Identity design

Bring your IdP or use Cloudflare-native identity

Cloudflare One can use your corporate identity provider, Cloudflare account membership, one-time PIN, or multiple login methods together. The right design depends on user type, lifecycle control, and policy depth.

The Decision

For production employee access, a corporate IdP such as Microsoft Entra ID, Okta, Google Workspace, or another SAML/OIDC provider is usually the control plane because it carries lifecycle, MFA, and group claims. Cloudflare-native identity is useful when you want fast setup, administrator access, Cloudflare account-member based policies, or access that does not require configuring a third-party IdP.

Corporate IdPBest for employees, group-based policy, SCIM lifecycle, centralized MFA, and enterprise audit alignment.
Cloudflare identity providerBest for fast setup, Cloudflare account members, admin-oriented access, and cross-account membership scenarios.
One-time PINUseful for simple guest or contractor access where a full IdP integration is not justified.
Multiple IdPsUse when employees, partners, contractors, and admins need different authentication paths.

What Changed

For newly created Zero Trust organizations, Cloudflare automatically adds the Cloudflare identity provider as the default login method. Users can sign in with existing Cloudflare account credentials, and administrators can later add corporate SAML or OIDC providers.

Recommended Patterns

Enterprise workforce

Bring your IdP

Use Entra ID, Okta, Google Workspace, or generic SAML/OIDC. Verify groups, enable SCIM where available, and build Access Groups from real identity claims.

Fast start

Cloudflare-native first

Use Cloudflare account membership to protect early admin tools or demos before the corporate IdP project is ready.

Contractors

Separate login path

Use OTP or a partner IdP for users outside your employee directory, with tighter session duration and app scope.

Multi-account

Account membership selector

Use Cloudflare account membership selectors for current-account or cross-account access scenarios.

Policy quality

Test every IdP

Use the dashboard test flow to confirm the login works and that expected email, group, and claim data is present.

Resilience

Keep break-glass

Retain a safe admin path and at least two Super Admins so a bad Access policy or IdP outage does not lock out operations.

Design Checklist

1. Pick login methodsDecide which users authenticate through corporate IdP, Cloudflare account membership, OTP, or partner IdPs.
2. Verify claimsConfirm email, groups, and custom claims before writing policies that depend on them.
3. Build reusable groupsCreate Access Groups for employee, admin, contractor, partner, and service access patterns.
4. Add posture where neededPair identity with device posture for sensitive apps and managed-device-only workflows.
5. Validate failure modesTest disabled users, missing groups, expired sessions, and break-glass access before broad rollout.

Source References

Based on current Cloudflare One identity documentation for identity providers and Cloudflare as an identity provider.