Skip to content

Cloudflare Access configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On Cloudflare Access, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare Access connector needs.

Checks (3)

severity: high CORS Allows All Origins fix difficulty: medium #

Restrict CORS allowed origins to specific trusted domains for the Access application

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Access > Applications
  3. Click the application name to open its settings
  4. Select the "CORS Settings" or "Advanced" tab
  5. Replace the wildcard (*) allowed origin with an explicit list of trusted domains
  6. Save changes and test that legitimate origins are still permitted

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Application Hidden from App Launcher fix difficulty: easy #

Make the Access application visible in the App Launcher for easier discovery and auditing

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Access > Applications and select the hidden application
  3. Open the Overview or Settings tab
  4. Enable "Show application in the App Launcher"
  5. Save the change and verify the application appears in the App Launcher

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Service Token Without Name fix difficulty: easy #

Give the Cloudflare Access service token a descriptive name for easier auditing and ownership tracking

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Access > Service Auth > Service Tokens
  3. Locate the unnamed service token
  4. Click on the token to edit its name
  5. Enter a descriptive name indicating the consuming service and team owner
  6. Save the change

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More Cloudflare Access checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial