
3/18/2022 · Molly Cinnamon, Evan Johnson
What this post added
This post details the technical implementation of enforcing FIDO2 security keys as the only second factor for accessing internal and external applications protected by Cloudflare Access. It includes a Terraform code example demonstrating how to configure Cloudflare Access policies to require the 'swk' authentication method, which corresponds to logins using a security key. The post also presents a graph showing the reduction in soft token usage after this enforcement.