Skip to content

Cloudflare Access identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On Cloudflare Access, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare Access connector needs.

Checks (6)

severity: medium Long Session Duration fix difficulty: easy #

Reduce the Access application session duration to 24 hours or less

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Access > Applications
  3. Click the application name to open its settings
  4. Select the "Overview" tab and locate "Session Duration"
  5. Change the session duration to 24h or a shorter value appropriate for the application's sensitivity
  6. Save changes and confirm the new session duration is applied

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.5 DORA (SaaS Security) DORA-9.5

severity: high No MFA Requirement fix difficulty: medium #

Enable MFA requirement on the Access policy to enforce multi-factor authentication

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Access > Applications
  3. Click the application and open the "Policies" tab
  4. Edit the relevant policy
  5. Under "Require" rules, add an "Authentication Method" requirement and select "mfa" or a specific MFA method
  6. Save the policy and verify that users without MFA are denied access

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high One-Time PIN Only Authentication fix difficulty: hard #

Add a corporate SAML or OIDC identity provider alongside one-time PIN to enforce stronger authentication

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Settings > Authentication (or Access > Identity Providers)
  3. Click "Add new" and select a SAML or OIDC provider (e.g., Okta, Azure AD, Google Workspace)
  4. Complete the provider configuration with your IdP credentials and metadata
  5. Test the new identity provider to confirm successful authentication
  6. Update critical Access policies to require authentication via the new corporate IdP rather than OTP

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high No SAML or OIDC Provider fix difficulty: hard #

Configure a SAML or OIDC identity provider that supports MFA enforcement in Cloudflare Access

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Settings > Authentication (or Access > Identity Providers)
  3. Click "Add new" and select a SAML or OIDC provider
  4. Enter the IdP metadata URL or manually input the SSO URL, entity ID, and certificate
  5. Enable MFA enforcement at the IdP level for all users
  6. Test the integration and update Access policies to require authentication via this provider

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Long Global Session Duration fix difficulty: easy #

Reduce the Cloudflare Zero Trust global session duration to 24 hours or less

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Settings > Authentication (or Access controls > Access settings)
  3. Locate "Global session duration" and select Edit
  4. Choose a duration of 24 hours or less appropriate for your risk tolerance
  5. Save and confirm users are prompted to re-authenticate after the new interval

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.5 DORA (SaaS Security) DORA-9.5

severity: low Long WARP Authentication Session fix difficulty: easy #

Reduce the WARP authentication session duration to 24 hours or less

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Settings > WARP Client (or Access controls > Access settings)
  3. Locate the WARP authentication session duration setting
  4. Set it to 24 hours or less
  5. Save and confirm WARP users re-authenticate after the new interval

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.5 DORA (SaaS Security) DORA-9.5

More Cloudflare Access checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial