Identity providers identify the user and add group and authentication context.
Start with the Cloudflare One Client. Build trust from there.
Cloudflare Access combines who the user is, whether their device is trusted, and where the request comes from. These signals become policies that define access to self-hosted and SaaS applications without granting broad network access.
Identity providers identify the user and add group and authentication context.
The Cloudflare One Client and endpoint integrations continuously supply posture signals.
Network and request attributes describe the source reaching the application.
Begin with the software users recognize on the endpoint. WARP registers the device, establishes its path to Cloudflare, and supplies identity and posture context to the controls that follow.
Access can combine the user asserted by an identity provider with continuously evaluated endpoint signals. The policy later decides which of those signals are required for a particular resource.
Use a self-hosted browser application first. The application defines the protected resource; its policies combine rule logic, selectors, values, and one primary action.
Who is considered, what must also be true, and who is carved out.
Move from who may access an application to what DNS, Network, and HTTP traffic may do.
Explore capability → Isolate applicationExecute risky content remotelyFollow the isolation control into browser execution and data-in-use restrictions.
Explore capability →A Tunnel provides outbound-only connectivity and routes; it does not create an Access application or Target. The same Tunnel can publish a web service, route a private application, and carry infrastructure traffic. Access objects then define what is protected and who may connect.
Use these capability paths when the conversation moves beyond application access. Each remains a distinct control plane with its own guided page.
Control DNS, Network, and HTTP traffic for Internet and SaaS use.
Explore capability → ExecutionBrowser IsolationRun active web content remotely and control data in use.
Explore capability → DataData Loss PreventionDefine sensitive data once and apply it across supported channels.
Explore capability → SaaSCASBDiscover cloud application use and inspect SaaS security posture.
Explore capability → AIAI SecurityGovern workforce AI, model traffic, and agent tool access.
Explore capability → MailboxEmail SecurityPrevent, contain, and investigate threats around the mailbox provider.
Explore capability → ExperienceDigital ExperienceInvestigate endpoint, network path, and application health.
Explore capability →