Identity design
Bring your IdP or use Cloudflare-native identity
Cloudflare One can use your corporate identity provider, Cloudflare account membership, one-time PIN, or multiple login methods together. The right design depends on user type, lifecycle control, and policy depth.
The Decision
For production employee access, a corporate IdP such as Microsoft Entra ID, Okta, Google Workspace, or another SAML/OIDC provider is usually the control plane because it carries lifecycle, MFA, and group claims. Cloudflare-native identity is useful when you want fast setup, administrator access, Cloudflare account-member based policies, or access that does not require configuring a third-party IdP.
What Changed
For newly created Zero Trust organizations, Cloudflare automatically adds the Cloudflare identity provider as the default login method. Users can sign in with existing Cloudflare account credentials, and administrators can later add corporate SAML or OIDC providers.
Recommended Patterns
Bring your IdP
Use Entra ID, Okta, Google Workspace, or generic SAML/OIDC. Verify groups, enable SCIM where available, and build Access Groups from real identity claims.
Cloudflare-native first
Use Cloudflare account membership to protect early admin tools or demos before the corporate IdP project is ready.
Separate login path
Use OTP or a partner IdP for users outside your employee directory, with tighter session duration and app scope.
Account membership selector
Use Cloudflare account membership selectors for current-account or cross-account access scenarios.
Test every IdP
Use the dashboard test flow to confirm the login works and that expected email, group, and claim data is present.
Keep break-glass
Retain a safe admin path and at least two Super Admins so a bad Access policy or IdP outage does not lock out operations.
Design Checklist
Source References
Based on current Cloudflare One identity documentation for identity providers and Cloudflare as an identity provider.