Cloudflare Access: Identity and Access Management

Secure Application Access Without a VPN

Secure, authenticate, and monitor user access to any domain, application, or path on Cloudflare.

Quickly apply application-level user access permissions using existing single sign-on providers.

Ensure compliance using real-time access logs available in the dashboard, API, or using a SIEM.

Already a customer? Activate Today

Enforcing Granular User Access to Internal Applications

Securing internal applications for remote employees and contractors is:

  • Cumbersome to deploy and maintain
  • Missing granular access controls
  • Slow for users on mobile devices

Employees and contractors often need access to specific, sensitive internal applications when working outside the corporate firewall.

Customers have typically tried to solve this problem by deploying a VPN or by using basic authentication on whitelisted IP addresses. These types of approaches have challenges maintaining, deploying and enforcing user access policies. They lack granular application access controls. Authenticating users by identity is difficult or non-existent. And user experience is slow, especially for those on mobile devices.

Secure Internal Applications with Granular User and Application Controls

Cloudflare Access protects internal resources by securing, authenticating and monitoring access per-user and by application. With Cloudflare Access, only authenticated users with the required permissions are able to access specific resources behind the Cloudflare edge. Support for existing identity providers such as GSuite and Okta ensures the right users have easy and instant access regardless of physical location. By enforcing access rules at the edge, Cloudflare reduces latency for users.

Control User Access to Applications

Enforce access to specific applications on a per-user basis with easy-to-create and manage rules. Adding and removing access to applications doesn’t require adding one-off groups or creating extra user accounts. Easily change access policies from the dashboard or API.

Deploy and Manage Access Control Quickly

Leverage existing identity providers and authenticate on the Cloudflare global network. Maintaining multiple or shared user accounts to internal resources is no longer necessary. Identity providers include: Google™, G Suite™, Github™, Okta™, Facebook™, and more...

Full provider list

Monitor User Access and Change Logs

View and search real-time access logs in the dashboard or integrate with a third party SIEM. Have full visibility into: recent logins, access requests, and policy changes. Search for and expand logs directly in the dashboard to see affected users, associated IPs, domains, actions taken, and timestamps.

Easy internal application access via mobile device.

Deliver Fast Applications to Devices Anywhere

Users get easy, secure, and fast access to internal applications wherever they are, from whatever device. Cloudflare's global network accelerates applications while also doing away with additional latency and the unnecessary authentication hassles of VPNs.

Key Features

Flexible Session Durations

Revocable Session Tokens

Support for Multiple Subdomains

Origin Hiding with Argo Tunnel

Customizable Login Page Branding

Searchable and Detailed Audit Logs

Dynamic Content Acceleration with Argo

Static Content Caching

Integrated WAF and Rate Limiting

DDoS Protection

Supports nested groups of users

Supports whitelisting of external services

Supports IP address ranges

Support for server access over SSH (Secure Shell)

Enables a secure, Zero Trust command line (CLI) authentication to APIs

Credentials for automated services with Access service tokens.

"Cloudflare Access is helping 23andMe access our internal applications securely from any device at anytime without the need for VPN."
Arnold de Leon
SRE Manager at 23andMe

Pricing for Cloudflare Access

Access pricing is based on the number of users and the choice of identity provider (IdP). There are two plans: Basic and Premium. The basic plan offers support for social IdPs such as Facebook or Google whereas the Premium plan offers support for enterprise IdPs such as Okta, and G-suite. A complete list of features by plan as well as answers to frequently asked questions can be seen here.

Your Access plan is shared across zones in your account. You should purchase the number of seats you expect to need for all zones. The Access pricing calculator will help you estimate your price and select your plan based on the identity provider/s you need and the number of seats you expect to use.