo Rollouts), 'thundering herd' problem mitigation, capacity planning for critical services, and the need for improved observability to differentiate between retries and new API requests.

Cloudflare recognized as a Visionary in 2025 Gartner® Magic Quadrant™ for SASE Platforms

7/15/2025

This post announces Cloudflare's recognition as a Visionary in the 2025 Gartner Magic Quadrant for SASE Platforms. It highlights Cloudflare One as their SASE platform, detailing its evolution with features like lightweight branch connectors, native DLP, and secure infrastructure access tools. The post emphasizes Cloudflare's unique connectivity cloud approach, built on a global network, unified control plane, and composable data plane, differentiating it from other SASE vendors by building the platform first and layering services upon it. It details how customers benefit from this design through reduced last-mile latency, efficient processing latency, and optimized inter-data center connectivity. Use cases for network and security modernization are also discussed, including Cloudflare Access, Magic WAN, and Cloudflare Gateway.

Introducing simple and secure egress policies by hostname in Cloudflare’s SASE platform

7/7/2025

Introduced hostname, domain, content category, and application-based egress policies within Cloudflare Gateway. This was achieved by leveraging Cloudflare's DNS resolver to associate DNS queries with network connections and using a synthetic IP mechanism to tag traffic destined for specific hostnames before Layer 4 connection establishment, overcoming the limitation of evaluating egress policies before Layer 7 information is available.

Everything you need to know about NIST’s new guidance in “SP 1800-35: Implementing a Zero Trust Architecture”

6/19/2025

This post details how Cloudflare's Zero Trust platform aligns with NIST SP 1800-35's reference architecture for implementing Zero Trust Architecture (ZTA). It explains how Cloudflare's products can be integrated with third-party vendors to support the NIST reference architecture, specifically focusing on the 'Run Phase' which covers both cloud and on-premise resources. It highlights Cloudflare's role in providing Policy Enforcement Points (PEPs) and Policy Engines (PEs) within the ZTA framework, and how its platform supports the Policy Information Points (PIPs) like Identity, Credential, and Access Management (ICAM), Endpoint Detection and Response (EDR)/Endpoint Protection Platforms (EPP), and Security Analytics.

Cloudflare named in 2025 Gartner® Magic Quadrant™ for Security Service Edge

5/23/2025

This post announces Cloudflare's recognition in the 2025 Gartner Magic Quadrant for Security Service Edge (SSE), underscoring the maturity and breadth of its Zero Trust Network Access (ZTNA) service, Cloudflare Access, and its integrated SSE platform. It details how Cloudflare's SSE capabilities align with key SSE components like zero trust access control, outbound filtering, secure SaaS usage, data protection, and employee experience. The post highlights planned advancements in access control (IdP-agnostic MFA, JIT access, browser RDP) and secure web gateway/DNS filtering (deep packet inspection, FQDN filtering), reinforcing Cloudflare's position as a unified SASE platform built on its global network.

Open-sourcing OpenPubkey SSH (OPKSSH): integrating single sign-on with SSH

3/25/2025

This post introduces the open-sourcing of OPKSSH (OpenPubkey SSH), a system that integrates single sign-on (SSO) technologies like OpenID Connect with SSH. OPKSSH allows users to authenticate to SSH servers using their identity provider (IdP) credentials, eliminating the need for manual SSH key management. It achieves this by packaging an OpenPubkey PK Token (which includes an identity and a public key) into an SSH certificate extension. The SSH server uses an AuthorizedKeysCommand to invoke an OpenPubkey verifier, which validates the PK Token and checks if the user's email address is authorized. This enhances security by using ephemeral keys and improves usability by simplifying the authentication process.

Detecting sensitive data and misconfigurations in AWS and GCP with Cloudflare One

3/21/2025

Introduced Cloud DLP (Data Loss Prevention) functionality integrated with Cloudflare CASB to scan objects in Amazon S3 buckets and Google Cloud Storage for sensitive data. This includes pre-built detection profiles for common data types and custom profiles using regular expressions. Also enhanced posture management features to identify misconfigurations in IAM, bucket, and object settings. The implementation utilizes a serverless architecture with a Compute Account, Controller function, Crawler process, and Scanner function to ensure data privacy and scalability.

RDP without the risk: Cloudflare's browser-based solution for secure third-party access

3/21/2025

Introduced clientless, browser-based support for Remote Desktop Protocol (RDP) as a new capability within the Cloudflare Access Zero Trust Network Access (ZTNA) service. This feature leverages the IronRDP client, which runs in the browser and encapsulates RDP sessions within WebSocket connections secured by Cloudflare Access policies, eliminating the need for VPNs or RDP client software. It integrates with Cloudflare Tunnel for connectivity and enforces authentication, authorization, and auditing through identity-aware policies.

Improved support for private applications and reusable access policies with Cloudflare Access

3/20/2025

This post introduces the ability to define private hostname and IP address-defined applications directly within Cloudflare Access, mirroring the administrative experience for web-based applications on public hostnames. It also introduces reusable access policies to simplify ongoing policy management. Previously, private application access was primarily handled through Cloudflare Gateway's network firewall component, with a limited wrapper from Access. This update integrates private application management directly into Access, improving consistency and ease of use for ZTNA deployments.

Advancing account security as part of Cloudflare’s commitment to CISA’s Secure by Design pledge

3/17/2025

This post details Cloudflare's advancements in account security, specifically focusing on multi-factor authentication (MFA) adoption as part of the CISA Secure by Design pledge. It highlights the addition of social logins with Google and Apple, which contribute to a significant portion of MFA-secured users. The post also discusses leaked password notifications and reinforces the importance of strong, unique passwords and enabling MFA through various methods like security keys and authenticator apps. For administrators, it outlines the ability to require MFA for all users and the availability of free SSO for enterprise customers.

2024

What’s new in Cloudflare: Account Owned Tokens and Zaraz Automated Actions

11/14/2024

Introduced Account Owned Tokens, which are API tokens scoped to an account rather than an individual user. This allows for better representation of services, independent of user lifecycle events, and improves auditability by attributing actions to the token name. Also launched Zaraz Automated Actions, which simplifies the setup of third-party tools by automating common events like pageviews and custom events, reducing manual configuration.

Fearless SSH: short-lived certificates bring Zero Trust to infrastructure

10/23/2024

This post introduces 'Access for Infrastructure' as a new feature within Cloudflare One, integrating BastionZero's capabilities. It specifically details the implementation of short-lived SSH access, which replaces traditional SSH keys and passwords with short-lived SSH certificates issued by a Cloudflare-managed Certificate Authority (CA). The system uses a CA secret key to sign certificates and a public key for servers to validate them. Servers are configured to trust the Cloudflare SSH CA. Certificates expire after 3 minutes, reducing the risk of compromise, while allowing for longer SSH sessions. Policies are centrally managed in the Cloudflare dashboard, enabling granular control over user access to specific servers and Linux users, authenticated via SSO, MFA, and device posture.

Protect against identity-based attacks by sharing Cloudflare user risk scores with Okta

10/15/2024

This post introduces a new integration between Cloudflare One and Okta that allows for the real-time sharing of Cloudflare's user risk scores with Okta. This enables Okta to automatically enforce security policies, such as multi-factor authentication or universal logouts, based on the user's risk level. The integration leverages the OpenID Shared Signals Framework Specification (SSF) for secure and standardized exchange of security event tokens.

Cloudflare acquires Kivera to add simple, preventive cloud security to Cloudflare One

10/8/2024

This post announces the acquisition of Kivera, which adds preventative, inline controls to Cloudflare One for enforcing secure configurations of cloud resources. It inspects cloud API traffic to provide enhanced visibility and granular controls for mitigating risks, managing cloud security posture, and streamlining DevOps processes. Key capabilities include one-click security for misconfigurations, enforced cloud tenant control, prevention of data exfiltration, reduction of 'shadow' cloud infrastructure, streamlined compliance, and a flexible DevOps model. This complements existing CSPM and CNAPP tools and integrates with Cloudflare's connectivity cloud.

Cloudflare acquires BastionZero to extend Zero Trust access to IT infrastructure

5/30/2024

This post announces the acquisition of BastionZero, a Zero Trust infrastructure access platform, and details how it will extend Cloudflare One's Zero Trust Network Access (ZTNA) capabilities to infrastructure like servers, Kubernetes clusters, and databases. It highlights the limitations of current infrastructure access methods (SSH, RDP, Kubernetes authentication) and how BastionZero's native integration with these protocols, coupled with its OpenPubkey-based SSO for infrastructure access, will provide a more secure and manageable solution. Key new capabilities include the elimination of long-lived keys/credentials via ephemeral PAM, a DevOps-based approach for securing SSH connections with session recording, and clientless RDP access.

Unified Risk Posture Management by Cloudflare | Use Cases

5/7/2024

This post introduces 'Cloudflare for Unified Risk Posture,' a new suite that converges SASE and WAAP capabilities to provide automated and dynamic risk posture enforcement. It details how Cloudflare evaluates risk across people and applications, exchanges risk indicators with partners like CrowdStrike and Okta, and enforces automated risk controls at scale. Key use cases include enforcing Zero Trust with CrowdStrike, leveraging user risk scores based on device posture, and integrating with SIEM/XDR platforms. This significantly expands the platform's ability to manage risk posture by offering a unified approach to risk evaluation, exchange, and enforcement.

Introducing WARP Connector: paving the path to any-to-any connectivity

3/20/2024

Introduced WARP Connector, an extension of the WARP client, to enable bidirectional, site-to-site, and mesh-like connectivity within Cloudflare One. This new connector addresses limitations of cloudflared by proxying at Layer 3, preserving true source IP addresses, and providing a unified experience for connecting users and networks. It supports use cases like VOIP/SIP servers and CI/CD pipelines by acting as a virtual router for subnets, allowing traffic to on/off-ramp through Cloudflare's global network.

Eliminate VPN vulnerabilities with Cloudflare One

3/6/2024

This post details how Cloudflare One's SASE platform, specifically its Zero Trust Network Access (ZTNA) service, addresses vulnerabilities found in legacy VPN solutions like Ivanti Connect Secure. It highlights how ZTNA enforces the principle of least privilege, limiting lateral movement for attackers, and how Cloudflare's platform design prevents external access to system internals, mitigating risks associated with appliance compromises. The post also references Cloudflare's WAF proactively detecting the Ivanti zero-day vulnerabilities.

Zero Trust WARP: tunneling with a MASQUE

3/6/2024

This post announces the integration of the MASQUE protocol into Zero Trust WARP. MASQUE, built on HTTP/3 and QUIC, replaces WireGuard as the tunneling protocol for Zero Trust WARP. Key benefits highlighted include improved connectivity from anywhere by using standard ports (443), enhanced performance on lossy networks due to QUIC's multiplexing and packet coalescing, and support for FIPS-compliant cipher suites. This integration addresses customer demands for traffic that looks like HTTPS and meets compliance requirements, marking a significant step in the evolution of Cloudflare's Zero Trust offering.

Securing Cloudflare with Cloudflare: a Zero Trust journey

3/5/2024

This post details Cloudflare's internal implementation of its Zero Trust suite of products (Access, Zero Trust Agent, Magic WAN, Gateway, Cloud Email Security) to secure its own workforce. It highlights the privacy-first approach taken, including data minimization, de-identification, transparent communication, and granular PII controls within logs. The post also touches upon the evolution of these capabilities over several years to protect a growing and distributed workforce.

Simpler migration from Netskope and Zscaler to Cloudflare: introducing Deskope and a Descaler partner update

3/5/2024

This post introduces the Deskope Program, a new set of tooling designed to simplify and accelerate the migration of existing Netskope customers to Cloudflare One's SASE platform. It also announces the expansion of the Descaler Program to Authorized Service Delivery Partners, allowing them to leverage the Descaler toolkit for Zscaler migrations. The post highlights the speed and simplicity advantages of Cloudflare Gateway over competitors like Netskope and Zscaler, and details the technical approach for migration using API calls and automated tools.

Introducing behavior-based user risk scoring in Cloudflare One

3/4/2024

This post introduces user risk scoring within Cloudflare One, a SASE platform. It leverages AI/ML to analyze user behavior and network telemetry to detect anomalous activities and potential indicators of compromise. This enables dynamic risk assessment (Low, Medium, High) for users, allowing security teams to automatically adapt security posture based on behaviors like 'impossible travel' and Data Loss Prevention (DLP) triggers, enhancing the Zero Trust approach.

Enhancing security analysis with Cloudflare Zero Trust logs and Elastic SIEM

2/22/2024

This post announces the integration of Cloudflare Zero Trust logs with Elastic SIEM, providing pre-built dashboards for analyzing Gateway HTTP and CASB events. It details the value of this integration for comprehensive visibility, field normalization, efficient search, correlation, and threat detection. It also outlines the setup process via Logpush jobs and enabling the integration in Kibana.

Fulfilling the promise of single-vendor SASE through network modernization

2/7/2024

This post announces updates to Cloudflare One to further the promise of a single-vendor SASE architecture. It introduces flexible on-ramps for site-to-site connectivity supporting agent/proxy-based and appliance/routing-based implementations, simplifying SASE networking for security and networking teams. New WAN-as-a-service (WANaaS) capabilities include high availability, application awareness, a virtual machine deployment option, and enhanced visibility and analytics. It also introduces Zero Trust connectivity for DevOps with mesh and peer-to-peer (P2P) secure networking capabilities extending ZTNA to service-to-service workflows and bidirectional traffic.

2023

Introducing advanced session audit capabilities in Cloudflare One

11/16/2023

Introduced advanced session audit capabilities in Cloudflare One, enabling administrators to view active user sessions and associated data used by Zero Trust policies. This feature leverages Cloudflare Workers KV to store user identity information (IdP claims, device posture, network context) at the time of authentication, facilitating easier troubleshooting of identity-related issues without requiring the sharing of JWTs or HAR files.

Introducing HAR Sanitizer: secure HAR sharing

10/26/2023

This post introduces the HAR Sanitizer, a new open-source tool that addresses a critical security vulnerability exposed by the Okta breach. It allows users to sanitize HTTP Archive (HAR) files by removing sensitive session cookies and JWTs before sharing them for debugging. This directly enhances the security of troubleshooting processes within the context of Cloudflare's Zero Trust offerings, particularly for Cloudflare Access, by preventing session hijacking and unauthorized access.

How Cloudflare mitigated yet another Okta compromise

10/20/2023

This post details how Cloudflare's Zero Trust architecture, specifically Cloudflare Access, Gateway, and Data Loss Prevention, was instrumental in mitigating a security incident originating from a compromise of Okta's systems. It highlights the effectiveness of real-time detection and rapid response in preventing impact to Cloudflare customer information and systems, even when faced with sophisticated attacks involving compromised employee accounts and session tokens. The post also provides recommendations for Okta and its customers to enhance security practices, particularly around multi-factor authentication and monitoring.

Welcome to connectivity cloud: the modern way to connect and protect your clouds, networks, applications and users

9/26/2023

This post introduces the concept of a 'connectivity cloud' as the next evolution of Cloudflare's platform. It frames the company's existing and future offerings as a unified, intelligent platform for any-to-any connectivity and security across diverse digital environments. This builds upon the existing thread of account access management and permissions by positioning these capabilities as integral components of this broader connectivity vision, emphasizing how they contribute to restoring control and simplifying complex IT and security challenges for customers.

What’s next for Cloudflare One’s data protection suite

9/7/2023

This post announces the launch of Cloudflare One for Data Protection, a unified suite that converges DLP, CASB, ZTNA, SWG, RBI, and cloud email security services. It recaps the DLP and CASB capabilities launched in the past year, highlighting improvements in customization, deep detections, and detailed detections for DLP, and expanded API integrations, strengthened findings, and convergence with DLP for CASB. It also previews new and upcoming functionality including exact data matching with custom wordlists, detection of source code and health data, and further convergence of API-driven CASB & DLP for data-at-rest protections in Microsoft 365 and GitHub.

Integrate Cloudflare Zero Trust with Datadog Cloud SIEM

8/3/2023

This post announces the general availability of Cloudflare Zero Trust Integration with Datadog Cloud SIEM. It details how customers can aggregate Cloudflare Zero Trust logs (including Access Requests, Audit logs, CASB findings, Gateway logs, and Zero Trust Session Logs) into Datadog for enhanced threat detection, investigation, and automated response. Key contributions include out-of-the-box dashboards and detection rules for CASB findings and impossible travel scenarios, significantly improving security insights and accelerating response times within the Zero Trust ecosystem.

Protecting data on Apple devices with Cloudflare and Jamf

7/20/2023

This post details the integration of Cloudflare's Zero Trust Solutions (DLP, RBI, SaaS Tenancy Controls) with Jamf's management of Apple devices. It outlines how Jamf customers can leverage Magic WAN to steer traffic to Cloudflare for inspection, enabling SSL/TLS decryption for content inspection of HTTPS traffic. Specific steps are provided for implementing DLP, RBI, and SaaS Tenancy Control, highlighting the use of Jamf Pro for profile deployment and Cloudflare One for policy configuration. This expands the reach of Cloudflare's Zero Trust platform to managed Apple endpoints.

Descale your network with Cloudflare’s enhanced Descaler Program

6/22/2023

This post introduces the enhanced Descaler Program, which facilitates the migration of Zscaler customers to Cloudflare One. It highlights the program's ability to accelerate the transition of security configurations, policies, and lists, reducing migration time from days to hours or even minutes. Key contributions include the addition of configuration summary views and Terraform output options to the Descaler tooling, addressing customer feedback and enabling infrastructure-as-code workflows.

A complete suite of Zero Trust security tools to help get the most from AI

5/15/2023

This post introduces Cloudflare One for AI, a new collection of features designed to help teams safely use AI services while maintaining a Zero Trust security posture. It details how Cloudflare Gateway can measure and control AI usage, how service tokens and policies can secure API access for AI models, and how Data Loss Prevention (DLP) can restrict sensitive data uploads to AI services. It also mentions upcoming CASB integrations for AI misconfiguration checks.

Cloudflare One named in Gartner® Magic Quadrant™ for Security Service Edge

4/13/2023

This post announces Cloudflare One's inclusion in the Gartner Magic Quadrant for Security Service Edge (SSE), highlighting its Zero Trust solution as a key component. It details the evolution of SSE from traditional perimeter security to cloud-based solutions, positioning Cloudflare One as a single-vendor SASE platform that integrates network-as-a-service and SSE capabilities. The post emphasizes Cloudflare's unique approach of delivering SSE features on its existing global network infrastructure, offering advantages in performance and security without additional hops. It also outlines the core SSE capabilities within Cloudflare One, including Zero Trust Access Control for internal resources and SaaS applications, and DNS filtering.

Wildcard and multi-domain support in Cloudflare Access

3/18/2023

This post introduces full support for wildcard and multi-domain application definitions in Cloudflare Access. Previously, Access applications were limited to single hostnames. The new features allow for protecting multiple subdomains with a single Access app (Multi-Domain Applications) and using wildcard characters (*) to define application patterns, enabling protection of hundreds of applications with one policy. This simplifies configuration, reduces administrative overhead, and ensures seamless JWT cookie issuance across associated hostnames, solving issues for single-page applications and automatically provisioned services.

Cloudflare Access is the fastest Zero Trust proxy

3/17/2023

This post provides detailed performance benchmarks comparing Cloudflare Access to Zscaler Private Access and Netskope Private Access. It presents data on P95 response times and connect times from 300 global locations to application servers in various regions (Toronto, South America, Asia). The analysis breaks down performance for new and existing authentication sessions, showcasing Cloudflare's significant speed advantage (e.g., 50% faster than Zscaler, 75% faster than Netskope) due to its global network and optimized architecture.

Introducing custom pages for Cloudflare Access

3/17/2023

Introduced customizable pages for Cloudflare Access, including login, block, and application launcher screens. This allows administrators to tailor the end-user experience with their own branding and messaging, reducing confusion and improving the user journey when interacting with Zero Trust workflows.

Adding Zero Trust signals to Sumo Logic for better security insights

3/14/2023

This post announces the expansion of Cloudflare's Logpush integration with Sumo Logic's Cloud SIEM to include automated normalization and correlation of Zero Trust logs. This enhances visibility into Cloudflare Gateway (Network, DNS, HTTP), Remote Browser Isolation, Data Loss Prevention, Access, and Cloud Access Security Broker logs, providing joint customers with deeper context into their security posture and accelerating the triage process for security analysts.

No hassle migration from Zscaler to Cloudflare One with The Descaler Program

3/14/2023

Introduces the Descaler Program, a new initiative to facilitate migration from Zscaler to Cloudflare One. The program includes technical tools for automated export, transformation, and loading of Zscaler configurations (ZIA/ZPA) into Cloudflare One, leveraging ETL best practices and API calls. It also outlines architecture workshops and partner engagements for technical success, and ROI calculations, contract escape hatches, and Zero Trust roadmap assessments for business success.

Scan and secure Atlassian with Cloudflare CASB

3/14/2023

Introduced new integrations for Cloudflare CASB with Atlassian Confluence and Jira, enabling scanning for application-specific security issues such as publicly shared content, unauthorized access, and third-party app access issues. This expands the list of supported SaaS applications for CASB.

Zero Trust security with Ping Identity and Cloudflare Access

3/14/2023

This post announces and details the integration of Cloudflare Access with Ping Identity (PingOne and PingFederate) to provide enhanced Zero Trust security. It highlights the ability to enforce strong authentication and access controls, including SSO and MFA, for both modern and legacy applications without requiring application code modifications. The post also mentions upcoming SCIM support for user and group synchronization.

Cloudflare Aegis: dedicated IPs for Zero Trust migration

3/13/2023

This post introduces Cloudflare Aegis, a new capability that provides dedicated egress IP addresses for customers migrating to Zero Trust. Aegis allows organizations to lock down their services at an IP level, ensuring that traffic originates from a trusted, customer-specific IP range. This complements existing Zero Trust solutions like mTLS and Cloudflare Access by providing an additional layer of IP-based security, particularly beneficial for large organizations with many applications that are transitioning to Zero Trust models.

Mutual TLS now available for Workers

3/13/2023

This post introduces Mutual TLS (mTLS) support for Cloudflare Workers, enabling Workers to authenticate to services that enforce mTLS. This expands the zero-trust capabilities of Workers by allowing them to act as authenticated clients to other services, such as APIs, microservices, and databases, which is crucial for secure internal communications and machine-to-machine interactions.

Using Cloudflare Access with CNI

3/13/2023

This post introduces a new method for protecting hosted applications using Cloudflare Access in conjunction with Cloudflare Network Interconnect (CNI) and Aegis. This approach allows for Zero Trust policies to be enforced without requiring installed software or custom code on application servers. Aegis provides a dedicated, Cloudflare-sourced IP address for inbound traffic, enabling origin applications to enforce network-level firewall policies and ensure that only authenticated Access calls from Cloudflare can reach the application. This effectively air-gaps the service from direct public internet access, offering a more secure alternative to traditional VPNs and Cloudflare Tunnel for certain use cases.

New Zero Trust navigation coming soon (and we need your feedback)

3/7/2023

This post announces an upcoming update to the Zero Trust dashboard navigation, scheduled for March 20, 2023. The changes aim to provide a more seamless user experience by enabling quicker navigation between Zero Trust and other Cloudflare products, easier account switching, and direct access to resources and support. The post also highlights underlying improvements in user and account authorization, the adoption of consistent table UIs, and a unified visual design for the Zero Trust dashboard to align with the broader Cloudflare experience. The motivation for this change stems from the growth of Zero Trust capabilities and the increasing use of multiple Cloudflare products together.

Manage and control the use of dedicated egress IPs with Cloudflare Zero Trust

2/3/2023

Introduced Gateway Egress policies within Cloudflare Zero Trust, allowing administrators to define rules for using dedicated egress IPs based on attributes like identity, application, IP address, and geolocation. This provides granular control over traffic egress, enabling specific use cases like geo-specific experiences and allowlisting third-party services without forcing all traffic through dedicated IPs.

Inside Geo Key Manager v2: re-imagining access control for distributed systems

1/27/2023

This post introduces Geo Key Manager v2, a significant evolution in Cloudflare's access control capabilities. It details the challenges of Geo Key Manager v1, particularly its inflexibility in policy management and performance issues. The post highlights the adoption of Attribute-Based Encryption (ABE) as a solution, enabling more granular, flexible, and geographically-aware access control for sensitive data like TLS private keys. It also emphasizes ABE's potential to avoid centralized points of failure and includes the implementation in Cloudflare's open-source cryptographic library.

Cloudflare incident on January 24, 2023

1/25/2023

This post details a significant incident on January 24, 2023, where a bug in the release of a service token feature led to widespread service degradation and unavailability for 121 minutes. The incident stemmed from an error in updating service token metadata, specifically overwriting the 'client_secret' with an empty string, which invalidated tokens for critical internal Cloudflare accounts. This impacted services like Workers, Zero Trust, WARP, Cache Purge, Cache Reserve, Images, and R2. The post explains the technical root cause, the incident timeline, the fix implemented through manual restoration and database backups, and the broader implications of service token management on platform authentication and stability.

Cloudflare Zero Trust for managed service providers

1/13/2023

Introduced parent-child policy configurations within the Tenant platform, integrating with Cloudflare Gateway. This enables MSPs to manage global corporate security policies at a parent account level and apply specific overrides or customizations at child account levels, facilitating scaled Zero Trust deployments for multi-tenant environments. Enhanced DNS location matching and filtering defaults for specific use cases like CISA's requirements for dedicated IPv4 resolvers and fail-closed behavior.

Give us a ping. (Cloudflare) One ping only.

1/13/2023

This post introduces the integration of network diagnostic tools (ping, traceroute, MTR) into Cloudflare Zero Trust. It details how these tools leverage the ICMP protocol and are proxied over QUIC datagrams between Cloudflare and cloudflared instances. The post also provides examples of using these tools to troubleshoot connectivity to private network destinations behind Cloudflare Tunnel, highlighting the technical underpinnings and practical application for users managing private networks on Cloudflare.

Announcing SCIM support for Cloudflare Access & Gateway

1/12/2023

Introduced SCIM protocol support for Cloudflare Access and Gateway, enabling automated user provisioning and deprovisioning based on identity provider events. This includes automatic revocation of active sessions upon user deactivation and synchronization of identity provider groups into Access and Gateway policy builders. Initial support is for Azure Active Directory and Okta for self-hosted Access applications, with plans to expand to more Identity Providers and SaaS applications.

Cloudflare's CASB integration with Salesforce and Box

1/12/2023

This post announces the release of two new SaaS integrations for Cloudflare CASB: Salesforce and Box. This expands Cloudflare's CASB capabilities to identify and remediate security risks within these widely used platforms, addressing issues like insecure settings, inappropriate file sharing, and default permissions. This directly contributes to the evolution of securing SaaS applications and enhancing visibility into sensitive business data.

Expanding our Microsoft collaboration: proactive and automated Zero Trust security for customers

1/12/2023

This post announces four new integrations between Azure AD and Cloudflare Zero Trust: 1. Per-application conditional access, allowing Azure AD Conditional Access policies to be enforced per application in Cloudflare Access. 2. SCIM for autonomous synchronization of Azure AD groups between Cloudflare Zero Trust and Azure AD, enabling real-time provisioning and deprovisioning of users and groups. 3. Risky user isolation, using Azure AD risk signals to automatically isolate high-risk users with Cloudflare's Browser Isolation product. 4. Secure joint Government Cloud customers, enabling integration with Azure AD for centralized identity and access management within the Cloudflare global network.

Improved access controls: API access can now be selectively disabled

1/11/2023

Introduced the ability for account owners to selectively disable API access for specific users or account-wide. This feature enhances security by allowing for granular control over user permissions and reducing the attack surface associated with API keys and tokens. It is a first step towards allowing account-owned API tokens and increasing general visibility of tokens.

One-click data security for your internal and SaaS applications

1/11/2023

This post introduces the integration of Cloudflare's browser isolation technology with its Zero Trust access control product. This allows administrators to enforce granular rules on application usage and data within user sessions. Key features include forcing sessions into an isolated browser without client software, disabling data loss vectors like file downloads, printing, and copy-pasting, adding watermarks, and disabling keyboard input. It also integrates with Cloudflare One's Data Loss Prevention (DLP) suite. This capability can be extended to SaaS applications by configuring Cloudflare's access control as an identity proxy. A beta program for a one-click version of this feature is also announced.

Network detection and settings profiles for the Cloudflare One agent

1/10/2023

Introduced network detection for the Cloudflare One agent, enabling automatic switching between Cloudflare's network and local networks based on the user's physical location. This is achieved by defining managed networks using TLS certificate fingerprints and configuring device profiles that apply based on these network locations. Additionally, profiles can now be applied based on user group membership, allowing for more granular control over traffic routing for different user segments.

New ways to troubleshoot Cloudflare Access 'blocked' messages

1/10/2023

This post introduces enhanced troubleshooting capabilities for Cloudflare Access, allowing administrators to investigate block decisions based on connection context (e.g., location, IP address, Secure Web Gateway presence) in addition to identity. It details a new GraphQL API for querying specific blocked requests by RayID, User, or Application, and improvements to the user-facing block page. The system leverages the existing analytics pipeline with intelligent sampling to manage the scale of log data generated by non-identity block events.

Why do CIOs choose Cloudflare One?

1/10/2023

This post details the evolution of Cloudflare One as a comprehensive SASE offering, driven by customer feedback and the need to address enterprise connectivity and security challenges beyond traditional WAF and CDN. It highlights six key themes: more complete security, making teams faster, easier management, product integration, cost-efficiency, and single vendor capability. Specific technical advancements mentioned include the use of BoringTun (WireGuard implementation) for the Cloudflare agent, smart routing technology, and the integration of Area 1 Email Security. The post also provides customer examples illustrating the benefits of Cloudflare One for security and performance.

Bring your own certificates to Cloudflare Gateway

1/9/2023

Introduced support for customers to bring their own certificates to Cloudflare Gateway. This allows IT and Security administrators to use custom certificates for traffic inspection and policy enforcement, offering greater flexibility and ease of deployment alongside the existing Cloudflare-provided certificate option. The post details the API process for uploading root certificates and private keys, and configuring Gateway to use them, enabling zero-maintenance downtime during transitions.

Weave your own global, private, virtual Zero Trust network on Cloudflare with WARP-to-WARP

1/9/2023

Introduced WARP-to-WARP connectivity, enabling direct private network connections between devices running Cloudflare WARP. This feature allows any WARP-enabled device within an organization to reach any other WARP-enabled device, facilitating use cases like developer testing, IT troubleshooting, and data synchronization between local and remote machines. Traffic is routed through Cloudflare's network, leveraging Argo Smart Routing and Zero Trust Secure Web Gateway for security and auditing, and can be upgraded from IP packets to proxied TLS connections.

2022

Cloudflare Zero Trust for Project Galileo and the Athenian Project

12/12/2022

This post announces the availability of the Cloudflare One Zero Trust suite to organizations qualifying for Project Galileo and the Athenian Project at no cost. It details how Cloudflare One addresses common security challenges faced by these organizations, including phishing attacks (via Area 1 email security and DNS filtering), connecting employees and partners (via Cloudflare Tunnel and clientless access), and securing internet access (via Secure Web Gateway with malware scanning and DLP). It highlights that these enterprise-grade solutions can be configured and deployed quickly, even for organizations without dedicated IT departments.

Democratizing access to Zero Trust with Project Galileo

12/12/2022

This post announces the extension of Cloudflare's Zero Trust products to all domains under Project Galileo, aiming to democratize access to enterprise-level cybersecurity for underfunded organizations. It highlights how Project Galileo has evolved to address new threat environments and the digital divide in security, providing specific examples of how partners like CyberPeace Institute, ITDRC, Meedan, and the Organization of American States are leveraging Zero Trust tools for enhanced security and operational continuity.

How Cloudflare uses Terraform to manage Cloudflare

11/17/2022

This post details Cloudflare's internal adoption and best practices for using the Cloudflare Terraform provider to manage its own account configurations. It highlights the benefits of code-driven management for security, auditability, and self-service, including the use of CI/CD pipelines (Atlantis), a monorepo structure for managing multiple accounts, encrypted state management, daily automated applies for drift detection and certificate rotation, and the introduction of API/Terraform read-only mode for Zero Trust configurations to enforce a single source of truth.

Gateway + CASB: alphabetti spaghetti that spells better SaaS security

9/30/2022

This post details the integration of Cloudflare Gateway and CASB, allowing for the automated creation of Gateway policies based on CASB-identified security findings in SaaS applications. It provides specific examples of how this integration can be used to block inappropriate file uploads, restrict oversharing, and prevent uploads to unapproved Shadow IT applications, thereby enhancing SaaS security.

The (hardware) key to making phishing defense seamless with Cloudflare Zero Trust and Yubico

9/29/2022

This post announces a new partnership with Yubico to offer discounted hardware security keys (YubiKeys) to Cloudflare customers. It highlights how these keys integrate with Cloudflare Zero Trust to provide phishing-proof multi-factor authentication (MFA) and how Cloudflare can enforce their usage via the Authentication Method Reference (AMR) standard. The post also addresses the challenges of deploying hardware keys at scale and positions this initiative as a way to remove friction for customers adopting stronger security measures.

How Cloudflare implemented hardware keys with FIDO2 and Zero Trust to prevent phishing

9/29/2022

This post details Cloudflare's complete migration from a 'castle and moat' VPN architecture with TOTP-based MFA to a Zero Trust model enforced by FIDO2/WebAuthn hardware security keys for all employees. It explains the technical aspects of FIDO2, WebAuthn, CTAP1/2, and how Cloudflare Access was used for selective enforcement and later full enforcement of security keys. The post also covers the integration of security keys with SSH via Cloudflare Tunnel, demonstrating a unified approach to identity and access management across protocols.

Now all customers can share access to their Cloudflare account with Role Based Access Controls

9/29/2022

Introduced Role-Based Access Controls (RBAC) for all Cloudflare plan types (including FREE and PAYGO), allowing for granular permissions to be assigned to users based on predefined roles. This enhances security by limiting access to specific account functionalities and products, reducing the threat surface and preventing accidental misconfigurations.

The first Zero Trust SIM

9/26/2022

Introduced the Zero Trust SIM, a new capability that integrates SIM card technology with Cloudflare's Zero Trust platform. This involves leveraging SIMs (eSIM and physical) as a foundational element for mobile device security, enabling DNS filtering via Cloudflare Gateway, mitigating SIM-swapping attacks, and providing identity signals for secure private connectivity through Magic WAN. The SIM acts as an on-ramp to the Cloudflare One platform, simplifying BYOD security and offering a unified control plane for mobile traffic.

Bringing Zero Trust to mobile network operators

9/26/2022

This post introduces a new partnership program for mobile networks, 'Zero Trust for Mobile Operators,' to address security and performance challenges in 5G environments. It highlights the integration of Cloudflare One's SASE components (Magic WAN, Access, Gateway, CASB, Area 1) with mobile network infrastructure, emphasizing the complementary nature of their networks and services. The post also details the application of Cloudflare Workers for edge computing use cases within mobile networks, such as IoT, eCommerce, and financial data platforms, and introduces 'Workers for Platforms' as a mechanism for MNOs to offer edge compute to their customers. It further explores the network infrastructure synergy, enabling local breakouts and embedding Cloudflare services within MNO networks for reduced latency and enhanced security.

Cloudflare Data Loss Prevention now Generally Available

9/20/2022

This post announces the General Availability of Cloudflare's Data Loss Prevention (DLP) product. It details what DLP is, how it works by inspecting HTTP traffic for sensitive data patterns (like PII, credit card numbers, and SSNs) using regex and algorithms, and how it can be configured and applied via HTTP policies within the Zero Trust Dashboard. The post also highlights DLP's integration with other Cloudflare Zero Trust services for a comprehensive data protection strategy.

Detect security issues in your SaaS apps with Cloudflare CASB

9/20/2022

Introduced Cloudflare CASB (Cloud Access Security Broker) as a new addition to the Zero Trust platform. CASB connects to and scans third-party SaaS applications (initially Google Workspace, Microsoft 365, Slack, and GitHub) to identify security issues such as data exposure, file oversharing, misconfigurations, insecure settings, and Shadow IT. It leverages vendor APIs to provide visibility into data-at-rest and access permissions, complementing existing Zero Trust solutions like Cloudflare Access and Gateway.

Improved Access Control: Domain Scoped Roles are now generally available

9/19/2022

Introduced Domain Scoped Roles, allowing user access to be limited to specific domains or domain groups. This enhances security by enforcing the principle of least privilege and reduces administrative overhead for account owners. The feature is rolling out to Enterprise accounts and represents a step towards a new authorization system.

Live-patching security vulnerabilities inside the Linux kernel with eBPF Linux Security Module

6/29/2022

This post introduces the use of eBPF LSM to implement a security policy that prevents unauthorized user namespace creation via the `unshare` syscall. This directly addresses a privilege escalation vulnerability and demonstrates how Cloudflare leverages advanced kernel features to enhance security, aligning with the broader theme of zero-trust and robust access control.

Cloudflare One vs Zscaler Zero Trust Exchange: who is most feature complete? It’s not who you might expect

6/24/2022

This post positions Cloudflare One as a superior Zero Trust solution compared to Zscaler Zero Trust Exchange. It highlights Cloudflare's advantages in terms of its internet-native network platform, cloud-native service platform, broader adoption of SASE services, and extensive network on-ramps. Specific technical advantages discussed include a single, global Anycast network versus Zscaler's multiple distinct clouds, leading to a unified administrator experience and consistent service availability. Performance is also emphasized, with Cloudflare One demonstrating significantly higher throughput (6 Gbps) compared to Zscaler's 1 Gbps limit for GRE tunnels, enabling better support for high-bandwidth applications. Furthermore, Cloudflare's extensive interconnection peers and virtual backbone are presented as superior to Zscaler's edge-focused approach, enabling better transit and connectivity beyond the initial on-ramp.

How Cloudflare Security does Zero Trust

6/24/2022

This post details Cloudflare's internal implementation of Zero Trust principles, focusing on the evolution from legacy VPNs to Cloudflare Access, Gateway, and the integration of Area 1 Email Security. It highlights the use of FIDO2 security keys for enhanced authentication, the deployment of DNS filtering and HTTP filtering for office and remote users, and the implementation of Remote Browser Isolation. The post also mentions the upcoming integration of CASB functionality.

Kubectl with Cloudflare Zero Trust

6/24/2022

This post details the implementation of Cloudflare Zero Trust to secure access to Kubernetes API servers for internal engineering teams. It describes the transition from VPN-based access to a solution using Cloudflare Tunnels and Zero Trust agent's private network routing, enabling kubectl access without proxies or complex tunnel configurations. The post provides Terraform configuration examples for setting up Argo Tunnels, Tunnel Routes, and Cloudflare Gateway rules to disable HTTP inspection for Kubernetes API traffic, along with Kubernetes deployment configurations for cloudflared tunnel endpoints.

Decommissioning your VDI

6/24/2022

This post introduces Remote Browser Isolation (RBI) as a viable alternative to Virtual Desktop Infrastructure (VDI) for securing access to internal web applications. It details the challenges of VDI (high costs, poor user experience, complexity) and explains how RBI, specifically Cloudflare Browser Isolation, addresses these by running browser sessions on Cloudflare's global network. It highlights the benefits of RBI, including improved user experience through Network Vector Rendering (NVR), simplified administration, and lower, more predictable costs compared to VDI. A customer story from PensionBee illustrates the successful adoption of RBI to secure access to Salesforce.

Connect to private network services with Browser Isolation

6/24/2022

Introduced Browser Isolation with private network connectivity, enabling users to access private web services via isolated remote browsers. This feature integrates Cloudflare Access for authorization and Cloudflare Tunnels for secure connectivity, eliminating the need for endpoint software or virtual desktops. It allows for granular policy definition, data protection controls (clipboard, printing, file upload/download), and logging through the Secure Web Gateway.

Announcing Gateway + CASB

6/24/2022

Introduces the integration of API-driven Cloud Access Security Broker (CASB) with Secure Web Gateway. This integration allows users to create Gateway policies directly from CASB security findings, enabling rapid remediation of security issues within SaaS applications. For example, a CASB finding about unauthorized third-party apps in Google Workspace can be used to create a Gateway policy to block specific activities like uploads or downloads to that application.

A stronger bridge to Zero Trust

6/23/2022

This post announces enhancements to the Cloudflare One platform, focusing on making the migration from legacy network architectures to Zero Trust easier. Key contributions include: 1. Enhanced interoperability between various on-ramps (BYOIP, WARP client, CNI, GRE tunnel, IPsec tunnel) and off-ramps (Cloudflare Tunnel), enabling a fully composable and interoperable Zero Trust network. 2. Expanded support for additional IPsec configuration parameters, a new UI for managing Anycast IPsec and GRE tunnels, and Terraform provider support for network-as-code management. 3. Improved on-ramp integration with SD-WAN appliances, including new integration guides for devices like Cisco Viptela.

Cloudflare integrates with Microsoft Intune to give CISOs secure control across devices, applications, and corporate networks

6/23/2022

This post details the integration of Cloudflare's Zero Trust suite (Access and Gateway) with Microsoft Endpoint Manager (Intune). It enables the creation of Access and Gateway policies based on device compliance status reported by Intune via the Microsoft Graph API. The integration allows customers to add Microsoft Endpoint Manager as a device posture provider in the Cloudflare Zero Trust dashboard, requiring specific client credentials. Device posture checks can then be configured to evaluate criteria like 'Compliance State' from Intune, which can be used to grant or deny access to applications, networks, or sites. Future enhancements will involve correlating more fields from the Graph API.

Cloudflare Gateway dedicated egress and egress policies

6/23/2022

Introduces dedicated egress IPs for Cloudflare Gateway, allowing administrators to assign dedicated source IPs (IPv4 and IPv6) for egress traffic. This feature enables granular allowlisting policies based on identity, application, network, and geolocation attributes, addressing the need for static source IPs in legacy systems and facilitating the deprecation of VPNs. An upcoming egress IP policy builder in the Zero Trust dashboard will provide further flexibility in routing specific traffic through dedicated egress IPs.

Verify Apple devices with no installed software

6/22/2022

This post introduces the integration of Private Access Tokens (PATs) into Cloudflare Access. This allows for the verification of device health (e.g., OS version, jailbreak status) for Apple devices without requiring any client software installation. It leverages the Privacy Pass Protocol and works in conjunction with device manufacturers (Attester) and Cloudflare (Issuer) to provide anonymous, unforgeable tokens for access control decisions, enhancing Zero Trust security.

Introducing Private Network Discovery

6/22/2022

Introduced Private Network Discovery, a Zero Trust network discovery tool that passively catalogs resources and users accessing them within private networks connected to Cloudflare. This feature aims to simplify the migration to Zero Trust by providing visibility into network traffic, allowing users to translate discovered origins (IP, port, protocol) into Cloudflare Access applications and subsequently create Zero Trust security policies. The tool operates in an observability mode, tagging discovered applications as 'Unreviewed' and allowing manual status updates to 'Approved' or 'Unapproved'. Future enhancements will enable direct creation of Access applications from the report and integration into the Zero Trust policy builder.

Infinitely extensible Access policies

6/21/2022

Introduced the 'External Evaluation' rule option for Cloudflare Access policies, allowing for infinitely customizable policies by calling external APIs during policy evaluation. This enables the incorporation of any signal (e.g., mTLS certificate verification against a registry, IP address threat feeds) into Zero Trust access decisions, moving beyond user identity, device, and location. An open-source repository with example code for consuming Access claims and verifying signing keys is provided.

Zero Trust, SASE and SSE: foundational concepts for your next-generation network

6/19/2022

This post introduces and defines Zero Trust, Secure Access Service Edge (SASE), and Security Service Edge (SSE) as foundational concepts for next-generation enterprise network architecture. It details the components of SASE, including secure access functions (ZTNA, SWG, RBI, CASB, DLP), on-ramps, and the service edge, and positions Cloudflare One as a comprehensive SASE platform that delivers these capabilities.

Building many private virtual networks through Cloudflare Zero Trust

4/26/2022

This post introduces the capability to create multiple segregated virtual private networks over Cloudflare Zero Trust, specifically for Cloudflare WARP and Cloudflare Tunnel. This addresses the long-standing problem of overlapping IP address spaces (CIDRs) in enterprise networks, which previously prevented the setup of distinct private networks with identical IP ranges. The solution allows for logical segregation of these networks, enabling users to select specific virtual networks for routing traffic, thus overcoming the limitations of a single, unified private network.

Cloudflare’s investigation of the January 2022 Okta compromise

3/22/2022

This post details Cloudflare's rapid response and investigation into a potential compromise of Okta, their internal identity provider. It highlights the effectiveness of Cloudflare's internal Security Incident Response Team (SIRT), their proactive monitoring of logs (both internal and external), and their swift actions to suspend affected accounts and enforce password resets. The post also emphasizes the importance of multi-factor authentication (MFA), particularly hardware tokens, and Cloudflare's strategy of storing logs externally to ensure integrity even if the primary provider is compromised. It reinforces the company's commitment to a layered security approach for internal access management.

Zero Trust for SaaS: Deploying mTLS on custom hostnames

3/22/2022

This post introduces the ability for SaaS providers to enable mutual TLS (mTLS) authentication on their customers' domains through Cloudflare Access. This extends the zero-trust security model to scenarios where SaaS providers manage origins for domains they do not own, allowing them to enforce device-level authentication for sensitive API endpoints and provide per-customer isolation.

Domain Scoped Roles - Early Access

3/18/2022

Introduced Domain Scoped Roles and Domain Groups, enabling granular access control for user permissions to specific domains or groups of domains. This is powered by the new Bach permission system, which replaces the legacy RBAC system by allowing for policy-based authorization with more explicit and scoped permissions, moving beyond broad role assignments to fine-grained control over resources.

Securing Cloudflare Using Cloudflare

3/18/2022

This post details how Cloudflare's Security team actively uses and dogfoods Cloudflare's own products to enhance its security posture. Key contributions include: enforcing FIDO2 security keys as the only acceptable second factor for accessing systems protected by Cloudflare Access, thereby eliminating phishing risks associated with TOTP; deploying Cloudflare Gateway and WARP to secure remote workers and gain visibility into threats; utilizing Cloudflare Access with Purpose Justification for granular internal tooling access and compliance with data policies; and developing a Workers-based tool for scanning pull requests for security bugs. This demonstrates a deep integration of Cloudflare's Zero Trust solutions into its internal security operations.

Using Cloudflare One to Secure IoT devices

3/18/2022

This post details how Cloudflare One can be used to secure notoriously insecure IoT devices by isolating them without deploying them on a separate network. It describes a proof-of-concept where a camera's traffic is tunneled via Anycast GRE to the Cloudflare Global network, allowing for egress rules to be configured from the Cloudflare dashboard to prevent lateral movement. This architecture provides Layer 3 and above traffic control from a single dashboard, offering a serverless, infrastructure-less solution for isolating IoT devices.

Zero Trust client sessions

3/18/2022

Introduces the general availability of Zero Trust client-based sessions for Cloudflare's Zero Trust Network Access (ZTNA). This feature requires users to reauthenticate with their identity provider before accessing specific resources, with configurable reauthentication frequency based on resource sensitivity. It addresses the security risks associated with persistent sessions on user devices by enabling periodic session validation for TCP connections and UDP flows, complementing existing web-based application session controls.

Introducing SSH command logging

3/18/2022

This post introduces SSH command logging as a new capability within Cloudflare Zero Trust. It addresses the security risks associated with SSH, such as lack of visibility and potential for log tampering, by providing network-layer command logging and replay. It leverages the Secure Web Gateway and Cloudflare Short-Lived Certificates for authentication and secure proxying of SSH traffic across multiple jump-hosts.

Cloudflare partners with Microsoft to protect joint customers with a Global Zero Trust Network

3/18/2022

This post details the integration of Cloudflare Access and Cloudflare Tunnel with Microsoft Azure Active Directory to provide a Global Zero Trust Network for joint customers. It explains how Azure AD's identity and access management features (SSO, MFA, conditional access) can be leveraged with Cloudflare Access to enforce policy-oriented access to applications, acting as a VPN replacement. It also highlights how Cloudflare Tunnel can secure internal applications without exposing them to the internet. The post emphasizes the partnership's ability to secure both legacy on-premise applications and Azure-hosted applications, detailing the integration points and benefits for unified user access management and enhanced security posture.

A bridge to Zero Trust

3/18/2022

Introduces the ability to route traffic from WARP-enrolled devices to networks connected via IP-layer tunnels (GRE, IPsec, CNI). This enables private network access for TCP/UDP applications and provides a bridge from traditional VPN architecture to Zero Trust, allowing for gradual transitions. Leverages a new internal service called Hermes for sharing WARP session location data across the network to facilitate return traffic routing.

Managing Clouds - Cloudflare CASB and our not so secret plan for what’s next

3/18/2022

This post announces the upcoming beta launch of Cloudflare's API-driven Cloud Access Security Broker (CASB) product, which was introduced via the acquisition of Vectrix. It outlines the future development roadmap for CASB, focusing on three key areas: new integrations with SaaS applications (starting with Google Workspace and GitHub, followed by Zoom, Slack, Okta, Microsoft 365, and Salesforce), SaaS asset management for a unified view of data and user activity across services, and remediation guides with automated workflows for issue resolution. The post also highlights the integration of CASB with Cloudflare Gateway to manage shadow IT.

Clientless Web Isolation is now generally available

3/17/2022

This post announces the general availability of Clientless Web Isolation, a new capability that integrates Zero Trust Network Access (ZTNA) with browser isolation. It enables secure browsing on any device without endpoint software installation, offering use cases for team-wide secure browsing, deep linking into isolated sessions, integration with secure web gateways, and secure access to sensitive data on BYOD devices. This significantly enhances the zero-trust offering by providing a seamless and secure browsing experience.

Cloudflare acquires Vectrix to expand Zero Trust SaaS security

2/10/2022

This post announces the acquisition of Vectrix and its integration into Cloudflare's Zero Trust platform. It highlights Vectrix's capabilities in detecting security issues within SaaS applications through an API-driven CASB approach, addressing data security, user activity, misconfigurations, compliance, and shadow IT. The post details how this acquisition will enhance the Cloudflare Zero Trust platform by providing unified visibility and control over SaaS security, complementing existing products like Access, Gateway, and Browser Isolation, and offering a seamless management experience from a single control plane.

Adding a CASB to Cloudflare Zero Trust

2/10/2022

This post announces the acquisition of Vectrix, a Cloud Access Security Broker (CASB) company, and its integration into the Cloudflare Zero Trust product group. It details how CASB functionality will be a component of a comprehensive Zero Trust deployment, rather than a standalone solution. The post outlines Cloudflare's journey in building its Zero Trust platform, starting with Cloudflare Access for internal resource protection (replacing VPNs) and then Cloudflare Gateway for protecting users from the public internet. The integration of Vectrix addresses the third piece of the Zero Trust puzzle: controlling data and configurations within SaaS applications. Vectrix's technology scans SaaS applications for configuration anomalies, permission issues, and sharing risks, providing a unified control and audit point. The post emphasizes the customer-obsessed nature of both Cloudflare and Vectrix, and how Vectrix's technology delivers value faster by simplifying security scans for organizations of all sizes.

2021

Version and Stage Configuration Changes with HTTP Applications in Beta

12/11/2021

This post introduces HTTP Applications and Routing Rules, a significant evolution in how customers manage edge configurations. It addresses the limitations of the traditional 'Zone' model by enabling versioned configurations for specific use cases, independent of hostnames. The introduction of staging and production routing rules allows for safe, staged testing and deployment of changes to Cloudflare's global edge network, directly mitigating issues of manual configuration copying, configuration drift, and the risk of outages during updates.

All the Platform Improvements We’ve Made in 2021 to Make CIOs Lives Easier

12/11/2021

This post details several platform improvements made in 2021 relevant to account access management and security. Key contributions include: 1. Streamlined SSO onboarding by leveraging SaaS Applications in Cloudflare Access for easier setup and management within the Cloudflare for Teams dashboard. 2. Introduction of a beta program for Zone Scoped Roles, allowing users to be granted access to a subset of zones within an account, enabling finer-grained edit/read-only permissions. 3. Significant enhancements to Terraform support, including the addition of 10 new resources (bringing the total to 51), support for the ruleset engine (Transform Rules, Managed WAF Rulesets, Managed DDoS Rulesets), and a major update to cf-terraforming for generating Terraform configurations. 4. Improvements to Notifications and Alerts, including new notification types (DDoS Alerts, Firewall Alerts, Workers CPU, Origin 5XX Errors) and new webhook destinations (DataDog, Discord, OpsGenie, Splunk), along with API support for Alert History. 5. Expansion of logging capabilities to include Firewall Events, Gateway, Spectrum, and Audit logs, with support for S3-compatible storage and integrations with analytics providers, including R2.

Secure how your servers connect to the Internet today

12/10/2021

This post details how Cloudflare One's network firewall and DNS filtering capabilities can be used to secure outbound traffic from servers, directly addressing the risks exposed by the Log4j vulnerability. It introduces the concept of applying layered security controls, including DNS filtering, network firewalling (layers 3-5), and Secure Web Gateway (HTTP inspection), to protect infrastructure from both inbound and outbound threats. The post emphasizes the ease of deployment and the ability to create positive security models by allowing only specific destinations.

Cloudflare One helps optimize user connectivity to Microsoft 365

12/10/2021

This post announces Cloudflare's participation in the Microsoft 365 Networking Partner Program (NPP) and highlights how Cloudflare One optimizes user connectivity to Microsoft 365. It details the benefits of using Cloudflare's global network for direct and fast access to Microsoft 365 services, while simultaneously applying zero-trust security measures to other internet traffic. The post also explains how Cloudflare One can identify and secure SaaS application usage, providing visibility into Shadow IT and enabling administrators to enforce policies for data protection.

Cloudflare announces integrations with MDM companies

12/10/2021

This post announces new integrations with Mobile Device Management (MDM) vendors (Microsoft Intune, Ivanti, JumpCloud, Kandji, and Hexnode) to simplify the deployment and installation of the Cloudflare WARP agent. It provides technical details on WARP deployment parameters and command-line examples for silent installation, organization enrollment, and enabling/disabling mode switching. The post also explains the role of MDM/UEM tools in managing distributed device fleets and highlights the benefits of these partnerships for streamlining Zero Trust deployments.

Cloudflare Agent — Seamless Deployment at Scale

12/10/2021

This post announces significant advancements in the Cloudflare WARP agent, a core component of Cloudflare for Teams' zero-trust offering. Key contributions include achieving feature parity across all major platforms (Windows, macOS, ChromeOS, Linux, iOS, Android), enhancing deployment scalability with Rust-based shared daemon and BoringTun for reliable connections, and introducing flexible traffic routing options like domain-based and include-only split tunneling. It also highlights API and Terraform integration for automated deployment and configuration, and previews upcoming features like posture-only mode and user/group-specific settings.

Introducing Clientless Web Isolation

12/8/2021

This post introduces 'clientless web isolation' as a new on-ramp for Browser Isolation. It extends Cloudflare for Teams' Zero Trust capabilities by allowing users on any device, including unmanaged ones, to securely access any website, internal app, or SaaS application via a simple hyperlink. This eliminates the need for endpoint software installation or certificate configuration, streamlining access for contractors and BYOD scenarios. It integrates with Cloudflare Access for authentication and Cloudflare Gateway for security inspection, enhancing data protection controls and enabling secure investigation of high-risk links.

Extending Cloudflare’s Zero Trust platform to support UDP and Internal DNS

12/8/2021

This post introduces early access to UDP support and Internal DNS resolution within Cloudflare's Zero Trust platform. It details how Cloudflare Tunnel and WARP are extended to handle UDP traffic, enabling use cases like internal DNS resolvers and thick client applications, thereby providing a more complete alternative to traditional VPNs. The post also outlines the steps for connecting networks and users to this enhanced platform.

Zero Trust Private Networking Rules

12/8/2021

Introduced session control and login interval enforcement for Zero Trust private network access, allowing administrators to configure specific session durations and require re-authentication with multi-factor authentication. Also added UDP support for private network access, enabling the use of existing private DNS nameservers to map application hostnames on local domains.

Announcing Anycast IPsec: a new on-ramp to Cloudflare One

12/6/2021

This post introduces IPsec as a new network-layer on-ramp to Cloudflare One. It addresses the need for a universally supported and encrypted method to connect private networks to Cloudflare's global network, overcoming the limitations of traditional hub-and-spoke and mesh IPsec architectures. The implementation leverages Cloudflare's Anycast network and internal technologies like Cloudflare Tunnels to provide a scalable, resilient, and easier-to-manage IPsec solution integrated with the broader Cloudflare One suite.

Cloudflare One: One Year Later

12/6/2021

This post marks one year of Cloudflare One, highlighting its evolution into a comprehensive Zero Trust platform. It details the growth in traffic defended (5x), applications protected (over 192,000), and adoption by small teams. New features announced include IPsec Tunnels, improvements to Cloudflare Tunnel, network firewall features, and network performance acceleration. The post emphasizes the composable traffic filtering stack, identity-driven controls, and the integration of security with performance.

PII and Selective Logging controls for Cloudflare’s Zero Trust platform

12/6/2021

This post introduces role-based dashboard access for logging and analytics pages within Cloudflare Gateway, and selective logging of events. Administrators can now control the level of logging stored for DNS, Network, and HTTP components (Capture all, Capture only blocked, Don't capture), and can choose to redact all PII from logs by default. New granular roles for partitioning administrator access to Access or Gateway components will be available in January 2022.

Welcome to CIO Week and the future of corporate networks

12/5/2021

This post introduces Cloudflare One as a comprehensive Zero Trust Network-as-a-Service (NaaS) platform, marking a significant evolution in how Cloudflare addresses corporate network challenges. It contrasts traditional 'castle-and-moat' and 'smörgåsbord of point solutions' architectures with Cloudflare's vision for the future of corporate networks. The post details the shortcomings of legacy approaches, including security gaps, performance issues, high costs, and lack of agility, and positions Cloudflare One as the solution to these problems by enabling next-generation networks on Cloudflare's infrastructure.

Cloudflare for SaaS for All, now Generally Available!

10/22/2021

This post announces the general availability of Cloudflare for SaaS, a product designed to help SaaS providers offer fast, secure, and scalable infrastructure to their customers. It details the components of Cloudflare for SaaS, including Workers, SSL for SaaS, custom hostnames, WAF, Bot Management, and the global Anycast network. The post also highlights flexible, usage-based pricing for custom hostnames and showcases examples of companies (mmm.page, Lightfunnels, Ventrata) successfully using the platform, particularly leveraging Cloudflare Workers for performance and custom hostnames for domain and SSL management.

Zero Trust — Not a Buzzword

10/20/2021

This post analyzes a survey on Zero Trust adoption in Asia Pacific, highlighting the impact of the pandemic on IT security, current challenges, and the awareness and implementation of Zero Trust. It details country-specific findings for Australia, India, Japan, Malaysia, and Singapore, and identifies common themes such as rising cyberattacks, the permanence of flexible work, the scarcity of skilled IT security workers, and the need for Zero Trust education. It concludes by positioning Cloudflare's Zero Trust solutions (Cloudflare Access and Secure Web Gateway) as a means to address these challenges.

Tunnel: Cloudflare’s Newest Homeowner

10/18/2021

This post introduces Cloudflare Tunnel, a new capability that securely connects infrastructure to Cloudflare without opening firewall holes. It significantly enhances the management of these tunnels through a new UI in the Cloudflare for Teams Dashboard, providing visibility into status, routes, uptime, connectors, and `cloudflared` versions. The post details improvements to the onboarding experience with interactive guides and introduces management features for tunnel routes, connectors, and `cloudflared` replicas, all contributing to a more robust zero-trust security offering.

Announcing Access Temporary Authentication

10/4/2021

Introduced Temporary Authentication to Cloudflare Access, allowing for approval-based access to applications. This feature extends Purpose Justification by adding scoped permissions and second approval requirements from a predefined list of administrators. Access requests and approvals are logged for audit trails. The system leverages Cloudflare Workers for low-latency processing of access requests and approvals, enabling dynamic application of temporary access based on context like device or location.

Cloudflare for Offices

9/29/2021

This post introduces 'Cloudflare for Offices,' a new offering that extends Cloudflare's network and Zero Trust capabilities directly into office buildings. It simplifies branch office connectivity by eliminating legacy hardware like MPLS links, WANs, and VPNs, and provides a direct onramp to Cloudflare One. This enhances security posture, improves performance by bringing the edge closer to users within their workspaces, and offers a more flexible and cost-effective alternative to traditional office network infrastructure, aligning with the broader evolution of Cloudflare's Zero Trust and network access management solutions.

The Zero Trust platform built for speed

9/16/2021

This post details how Cloudflare for Teams, a Zero Trust platform, is built on Cloudflare's existing infrastructure to provide speed and security. It highlights the replacement of legacy private networks with Cloudflare's network, the use of Cloudflare Workers for instant Zero Trust decisions, the DNS filtering capabilities powered by 1.1.1.1 technology, and the performance advantages of Cloudflare's Secure Web Gateway and Browser Isolation. It also explains how Cloudflare Tunnel and Argo Smart Routing contribute to faster application performance and how the global network infrastructure ensures low latency.

What’s new with Cloudflare for SaaS?

9/7/2021

This post announces significant enhancements to Cloudflare for SaaS and SSL for SaaS for Enterprise customers. Key additions include Apex Proxying to allow customers to use their zone apex with Cloudflare, Bring Your Own IPs (BYOIP) for greater IP allocation control, custom origin support to route different customers to different origins, wildcard support for custom hostnames to cover subdomains, CSR support and custom cert uploads for flexible TLS certificate management, and custom metadata with Workers for per-hostname configuration. The post also teases upcoming analytics features for customer traffic visibility.

Data protection controls with Cloudflare Browser Isolation

8/20/2021

Introduces granular data protection controls within Cloudflare Browser Isolation, allowing administrators to define Zero Trust policies to control copy, paste, and print actions on web-based applications. This feature executes all website code in a remote browser, sending only lightweight vector instructions to the endpoint, thus preventing data exfiltration and malware execution. The controls can be configured per-rule with options for application, hostname, and user identity.

Announcing Tenant Control in Cloudflare Gateway

8/20/2021

This post introduces 'Tenant Control' in Cloudflare Gateway, a new feature that allows organizations to enforce rules for employees logging into corporate versions of SaaS applications. It enables administrators to prevent users from logging into personal or consumer instances of applications and ensures corporate data stays within controlled tenants by leveraging specific headers recognized by SaaS applications. This complements existing Gateway features by adding a layer of control over application tenant access.

Zero Trust controls for your SaaS applications

8/18/2021

This post introduces the ability to apply Zero Trust controls to SaaS applications by integrating Cloudflare Access with SAML authentication flows. It leverages Cloudflare Workers to convert JWTs into SAML assertions, enabling the enforcement of identity-aware and context-driven rules (like device posture and country of login) for SaaS applications. It also introduces a new rule type in Cloudflare Access that requires Cloudflare Gateway for users logging into SaaS applications, ensuring traffic is filtered through Gateway-protected devices.

Capturing Purpose Justification in Cloudflare Access

8/18/2021

Introduced the ability for Cloudflare for Teams administrators to prompt users to enter a justification for accessing an application prior to login. This feature can be added to any existing or new Access application with two clicks, allowing for logging and review of justifications, adding security layers, customizing modal text, and helping meet regulatory requirements for data access control.

6 New Ways to Validate Device Posture

8/17/2021

This post introduces six new device posture attributes that can be used to build granular Zero Trust rules within Cloudflare for Teams: Application Check, File Check, Disk Encryption, OS Version, Firewall, and Domain Joined. It details how these attributes can be configured in the Cloudflare for Teams dashboard and integrated into Access policies to enhance security beyond identity verification. The post also reiterates the Zero Trust model and the role of Cloudflare Tunnel in securing internal resources.

Introducing Shadow IT Discovery

8/16/2021

This post introduces 'Shadow IT Discovery' to Cloudflare for Teams, allowing administrators to detect and block unapproved SaaS applications. It leverages Cloudflare Gateway's activity logs to identify applications used by an organization, categorizes them, and allows administrators to review and designate them as approved or unapproved. The feature also provides insights into application usage for license optimization and highlights applications secured by Cloudflare Access.

Browser VNC with Zero Trust Rules

6/24/2021

This post introduces Browser VNC, a new capability within Cloudflare for Teams that allows users to access VNC clients directly through a web browser. This feature leverages Cloudflare Workers for edge rendering and Cloudflare Access for Zero Trust controls, providing a secure, clientless way to connect to graphical interfaces on remote servers, enhancing security and manageability compared to traditional VNC deployments.

Announcing WARP for Linux and Proxy Mode

6/17/2021

This post announces the expansion of Cloudflare WARP to Linux and introduces a new 'proxy mode' for all desktop platforms. WARP for Linux brings the secure and fast internet experience to a new operating system, leveraging a shared Rust codebase for cross-platform consistency. The proxy mode allows users to selectively route application traffic through WARP, offering more granular control than the previous all-or-nothing approach, and complements existing Cloudflare for Teams features like Secure Web Gateway.

Introducing Zero Trust Private Networking

6/10/2021

This post introduces Zero Trust Private Networking, enabling identity-aware network policies for traffic within private networks. It details the deprecation of the castle-and-moat model and the limitations of traditional VPNs. The solution involves using `cloudflared` to create secure TCP tunnels to Cloudflare's edge and WARP clients for user traffic. Network-based policies are enforced at Layer 4, allowing matching based on source/destination IP/port, and can be combined with identity policies for granular access control to private resources.

Network-based policies in Cloudflare Gateway

6/4/2021

Introduced network-based policies in Cloudflare Gateway, extending Zero Trust controls to non-HTTP traffic. This allows administrators to define policies based on IP address, port, and user identity for TCP traffic originating from WARP-enabled devices. The system leverages the WireGuard tunnel and the Wirefilter execution engine for efficient policy enforcement at the edge.

Highly available and highly scalable Cloudflare tunnels

5/12/2021

This post introduces the ability to run multiple instances of `cloudflared` for a single Cloudflare Tunnel. This significantly enhances the reliability and scalability of tunnels by enabling graceful restarts, elastic auto-scaling, and easier integration with container orchestration platforms like Kubernetes. It addresses a key user request for scaling `cloudflared` to match the scalability of other system components.

SSHing to my Raspberry Pi 400 from a browser, with Cloudflare Tunnel and Auditable Terminal

4/27/2021

This post details the practical application of Cloudflare Tunnel and Auditable Terminal to securely access a Raspberry Pi 400 from a browser, without opening firewall ports. It highlights the integration of Cloudflare for Teams for authentication and access control, demonstrating a real-world use case for zero-trust access to internal resources.

Start building your own private network on Cloudflare today

4/20/2021

Introduced a new capability for creating private networks on Cloudflare's edge, combining IP-level connectivity with Zero Trust controls. This feature utilizes Cloudflare Tunnel (formerly Argo Tunnel) with the `cloudflared` connector to establish outbound-only TCP connections from data centers/cloud environments to Cloudflare's edge. On the client side, the Cloudflare WARP agent authenticates users and creates a Wireguard tunnel to Cloudflare's network, routing traffic to the configured private IP ranges. This enables seamless access to non-web applications without requiring additional client software beyond WARP, and offers enhanced security through DNS filtering and Secure Web Gateway functionalities.

A Boring Announcement: Free Tunnels for Everyone

4/15/2021

This post announces the renaming of Argo Tunnel to Cloudflare Tunnel and makes its core functionality—secure, outbound-only connections—free for everyone. It details the evolution of Tunnel from a solution for connecting origins to Cloudflare without public IPs, to enhancing security by enforcing Zero Trust policies and eliminating inbound firewall rules. Key improvements highlighted include enhanced stability through removal of internal dependencies and migration to Cloudflare's edge load balancer (Unimog), and increased persistence with the introduction of Named Tunnels. The post also provides examples of how to use Tunnel for connecting applications and building private networks.

A Zero Trust terminal in your web browser

4/15/2021

Introduced a browser-based terminal for accessing non-HTTP resources (starting with SSH) via Cloudflare's Zero Trust platform. This enables single-click access after SSO authentication, enforces Zero Trust rules at the edge, accelerates connections through Cloudflare's network, and provides auditable session logging without requiring client-side configuration or agents. The solution involves a lightweight daemon (`cloudflared`) connecting the on-premise/cloud service to Cloudflare's edge, and rendering the session in the user's browser.

The Teams Dashboard: A New Place to Call Home

4/2/2021

This post introduces the 'Home' feature within the Cloudflare for Teams Dashboard. It describes the design principles (transparency, warmth, guidance, adaptiveness) and implementation details behind creating an adaptive and informative landing page. The 'Home' page consolidates network and application traffic views, user signals, and provides direct links to plans and other resources. The design emphasizes approachability through conversational copy and user-centric loading animations. Guidance is provided through links to Radar, Help pages, and quick-start guides, with empty states designed to prompt user action. The modular approach ensures future scalability and the integration of new features.

Build Zero Trust rules with managed devices

3/30/2021

Introduced the ability to build Zero Trust rules in Cloudflare Access that enforce connections only from managed devices. This is achieved by importing a list of corporate device serial numbers and using the Cloudflare for Teams agent to verify device ownership against this list, preventing access from unmanaged devices.

Inside Cloudflare: Preventing Account Takeovers

3/30/2021

This post details how Cloudflare's Security Team uses Cloudflare products (Gateway, Access) and internal engineering to prevent account takeovers on its own applications. It highlights the use of FIDO2 hardware security tokens, managed corporate device policies in Access, and custom detections built on Gateway/Access logs to protect against various account takeover techniques like credential stuffing, phishing, and SIM-swapping. It also discusses the importance of influencing the product roadmap based on internal security needs.

Using Cloudflare for Data Loss Prevention

3/24/2021

This post details how Cloudflare's existing account access management and security tools, specifically Cloudflare Access, Gateway, and Browser Isolation, can be leveraged for Data Loss Prevention (DLP). It highlights the importance of addressing both internal and external threats, including accidental breaches and compromised accounts, by implementing granular access controls, securing endpoints, and protecting APIs. The post emphasizes the role of Zero Trust principles in preventing data exfiltration and improving incident response.

New device security partnerships for Cloudflare One

3/23/2021

Introduced new integrations with VMware Carbon Black, CrowdStrike, and SentinelOne to complement the existing Tanium integration for Cloudflare for Teams. These integrations enable the configuration of access policies based on device security signals (e.g., OS version, patch status, disk encryption, anti-malware status) provided by endpoint security vendors. For Tanium, no additional software is required on the user's machine, only configuration in the Teams Dashboard and Tanium instance. For CrowdStrike, SentinelOne, and VMware Carbon Black, the WARP client must be deployed, and the integration is configured via the 'Device posture' tab in the Teams Dashboard. These device posture checks can be layered with MFA and User Identity for enhanced security.

The Teams Dashboard: The Design Story

3/18/2021

This post details the design story and evolution of the Cloudflare for Teams product, focusing on the integration of Access and Gateway. It highlights the transition from a site-based model to an account-based platform, the design iterations to complement existing security technologies, and the expansion of capabilities including L7 inspection, the Teams WARP client, and SaaS application support. The post emphasizes the importance of designing with scale in mind and fostering collaboration between Product, Design, and Engineering for efficient and long-term product growth.

Control web applications with two-clicks in Cloudflare Gateway

3/9/2021

This post introduces a significant enhancement to Cloudflare Gateway's L7 firewall by enabling administrators to create firewall rules based on 'Applications' and 'App Types'. This dramatically simplifies the management of cloud application access by abstracting away the complexity of hundreds of individual hostnames and IP addresses associated with popular services like Salesforce and Microsoft Office 365. It allows for policy creation with just a few clicks, reducing manual effort and ensuring policies remain comprehensive and up-to-date.

The Teams Dashboard: Behind the Scenes

3/1/2021

This post details the redesign of the Cloudflare for Teams dashboard onboarding experience, addressing the 'duplex problem' of siloed Access and Gateway onboarding. The new approach, led by Design, focuses on a single, unified onboarding flow with three simple steps (Welcome, Create Team Name, Pick Plan) followed by a 'Quick Start' guide and 'Starter Packs' to automate configuration and accelerate time-to-value. This represents a shift from a 'feature shop' mentality to a more intentional, user-centric design process.

2020

Integrating Cloudflare Gateway and Access

12/23/2020

This post introduces the integration of Cloudflare Gateway with Cloudflare Access policies. It enables administrators to enforce that all user traffic to applications must be filtered by Cloudflare Gateway, ensuring threat filtering, file upload/download restrictions, and content category blocking. It also allows for the restriction of access to applications based on whether Cloudflare Gateway is running on the user's device, enhancing log integrity and enabling data control rules within SaaS applications by enforcing Gateway usage during login.

Configure identity-based policies in Cloudflare Gateway

12/21/2020

This post introduces identity-based policies to Cloudflare Gateway, enabling administrators to create fine-grained rules based on user identity and group affiliation. It also enhances user-level visibility in activity logs for auditing and security investigations. The post highlights the integration with Cloudflare Access and various identity providers, and introduces the concept of using Cloudflare Isolated Browser for enhanced security for specific users.

Announcing Workplace Records for Cloudflare for Teams

12/10/2020

Introduced Workplace Records, a feature for Cloudflare for Teams that leverages Access and Gateway logs to determine the country from which employees are working. This data helps finance, legal, and HR departments with payroll tax obligations and regional compliance. The feature provides country-level resolution without capturing specific addresses and can be used to enforce country-specific access rules in Cloudflare Access.

Many services, one cloudflared

11/19/2020

This post introduces a major enhancement to Argo Tunnel by enabling a single instance of `cloudflared` to proxy an unlimited number of services. This is achieved through the introduction of 'Named Tunnels' and a new 'ingress rules' configuration system. These features allow users to define how traffic is routed from the Cloudflare edge to specific local services based on hostname and path, significantly reducing resource consumption and management overhead for customers with large deployments. It also introduces validation tools for ingress rules and per-rule configuration options for origin requests.

How our network powers Cloudflare One

10/16/2020

This post introduces Cloudflare One as a unified approach to enterprise networking and security, directly leveraging Cloudflare's existing global network infrastructure. It details how the network's distribution (data centers in over 200 cities, 100 countries, 42 Tbps capacity), scalability (every product on every server, commodity hardware, software-based functions), connectivity (8,800+ network interconnections, CNI, private backbone), and insight (attack intelligence, smart routing) are fundamental to delivering Cloudflare One's value proposition to organizations. It highlights how Cloudflare One extends these network advantages to protect and manage enterprise data centers, offices, and devices.

How small businesses can start using Cloudflare One today

10/15/2020

This post details how small businesses can start using Cloudflare One, a network-as-a-service solution, by implementing DNS Filtering, WARP+ for secure remote worker connections, Cloudflare Access to replace VPNs, and a Secure Web Gateway for threat and data loss prevention. It highlights the availability of a free plan for up to 50 users, making Zero Trust security accessible to smaller organizations. The post provides step-by-step instructions and links to relevant documentation for deploying these features.

Introducing Cloudflare Browser Isolation beta

10/15/2020

This post introduces Cloudflare Browser Isolation as a beta feature, representing a new approach to secure web browsing. It addresses the inherent risks of web browsers by running them in sandboxed, remote environments within Cloudflare's global network. This complements existing Cloudflare for Teams offerings like Cloudflare Access and Gateway by providing a solution for unknown and unforeseeable threats, effectively extending the zero-trust perimeter to the browser itself and improving the user experience compared to traditional browser isolation methods.

Introducing WARP for Desktop and Cloudflare for Teams

10/14/2020

This post introduces the general availability of Cloudflare WARP for desktop users and its integration with Cloudflare Gateway for enterprise security teams. It details how the WARP client, powered by BoringTun (Cloudflare's WireGuard implementation), encrypts all device traffic and routes it to Cloudflare's edge. For businesses, WARP integrates with Cloudflare Gateway to enforce web filtering and security policies for remote workers without backhauling traffic. Key features highlighted include end-to-end encryption, WARP+ speed benefits, user-based policies, and device/user auditing capabilities. Deployment options for organizations are also outlined.

Cloudflare Gateway now protects teams, wherever they are

10/14/2020

This post announces significant enhancements to Cloudflare Gateway, transforming it from a secure DNS filtering solution into a Secure Web Gateway with L7 filtering capabilities. It integrates with the Cloudflare WARP desktop client to provide enterprise-level security for distributed workforces, addressing the challenges of remote work and increased security threats. The post details new filtering criteria for HTTP traffic, including URL, file type, and content category, and outlines future plans for L4 filtering and identity-based policies.

Zero Trust For Everyone

10/13/2020

Introduced Cloudflare for Teams, a Zero Trust solution comprising Cloudflare Access (for inbound connections) and Cloudflare Gateway (for outbound connections). Launched a Free plan for Cloudflare for Teams, offering Zero Trust security features for up to 50 users, including DNS content and security filtering with 24-hour log retention. Also introduced standalone Cloudflare Access and Cloudflare Gateway plans with enhanced features and pricing, and a bundled Teams Standard plan.

Cloudflare Access: now for SaaS apps, too

10/13/2020

This post introduces the capability to protect SaaS applications using Cloudflare Access by integrating with their SAML identity providers. It details how Cloudflare Access acts as a SAML identity provider, converting JWTs generated from various identity sources (SSO, MFA, device posture) into SAML assertions for SaaS applications. Cloudflare Workers are used to perform this JWT to SAML conversion at the edge, maintaining performance and availability.

Introducing Cloudflare One

10/12/2020

This post introduces Cloudflare One, a comprehensive SASE solution that integrates Cloudflare's network services with leading identity management (Okta, Ping Identity, OneLogin) and device integrity (CrowdStrike, VMware Carbon Black, SentinelOne, Tanium) providers. It marks a significant evolution in Cloudflare's zero-trust networking strategy, moving beyond traditional network security to a unified platform for secure, optimized global networking, replacing legacy appliance-based approaches with a cloud-native solution.

What is Cloudflare One?

10/12/2020

This post introduces Cloudflare One, a comprehensive vision for corporate security and networking that integrates existing and new products like WARP, Gateway, Magic Transit, Magic Firewall, and Cloudflare Access. It explicitly positions Cloudflare One as a solution to the challenges of modern enterprise networking and security, moving beyond the traditional perimeter model to a Zero Trust architecture. It highlights the combination of networking and security controls, flexible data planes, and a unified control plane for managing traffic, identity, and security policies.

What Happens When The Whole World Goes Remote? Not To Worry, We Were Built For This

9/14/2020

This post details the successful migration of a telemedicine company's internal applications to Cloudflare Access to support a sudden shift to remote work. It highlights how Cloudflare Access, integrated with existing Cloudflare infrastructure (Zone lockdown, WAF, CDN), enabled secure, VPN-less access for over 700 users within 15 minutes. The narrative emphasizes the role of Customer Success Managers (CSMs) and subject matter experts in facilitating this rapid adoption and the customer's prior positive experience with Cloudflare's infrastructure products.

Two clicks to add region-based Zero Trust compliance

9/1/2020

This post introduces region-based Zero Trust compliance rules within Cloudflare Access. Administrators can now create policies that require users to connect from specific countries or exclude certain countries from accessing applications. This feature leverages existing identity provider configurations and requires no additional client-side software. The post details how to configure these rules using include, require, and exclude operators, and how to combine them with other Zero Trust signals for comprehensive policy enforcement. It also highlights the ability to audit login origins via exported logs.

Improving the Wrangler Startup Experience

8/25/2020

This post introduces `wrangler login`, a new authentication flow for the Wrangler CLI tool that simplifies the developer experience for Cloudflare Workers. It replaces the manual API token creation process with a direct Cloudflare login, leveraging a secure token transfer mechanism with asymmetric RSA encryption to protect user credentials. This significantly improves the initial setup and onboarding for developers using Cloudflare's serverless platform.

Require hard key auth with Cloudflare Access

8/20/2020

This post details the implementation of a new Cloudflare Access rule that enforces the use of hardware security keys (WebAuthn/FIDO2) for accessing internal administrative panels. This is achieved by leveraging the `amr` (Authentication Method Reference) field within the JSON Web Token (JWT) generated by the identity provider. By configuring Cloudflare Access to require specific `amr` values, the system can reject logins that use less secure MFA fallbacks like TOTP, even if the identity provider allows them. This directly addresses the risk of phishing attacks targeting administrative panels.

Protecting Remote Desktops at Scale with Cloudflare Access

8/7/2020

This post introduces Argo Tunnel RDP Bastion mode, a significant enhancement to Cloudflare Access's ability to protect remote desktop protocol (RDP) connections at scale. It addresses the deployment challenges of installing individual daemons on every RDP server by allowing a single cloudflared instance to act as a jump-host, proxying requests to multiple internal servers. This simplifies the process for organizations managing large fleets of remote desktops, enabling identity-driven access control for RDP and other protocols like SSH and FTP, thereby strengthening security and manageability in remote work scenarios.

Tanium’s endpoint security meets Cloudflare for Teams

5/27/2020

This post introduces the integration of Tanium's endpoint management platform with Cloudflare for Teams, specifically Cloudflare Access. This integration allows administrators to enforce device posture as a condition for accessing applications. When a user attempts to connect, Cloudflare Access will now query Tanium to verify the health and managed status of the device, in addition to checking user credentials. This provides a second layer of assurance in a zero-trust model, enhancing security by ensuring that only healthy, managed devices can access corporate resources.

Releasing Cloudflare Access’ most requested feature

5/22/2020

Introduced the ability to configure identity options on individual applications within Cloudflare Access, allowing administrators to scope specific SSO providers to specific applications. This addresses the scalability issue of listing all SSO providers for every application and reduces user confusion by only presenting relevant options. The feature is configurable via the Cloudflare for Teams UI and can automatically skip the login page if only one provider is enabled for an application.

Resolve internal hostnames with Cloudflare for Teams

5/19/2020

Introduced domain override functionality within Cloudflare Gateway. This feature allows administrators to configure rules that redirect traffic destined for specific hostnames to alternative IP addresses, enabling seamless access to internal resources while maintaining security for public internet traffic. This complements existing secure DNS filtering and facilitates the transition to zero-trust architectures by allowing organizations to manage internal and external traffic routing through a single platform.

DeepLinks and ScrollAnchor

5/18/2020

This post introduces and details the implementation of 'DeepLinks' and 'ScrollAnchor' within the Cloudflare Dashboard. It explains how deep linking enhances user experience by allowing direct navigation to specific resources, improving troubleshooting documentation, and enabling dynamic resolution of account and zone contexts. The post also describes the 'ScrollAnchor' component for scrolling to specific content on a page, and the underlying resolver mechanism that handles dynamic value resolution and user interaction when necessary.

Setting up Cloudflare for Teams as a Start-Up Business

5/5/2020

This post details how the acquired S2 Systems team, previously struggling with a complex, six-month build for managing access to their Remote Browser Isolation (RBI) platform, adopted Cloudflare Access. They replaced their custom solution with Access, reducing the time to grant customer access from six months to minutes. Additionally, they implemented Cloudflare Gateway to secure their office network, replacing a problematic multi-firewall setup with a 10-minute deployment. The post also describes using Cloudflare Access and `cloudflared` to securely connect developers to their powerful development machines remotely, replacing a difficult-to-use VPN appliance with a seamless SSO-based workflow.

A single dashboard for Cloudflare for Teams

5/4/2020

This post details the migration of Cloudflare Access UI into the unified Cloudflare for Teams dashboard. It addresses user confusion stemming from the previous design where account-level configurations (like SSO integration and logs) were displayed within site-specific pages. The new dashboard separates account-level settings from site-specific rules, providing a clearer user experience and a foundation for future integrated features across Access and Gateway.

Releasing kubectl support in Access

4/27/2020

This post introduces the integration of Cloudflare Access and Argo Tunnel to secure kubectl access to Kubernetes clusters. It details how Argo Tunnel establishes a secure connection from the cluster to Cloudflare's network and how Cloudflare Access enforces identity checks via SSO before allowing kubectl commands to reach the Kubernetes API server. It also explains the client-side setup using `cloudflared` to create a SOCKS proxy for kubectl commands and the lessons learned from dogfooding this feature.

Deploying Gateway using a Raspberry Pi, DNS over HTTPS and Pi-hole

4/21/2020

This post details the deployment of Cloudflare Gateway for home networks using a Raspberry Pi, Pi-hole, and DNS over HTTPS (DoH). It highlights how Gateway can be used by individuals and small businesses to protect their devices and networks from security threats, extending the reach of Cloudflare for Teams beyond traditional corporate environments. The post provides a technical walkthrough of setting up Gateway on a Raspberry Pi with Pi-hole and dnscrypt-proxy, and also explains how to configure DoH in browsers like Firefox and Chromium-based browsers.

Time-Based One-Time Passwords for Phone Support

4/17/2020

This post introduces Time-Based One-Time Passwords (TOTP) for Enterprise customer phone support. It details how customers can generate single-use tokens from the Cloudflare dashboard or use a 2FA app to authenticate themselves over the phone, enhancing account security and enabling greater support without relying solely on support tickets. The post also explains the underlying TOTP mechanism (RFC 6238) and Cloudflare's specific implementation for both dashboard-generated tokens and authenticator app integration, including a mechanism to validate tokens from the previous time step to account for network delays.

Cloudflare now supports security keys with Web Authentication (WebAuthn)!

4/1/2020

This post introduces support for security keys using the Web Authentication (WebAuthn) protocol as a two-factor authentication (2FA) method for all Cloudflare users. It highlights WebAuthn's advantages over other 2FA methods, such as its resistance to phishing, SIM swapping, and its improved user experience, by leveraging public key cryptography and domain-scoping for enhanced security.

Dogfooding from Home: How Cloudflare Built our Cloud VPN Replacement

3/28/2020

This post details the internal development and adoption of Cloudflare Access as a replacement for traditional VPNs. It highlights the motivation for building Access (dogfooding), its evolution from EdgeAuth to supporting various protocols (HTTP, Git), and its benefits for a global team (edge authentication, performance, reliability). It also emphasizes the zero-trust model, granular permissions via Access Groups, extensive logging, and simplified onboarding/offboarding processes.

Migrating from VPN to Access

3/28/2020

This post details the migration from a traditional VPN-based security model to Cloudflare's Access zero-trust proxy for internal applications. It highlights the challenges of VPN management and the benefits of Access for protecting HTTP-based services. For non-HTTP services like git+ssh, Access with SSH support was introduced. During the transition, Spectrum was used to protect the existing VPN infrastructure from DDoS attacks and improve performance, addressing MTU issues by setting it to 1420 for UDP-based VPN traffic.

Using Cloudflare Gateway to Stay Productive (and turn off distractions) While Working Remotely

3/19/2020

This post introduces Cloudflare Gateway as a tool for users to block distracting websites and improve productivity while working remotely. It details the setup process, including configuring locations, changing router DNS settings to use Cloudflare Gateway's resolvers, and creating policies to block specific domains or content categories. It also explains how to test the blocking functionality using DNS lookups and browser redirects.

Open sourcing our Sentry SSO plugin

3/11/2020

This post introduces an open-source plugin for Cloudflare Access that enables single sign-on (SSO) with Sentry, a popular error tracking and diagnostics tool. The plugin leverages JSON Web Tokens (JWTs) signed by Cloudflare Access to authenticate users to Sentry without requiring a second login. This reduces friction for end-users and simplifies credential management for administrators. The post also details the structure of JWTs and provides guidance on building similar plugins for other applications.

How Replicated Developers Develop Remotely

3/10/2020

This post details how Replicated uses Cloudflare Access and Argo Tunnel to provide secure, VPN-less access to remote development environments. It describes the architecture where cloud-based instances are accessed via Argo Tunnels secured by Cloudflare Access policies, which leverage BeyondCorp-style authentication using Google credentials. This approach eliminates the need for public IPs or open ports, simplifies credential management, and improves developer productivity by reducing local environment troubleshooting.

How Cloudflare keeps employees productive from any location

3/6/2020

This post details the internal development and rollout of Cloudflare Access, a system designed to replace traditional corporate VPNs. It highlights the technical implementation of Access running on Cloudflare Workers, acting as an identity proxy at each data center for scalability. The post describes how Access integrates with identity providers for authentication, uses Argo Tunnel for secure outbound connections, and enables features like one-click SSO for internal applications (specifically the Atlassian suite), SSH access to resources, an Access App Launch for simplified onboarding, and per-request logging for security auditing. It also mentions the free offering of Cloudflare for Teams during the COVID-19 emergency.

Seamless remote work with Cloudflare for Teams

2/24/2020

This post introduces Cloudflare Access as a replacement for corporate VPNs, enabling seamless remote work by securing self-hosted applications with identity-based policies. It details how Access integrates with identity providers, uses Argo Tunnel for secure outbound connections, and supports RDP and SSH workflows without requiring client installations. The post also highlights logging capabilities for compliance and an application launchpad for user onboarding.

Using your devices as the key to your apps

2/21/2020

This post details the implementation of mutual TLS (mTLS) authentication for a personal web application using Cloudflare Access and `cfssl`. It covers generating a Root CA, creating client certificates, configuring an Access policy to enforce mTLS, and placing the client certificate on an iPhone. This demonstrates a method for device-level authentication beyond traditional identity providers.

Multi-SSO and Cloudflare Access: Adding LinkedIn and GitHub Teams

2/20/2020

Introduced the ability to add LinkedIn and GitHub Teams as login methods within Cloudflare Access, expanding Multi-SSO capabilities. This allows organizations to integrate external identity providers alongside corporate SSO, simplifying the onboarding of contractors, partners, and freelancers. The post also highlights the benefits for mergers and acquisitions and zero-downtime SSO migrations, emphasizing the generation of standardized JWTs for authorization and the Access App Launch for a unified application portal.

Announcing the Cloudflare Access App Launch

1/16/2020

Introduced the Access App Launch portal, a new feature for Cloudflare Access. This portal provides end-users with a dashboard to access all applications protected by Access with a single click. It leverages existing Access policies and identity provider integrations to display only authorized applications per user. The feature also enhances defense-in-depth against phishing attacks by providing a centralized, trusted entry point for internal applications.

Helping mitigate the Citrix NetScaler CVE with Cloudflare Access

1/12/2020

This post details how Cloudflare Access can be used as an interim mitigation strategy for the Citrix NetScaler CVE. It highlights how Access acts as an identity proxy to protect the administrator portal and other resources managed by the ADC, preventing unauthenticated access and providing an additional layer of security alongside Citrix's recommended mitigation steps and future patches. It also emphasizes the use of Argo Tunnel for secure outbound connections and the integration with WAF rules for comprehensive protection.

Introducing Cloudflare for Teams

1/7/2020

This post introduces Cloudflare for Teams, a suite of tools designed to address the 'other half' of IT security challenges: securing internal users and their access to resources. It details two core products: Cloudflare Access (a modern VPN alternative) and Cloudflare Gateway (a next-generation firewall). The post explains the limitations of the traditional 'castle and moat' security model in the context of cloud, SaaS, and mobile workforces, and positions Cloudflare for Teams as a Zero Trust solution built on Cloudflare's global network and threat intelligence. It highlights the integration with existing products like 1.1.1.1 and WARP, and mentions partnerships with endpoint security, SIEM, and identity providers.

Security on the Internet with Cloudflare for Teams

1/7/2020

This post introduces Cloudflare for Teams, a new platform that extends Cloudflare's network and security expertise to protect teams, devices, and data. It comprises two products: Cloudflare Access, which replaces corporate VPNs by securing internally managed applications through Cloudflare's network and enforcing identity-based policies globally, and Cloudflare Gateway, which secures users from Internet threats and corporate data. The post details the legacy problems of corporate security (securing internal applications, threats on the Internet, and securing data) and how Cloudflare for Teams addresses them by leveraging Cloudflare's global network, Argo Tunnel for secure outbound connections, and identity provider integration for authentication.

2019

Log every request to corporate apps, no code changes required

11/17/2019

This post introduces per-request logging for Cloudflare Access, enabling detailed auditing of every request made to internal applications protected by Access. Previously, logging only captured initial authentication events. This new capability allows security teams to track the full user session, providing crucial data for incident response, compromised account investigations, and compliance audits. The logs are standardized and can be exported to SIEMs via Cloudflare Logpush.

Public keys are not enough for SSH security

10/25/2019

This post introduces the replacement of static SSH keys with short-lived certificates for infrastructure access, integrated with Cloudflare Access. It details how Cloudflare Access, Argo Tunnel, and Workers are used to achieve this by leveraging identity providers for SSO, generating short-lived certificates, and proxying SSH traffic through Cloudflare's network. The end-user experience is described as transparent, requiring installation of the `cloudflared` daemon and an update to the SSH config file.

Terraforming Cloudflare: in quest of the optimal setup

10/9/2019

This post introduces the adoption of Infrastructure-as-Code (IaC) practices for managing Cloudflare configurations, specifically focusing on access rules, zone settings, and account members. It details the use of Terraform and Terragrunt to achieve declarative, version-controlled management, enabling modularity, reusability, and dynamic resource creation through static, parameterized, and dynamic resource implementations. This significantly enhances the manageability and consistency of Cloudflare's account access and permissions across multiple domains and environments.

Talk Transcript: How Cloudflare Thinks About Security

10/8/2019

This post details Cloudflare's internal approach to security, emphasizing a strong reporting culture, the use of HackerOne for external vulnerability disclosure, and the development of internal identity and authentication solutions like Cloudflare Access. It highlights the transition from a chaotic system of multiple logins to a unified, secure access control mechanism, including the rollout of Yubikeys and TOTP for all employees. The post also touches on the importance of transparency in security incidents (like Cloudbleed) and the shift towards memory-safe languages (Go and Rust) in software development.

Announcing the General Availability of API Tokens

8/30/2019

This post introduces the general availability of API Tokens, a new feature that allows for more secure and scalable interaction with the Cloudflare API. API Tokens enable scoping by Cloudflare resource (accounts and zones) and by permission, adhering to the principle of least privilege. The post details how to create and use these tokens, including examples with templates and curl requests, and highlights their integration with existing tools like the Terraform provider and Cloudflare-Go library. It also recommends migrating from Global API Keys to API Tokens for enhanced security.

Securing infrastructure at scale with Cloudflare Access

7/19/2019

Introduced wildcard subdomain policies for Cloudflare Access, allowing administrators to apply a single access policy to all subdomains of a given domain. This significantly scales access control for internal applications and infrastructure, reducing the need for discrete policies per resource. Also highlighted the integration with Argo Tunnel for simplified DNS record creation and deployment of secured resources.

A Tale of Two (APT) Transports

7/18/2019

Introduced a custom APT transport that integrates with Cloudflare Access to secure internal APT repositories. This transport leverages `cloudflared` to handle authentication and token generation, allowing users to access repositories via `cfd://` URIs. The post also details the history of APT, the bootstrapping problem of installing HTTPS support, and provides instructions for installing and using the custom transport, including fetching GPG keys.

Announcing the New Cloudflare Partner Platform

6/6/2019

This post introduces the new Cloudflare Partner Platform, which is a significant evolution of account access management and permissions. It details the development of 'tenants' for managing customer accounts and 'subscriptions' for packaging and provisioning services, enabling partners to sell and manage Cloudflare for their customers in a scalable manner. This builds upon previous work in multi-user access and introduces a more robust system for partner integrations, exemplified by the early partnership with IBM.

Cloudflare Access now supports RDP

2/21/2019

This post introduces the integration of Remote Desktop Protocol (RDP) support into Cloudflare Access. It addresses security vulnerabilities associated with RDP, such as weak passwords and open ports, by leveraging identity provider integration for stronger authentication and Argo Tunnel to secure connections without exposing the RDP port (3389). The post details the configuration steps using `cloudflared` for both protecting RDP machines and connecting to them, emphasizing the use of SSO credentials for RDP sessions.

Give your automated services credentials with Access service tokens

2/7/2019

Introduced Access service tokens, a new feature for Cloudflare Access that provides credentials (Client ID and Secret) to automated tools, scripts, and bots. This allows these services to authenticate with Cloudflare Access without redirecting to an identity provider, enabling secure access to internal sites and applications for machine-to-machine communication. Service tokens are scoped to a specific service and can be added to Access policies to grant granular permissions. The Client ID and Secret are valid for one year and can be rotated or revoked.

2018

Banking-Grade Credential Stuffing: The Futility of Partial Password Validation

12/20/2018

This post critically analyzes the security flaws of partial password validation, a common practice in account access management. It demonstrates how this method is ineffective against credential stuffing attacks and poses usability challenges for password manager users. The post strongly advocates for the adoption of multi-factor authentication (MFA) as a superior security measure, highlighting TOTP and hardware tokens as preferred alternatives to less secure methods like SMS OTP.

Announcing SSH Access through Cloudflare

11/16/2018

Introduced SSH access through Cloudflare Access, enabling secure connections to internal applications like source control repositories. This was achieved by leveraging Argo Tunnel for secure connections, Argo smart routing for performance acceleration, and the `cloudflared` CLI tool for establishing the connection between the user's device and the target server. The flow involves redirecting users to their identity provider for authentication, generating a JWT, and transferring it to `cloudflared` for subsequent requests.

Introducing Single Sign-On for the Cloudflare Dashboard

10/10/2018

Introduced Single Sign-On (SSO) for the Cloudflare dashboard for Enterprise customers. This allows customers to use their existing identity providers (e.g., G Suite via SAML) to authenticate users accessing the dashboard. A Cloudflare Worker was developed to translate Access authentication tokens to the dashboard's internal authentication tokens, running at the edge to reduce latency.

Leave your VPN and cURL secure APIs with Cloudflare Access

10/5/2018

Introduced `cloudflared`, a CLI tool that enables command-line authentication for Cloudflare Access. This allows users to securely access APIs and sensitive data via tools like `curl` by obtaining and injecting a JWT into requests, effectively replacing the need for VPNs for command-line tasks. This extends Access control policies to API endpoints and CLI operations.

Cloudflare Access: Sharing our single-sign on plugin for Atlassian

10/2/2018

This post introduces a new plugin for Atlassian tools (Jira and Confluence) that enables single sign-on (SSO) by leveraging JWTs issued by Cloudflare Access. The plugin maps identity data from the JWT payload to existing Atlassian user accounts, allowing users to access these tools with a single login. The post also details the structure and usage of JWTs in Cloudflare Access and announces efforts to expand JWT-based authorization to other applications.

Three new ways teams are using Cloudflare Access

8/15/2018

Introduced One-Time Pin (OTP) as a login method for external partners, allowing access to internal applications without requiring them to be added to the primary Identity Provider (IdP). This involves configuring OTP alongside an existing IdP (e.g., Okta) and creating Access Groups to manage external user email addresses. Also detailed how to create policies that require both IdP authentication and origin from specific network IP ranges for enhanced security.

Cloudflare Access: Now teams of any size can turn off their VPN

7/24/2018

This post announces the general availability of Cloudflare Access, a zero-trust solution designed to replace VPNs. It details the core functionality of Access, which controls who can reach internal resources by checking policies before requests reach the origin. Key features introduced or highlighted include integration with identity providers (GSuite, Okta), policy enforcement based on user authentication, IP addresses, and the introduction of 'Access Groups' for managing sets of users. New policy types like 'Bypass' for specific paths and 'Everyone' for broader access are also described. The post also outlines the pricing structure for Access Basic and Access Premium plans.

Expanding Multi-User Access on dash.cloudflare.com

5/2/2018

This post announces the expansion of multi-user access to all Cloudflare customers, previously only available at the Enterprise level. It introduces the concept of 'Administrators' who can manage account-level settings and features, with the exception of managing members and billing information. It also details the redesign of the account experience within the new dashboard at dash.cloudflare.com, including an account selector for users with multiple accounts and a zone selector. The post also mentions the backend architectural changes, including the rewrite of the dashboard from Backbone to React and the overhaul of the data model for account and user management, decoupling accounts, users, and resources.

Getting started with Terraform and Cloudflare (Part 1 of 2)

4/27/2018

This post introduces the integration of Terraform with Cloudflare, enabling infrastructure as code for managing Cloudflare configurations. It details how developers can use Terraform to programmatically manage DNS records, zone settings, rate limiting, load balancing, and page rules, moving configuration management from manual UI interactions to version-controlled code. This significantly enhances account management by allowing for automated deployments, change tracking, and rollbacks, aligning with best practices in software development.

Now You Can Setup Centrify, OneLogin, Ping and Other Identity Providers with Cloudflare Access

4/23/2018

This post introduces support for Centrify, OneLogin, and generic OIDC-based identity providers within Cloudflare Access. It provides detailed technical steps for configuring these integrations, including setting up applications in Centrify and OneLogin, and configuring client ID, client secret, auth URL, token URL, and certificate URL for generic OIDC providers. This expands the identity provider integration options for Cloudflare Access beyond existing GSuite, Okta, and Azure AD.

How Developers got Password Security so Wrong

2/21/2018

This post delves into the historical and ongoing challenges of password security, highlighting insecure storage practices and weak user-generated passwords. It explains cryptographic hashing, salting, and the limitations of these methods against modern cracking techniques and credential stuffing. The post advocates for improved developer education, the elimination of password reuse through mechanisms like range search APIs for breached password databases, and the broader adoption of two-factor authentication (2FA) as a critical security layer.

Keeping our users safe

2/16/2018

This post highlights the critical importance of account security and the prevalent threat of credential theft and phishing attacks, even in 2018. It details how attackers exploit weak credentials and password reuse, and showcases sophisticated attack vectors like malicious browser extensions that steal API keys. Cloudflare's response includes enhancing its backend security with strong password hashing (bcrypt) and API key generation (AES, SHA256), robust logging and auditing, and secure transit over HTTPS. For user interface protection, it emphasizes the necessity of strong passwords and 2FA, and introduces IP-based alerts and MFA codes for higher-tier accounts. Furthermore, it announces immediate improvements to API key security, such as CAPTCHA protection for viewing API keys, and outlines future plans for scoped API keys and IP restrictions.

Introducing Cloudflare Access: Like BeyondCorp, But You Don’t Have To Be A Google Employee To Use It

1/17/2018

Introduced Cloudflare Access, a perimeter-less access control solution for cloud and on-premise applications. Access acts as a reverse proxy that enforces access control by ensuring every request is authenticated (integrating with identity providers like Google, Azure AD, Okta, and supporting TLS with client authentication), authorized (configuring access policies for groups and users), and encrypted (leveraging HTTPS instead of VPN). Features include easy policy changes, session duration modification, session revocation, and centralized logging. It can be paired with Argo and Argo Tunnel for enhanced performance and security, and integrated with the Web Application Firewall for legacy application protection.

2017

Introducing TLS with Client Authentication

5/1/2017

Introduced TLS with Client Authentication for enterprise customers, enabling server-side authentication of clients via unique client certificates. This feature offloads CPU-intensive cryptographic operations to Cloudflare's edge. It supports two modes: 'enforce' (returns 403 for invalid certs) and 'report' (forwards requests with certificate status and SKI headers). Cloudflare can also forward client certificate fields as custom headers. The post also highlights the open-sourcing of Cloudflare's PKI tool, cfssl, to assist customers in setting up their own certificate authorities.

You can now use Google Authenticator and any TOTP app for Two-Factor Authentication

2/16/2017

This post introduces support for Google Authenticator and any Time-based One Time Password (TOTP) app for two-factor authentication (2FA). This expands the existing 2FA offering beyond Authy, giving users more choices for securing their accounts and enhancing the overall security posture of account access management.

2016

python-cloudflare

5/10/2016

This post introduces `python-cloudflare`, a Python wrapper for the Cloudflare v4 API, and a command-line interface (CLI) tool. It demonstrates how users can programmatically manage their Cloudflare resources, including listing domains, checking settings like IPv6, creating DNS records, and purging cache. The post highlights the API's structure, its direct mapping to the Python library, and the availability of client libraries for other languages, emphasizing the extensibility and control offered to users.

Sunsetting API v1 In Favor Of CloudFlare’s Current Client API: API v4

5/9/2016

This post announces the sunsetting of API v1 and the promotion of API v4. It details the extensive new capabilities available through API v4, including programmatic control over a wide range of Cloudflare features such as zone management, SSL certificates, Railgun, custom error pages, analytics, advanced firewall access rules, mobile redirects, and more. It also highlights the developer-friendly aspects of API v4, such as consistent JSON usage and improved namespacing, and provides resources for migration and adoption.

New for Virtual DNS Customers: Self-Service Dashboard and APIs, and Two New Features

4/13/2016

This post introduces Multi-User access control for Virtual DNS, allowing team members to manage Virtual DNS instances together. It also highlights advanced security features like the ability to require two-factor authentication across a team for Virtual DNS users.

2015

Introducing Multi-User Organizations: Share An Account Without Sharing A Login

4/29/2015

Introduced Multi-User functionality for Enterprise accounts, enabling role-based permissions for different team members (e.g., DNS Administrator, Analytics Administrator). This allows for granular access control to specific Cloudflare apps and settings without sharing a single login or API key. Super Administrators have root privileges to manage users and permissions. This feature also supports individual API keys per user and integrates with existing 2FA support for enhanced account security.

2013

Red October: CloudFlare’s Open Source Implementation of the Two-Man Rule

11/21/2013

Introduced Red October, a Go-based, open-source service implementing the 'two-man rule' for sensitive data protection. It uses a cryptographically-secure encryption/decryption server where multiple authorized users must delegate credentials to decrypt data, preventing single-person misuse. The system employs AES, RSA, and scrypt for cryptographic primitives, with RSA keys encrypted by password-derived keys. It supports JSON-based APIs for encryption, decryption, and credential delegation, with TLS for secure communication.