Cloudflare Access identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On Cloudflare Access, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare Access connector needs.
Checks (6)
severity: medium Long Session Duration fix difficulty: easy #
Reduce the Access application session duration to 24 hours or less
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Access > Applications
- Click the application name to open its settings
- Select the "Overview" tab and locate "Session Duration"
- Change the session duration to 24h or a shorter value appropriate for the application's sensitivity
- Save changes and confirm the new session duration is applied
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.5 DORA (SaaS Security) DORA-9.5
severity: high No MFA Requirement fix difficulty: medium #
Enable MFA requirement on the Access policy to enforce multi-factor authentication
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Access > Applications
- Click the application and open the "Policies" tab
- Edit the relevant policy
- Under "Require" rules, add an "Authentication Method" requirement and select "mfa" or a specific MFA method
- Save the policy and verify that users without MFA are denied access
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high One-Time PIN Only Authentication fix difficulty: hard #
Add a corporate SAML or OIDC identity provider alongside one-time PIN to enforce stronger authentication
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Settings > Authentication (or Access > Identity Providers)
- Click "Add new" and select a SAML or OIDC provider (e.g., Okta, Azure AD, Google Workspace)
- Complete the provider configuration with your IdP credentials and metadata
- Test the new identity provider to confirm successful authentication
- Update critical Access policies to require authentication via the new corporate IdP rather than OTP
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high No SAML or OIDC Provider fix difficulty: hard #
Configure a SAML or OIDC identity provider that supports MFA enforcement in Cloudflare Access
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Settings > Authentication (or Access > Identity Providers)
- Click "Add new" and select a SAML or OIDC provider
- Enter the IdP metadata URL or manually input the SSO URL, entity ID, and certificate
- Enable MFA enforcement at the IdP level for all users
- Test the integration and update Access policies to require authentication via this provider
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Long Global Session Duration fix difficulty: easy #
Reduce the Cloudflare Zero Trust global session duration to 24 hours or less
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Settings > Authentication (or Access controls > Access settings)
- Locate "Global session duration" and select Edit
- Choose a duration of 24 hours or less appropriate for your risk tolerance
- Save and confirm users are prompted to re-authenticate after the new interval
Satisfies: NIS2 Directive NIS2-21.i.5 DORA (SaaS Security) DORA-9.5
severity: low Long WARP Authentication Session fix difficulty: easy #
Reduce the WARP authentication session duration to 24 hours or less
- Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
- Navigate to Settings > WARP Client (or Access controls > Access settings)
- Locate the WARP authentication session duration setting
- Set it to 24 hours or less
- Save and confirm WARP users re-authenticate after the new interval
Satisfies: NIS2 Directive NIS2-21.i.5 DORA (SaaS Security) DORA-9.5