Cloudflare Access configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On Cloudflare Access, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare Access connector needs.
Checks (3)
severity: high CORS Allows All Origins fix difficulty: medium #
Restrict CORS allowed origins to specific trusted domains for the Access application
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Access > Applications
- Click the application name to open its settings
- Select the "CORS Settings" or "Advanced" tab
- Replace the wildcard (*) allowed origin with an explicit list of trusted domains
- Save changes and test that legitimate origins are still permitted
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Application Hidden from App Launcher fix difficulty: easy #
Make the Access application visible in the App Launcher for easier discovery and auditing
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Access > Applications and select the hidden application
- Open the Overview or Settings tab
- Enable "Show application in the App Launcher"
- Save the change and verify the application appears in the App Launcher
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Service Token Without Name fix difficulty: easy #
Give the Cloudflare Access service token a descriptive name for easier auditing and ownership tracking
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Access > Service Auth > Service Tokens
- Locate the unnamed service token
- Click on the token to edit its name
- Enter a descriptive name indicating the consuming service and team owner
- Save the change
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10