Cloudflare access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Cloudflare, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare connector needs.
Checks (9)
severity: medium External Account Member fix difficulty: medium #
Remove or convert external Cloudflare account members not part of your organization
- Log in to the Cloudflare Dashboard
- Navigate to the Members page
- Review external members who are not part of your organization
- Remove external members or convert them to SSO-managed accounts
Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.2 CIS Controls v8 CIS-15.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium SSO Not Configured fix difficulty: hard #
Configure SSO with an identity provider in Cloudflare Zero Trust for centralized authentication
- Open the Cloudflare Zero Trust Dashboard
- Navigate to Settings > Authentication
- Configure SSO with your identity provider (SAML or OIDC)
- Test the SSO flow before enabling enforcement
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-02 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Super Admin Count Excessive fix difficulty: medium #
Reduce Cloudflare Super Administrator count by demoting unnecessary admins to specific roles
- Log in to the Cloudflare Dashboard
- Navigate to the Members page
- Review users with the Super Administrator role
- Demote unnecessary super admins to more specific roles
Satisfies: ISO 27001:2022 A.8.2 SOC 2 Type II CC6.3 CIS Controls v8 CIS-05.4 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Super Admin Redundancy Missing fix difficulty: easy #
Ensure at least two Cloudflare Super Administrator accounts exist for redundancy
- Log in to the Cloudflare Dashboard
- Navigate to the Members page
- Verify at least two super admin accounts exist
- If only one exists, promote a second trusted member
Satisfies: ISO 27001:2022 A.8.2 SOC 2 Type II CC6.3 CIS Controls v8 CIS-05.4 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: critical Super Admin Without MFA fix difficulty: easy #
Require Cloudflare Super Administrators to enable two-factor authentication immediately
- Log in to the Cloudflare Dashboard
- Navigate to the Members page and identify the Super Administrator without MFA
- Contact the member and instruct them to enable 2FA in My Profile > Authentication
- Verify that two-factor authentication is active for all Super Administrators
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Pending Account Member fix difficulty: easy #
Review and revoke stale pending Cloudflare account member invitations
- Log in to the Cloudflare Dashboard
- Navigate to the Members page
- Identify pending invitations that have not been accepted
- Revoke stale invitations and re-invite if still needed
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Role-less Account Member fix difficulty: easy #
Review Cloudflare account members that have no role assigned and either grant a scoped role or remove the member
- Log in to the Cloudflare Dashboard
- Navigate to the Members page
- Identify members listed with no role
- Assign an appropriate scoped role or remove the member
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium API Token Without Expiry fix difficulty: easy #
Set an expiry on Cloudflare account API tokens
- Open the Cloudflare dashboard API Tokens page
- Edit the token and set a TTL / expiration date
- Recreate long-lived tokens as short-lived and rotate them on a schedule
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium API Token Stale fix difficulty: medium #
Revoke or rotate Cloudflare API tokens unused for 90+ days
- Open the Cloudflare dashboard API Tokens page
- Identify tokens with no recent "Last used" activity
- Roll (rotate) tokens that are still needed and delete the rest
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2