The 26 Cloudflare Access security checks Black Cat runs
Black Cat SSPM evaluates 26 security policies against your Cloudflare Access configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Cloudflare Access — what access Black Cat needs, and why.
Identity, MFA & sign-in
6 checks · highest severity: high
Access control & privilege
14 checks · highest severity: critical
Encryption, keys & secrets
3 checks · highest severity: high
Configuration hardening
3 checks · highest severity: high
Identity, MFA & sign-in (6)
- Long Session Duration severity: medium
- No MFA Requirement severity: high
- One-Time PIN Only Authentication severity: high
- No SAML or OIDC Provider severity: high
- Long Global Session Duration severity: medium
- Long WARP Authentication Session severity: low
Access control & privilege (14)
- Application Without Policies severity: critical
- Bypass Decision Policy severity: high
- Policy Allows Everyone severity: high
- No Purpose Justification severity: low
- Group Includes Everyone severity: high
- Group With Empty Include Rules severity: medium
- Single Identity Provider severity: medium
- Application Allows All IdPs severity: medium
- Application No Auto-Redirect to IdP severity: medium
- Policy Without Require Rules severity: medium
- Group Without Require Rules severity: medium
- Service Token Over One Year Old severity: medium
- Seat Expiration Not Configured severity: medium
- Dashboard Not Read-Only severity: low
Encryption, keys & secrets (3)
- Service Token Without Expiry severity: high
- Stale Service Token severity: medium
- Expired Service Token Not Deleted severity: low
Configuration hardening (3)
- CORS Allows All Origins severity: high
- Service Token Without Name severity: low