Secure Application Access Without a VPN
Secure, authenticate, and monitor user access to any domain, application, or path on Cloudflare.
Quickly apply application-level user access permissions using existing single sign-on providers.
Ensure compliance using real-time access logs available in the dashboard, API, or using a SIEM.
Already a customer? Activate Today
Securing internal applications for remote employees and contractors is:
Cloudflare Access improves security, reduces costs, and protects internal resources by securing, authenticating, and monitoring access per-user and by application. Setup access policies in minutes to ensure that only authenticated users with the required permissions are able to access specific resources.
Enforce access to specific applications on a per-user basis with easy-to-create and manage rules. Adding and removing access to applications doesn’t require adding one-off groups or creating extra user accounts. Easily change access policies from the dashboard or API.
Leverage existing identity providers and authenticate on the Cloudflare global network. Maintaining multiple or shared user accounts to internal resources is no longer necessary. Identity providers include: Google™, G Suite™, Github™, Okta™, Facebook™, and more...
View and search real-time access logs in the dashboard or integrate with a third party SIEM. Have full visibility into: recent logins, access requests, and policy changes. Search for and expand logs directly in the dashboard to see affected users, associated IPs, domains, actions taken, and timestamps.
Users get easy, secure, and fast access to internal applications wherever they are, from whatever device. Cloudflare's global network accelerates applications while also doing away with additional latency and the unnecessary authentication hassles of VPNs.
Log every request made to a resource behind Cloudflare Access and attribute it to the authenticated user. Monitor and log user sessions as they navigate through an application, and export these logs to your SIEM with Cloudflare Logpush. Currently available for Enterprise customers.
Support for Major Identity Providers
Flexible Session Durations
Revocable Session Tokens
Support for Multiple Subdomains
Origin Hiding with Argo Tunnel
Customizable Login Page Branding
Searchable and Detailed Audit Logs
Dynamic Content Acceleration with Argo
Static Content Caching
Integrated WAF and Rate Limiting
DDoS Protection
Supports nested groups of users
Supports whitelisting of external services
Supports IP address ranges
Support for server access over SSH (Secure Shell)
Enables a secure, Zero Trust command line (CLI) authentication to APIs
Credentials for automated services with Access service tokens.
Access pricing is based on the number of users and the choice of identity provider (IdP). There are two plans: Basic and Premium. The basic plan offers support for social IdPs such as Facebook or Google whereas the Premium plan offers support for enterprise IdPs such as Okta, and G-suite. A complete list of features by plan as well as answers to frequently asked questions can be seen here.
Your Access plan is shared across zones in your account. You should purchase the number of seats you expect to need for all zones. The Access pricing calculator will help you estimate your price and select your plan based on the identity provider/s you need and the number of seats you expect to use.