Skip to content

Cloudflare access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Cloudflare, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare connector needs.

Checks (9)

severity: medium External Account Member fix difficulty: medium #

Remove or convert external Cloudflare account members not part of your organization

  1. Log in to the Cloudflare Dashboard
  2. Navigate to the Members page
  3. Review external members who are not part of your organization
  4. Remove external members or convert them to SSO-managed accounts

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.2 CIS Controls v8 CIS-15.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium SSO Not Configured fix difficulty: hard #

Configure SSO with an identity provider in Cloudflare Zero Trust for centralized authentication

  1. Open the Cloudflare Zero Trust Dashboard
  2. Navigate to Settings > Authentication
  3. Configure SSO with your identity provider (SAML or OIDC)
  4. Test the SSO flow before enabling enforcement

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-02 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Super Admin Count Excessive fix difficulty: medium #

Reduce Cloudflare Super Administrator count by demoting unnecessary admins to specific roles

  1. Log in to the Cloudflare Dashboard
  2. Navigate to the Members page
  3. Review users with the Super Administrator role
  4. Demote unnecessary super admins to more specific roles

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.2 SOC 2 Type II CC6.3 CIS Controls v8 CIS-05.4 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Super Admin Redundancy Missing fix difficulty: easy #

Ensure at least two Cloudflare Super Administrator accounts exist for redundancy

  1. Log in to the Cloudflare Dashboard
  2. Navigate to the Members page
  3. Verify at least two super admin accounts exist
  4. If only one exists, promote a second trusted member

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.2 SOC 2 Type II CC6.3 CIS Controls v8 CIS-05.4 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: critical Super Admin Without MFA fix difficulty: easy #

Require Cloudflare Super Administrators to enable two-factor authentication immediately

  1. Log in to the Cloudflare Dashboard
  2. Navigate to the Members page and identify the Super Administrator without MFA
  3. Contact the member and instruct them to enable 2FA in My Profile > Authentication
  4. Verify that two-factor authentication is active for all Super Administrators

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Pending Account Member fix difficulty: easy #

Review and revoke stale pending Cloudflare account member invitations

  1. Log in to the Cloudflare Dashboard
  2. Navigate to the Members page
  3. Identify pending invitations that have not been accepted
  4. Revoke stale invitations and re-invite if still needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Role-less Account Member fix difficulty: easy #

Review Cloudflare account members that have no role assigned and either grant a scoped role or remove the member

  1. Log in to the Cloudflare Dashboard
  2. Navigate to the Members page
  3. Identify members listed with no role
  4. Assign an appropriate scoped role or remove the member

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium API Token Without Expiry fix difficulty: easy #

Set an expiry on Cloudflare account API tokens

  1. Open the Cloudflare dashboard API Tokens page
  2. Edit the token and set a TTL / expiration date
  3. Recreate long-lived tokens as short-lived and rotate them on a schedule

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium API Token Stale fix difficulty: medium #

Revoke or rotate Cloudflare API tokens unused for 90+ days

  1. Open the Cloudflare dashboard API Tokens page
  2. Identify tokens with no recent "Last used" activity
  3. Roll (rotate) tokens that are still needed and delete the rest

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Cloudflare checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial