Preview Mode
Documentation
Cloudflare named in 2024 Gartner® Magic Quadrant™ for SV-SASE. Announcement >

Cloudflare Access

Fast, reliable Zero Trust Network Access (ZTNA)

Access verifies context (like identity and device posture) to secure access across your entire environment — no VPN required.

BENEFITS OF CLOUDFLARE ACCESS
Lightning bolt icon
Improve team productivity

Make on-premises applications as easy to use as SaaS apps. ZTNA reduces remote access support tickets by 80% compared to a VPN.

Security shield protection orange
Simplify management

Simplify the setup and operation of ZTNA with robust software connectors and unified Zero Trust policies.

Lateral movement icon: 128x128
Eliminate lateral movement

Shrink your attack surface by enforcing context-based, least-privilege access policies for every resource.

icon scale aqua
Scale Zero Trust effortlessly

Shield critical applications and high-risk user groups first — then expand cloud-native ZTNA to protect your entire business.

How it works

Manage user access across your entire environment

Cloudflare Access verifies and secures employee and third-party access across all of your self-hosted, SaaS, and non-web applications, helping mitigate risk and ensure a smooth user experience.

It checks granular context like identity and device posture for every request to provide fast, reliable access across your business.

Learn more in our ZTNA product overview

Learn how Access works within Cloudflare’s SASE platform

ANALYST RECOGNITION
Gartner logo
Cloudflare named in 2024 Gartner® Magic Quadrant™ for Single-Vendor SASE

We believe this recognition is a testament to Cloudflare’s “light branch, heavy cloud” architecture and its ability to help global, cloud-minded enterprises accelerate their network modernization.

Forrester logo
Cloudflare a Strong Performer in The Forrester Wave™: Security Service Edge Solutions, Q1 2024

Cloudflare received the highest score in the global network criterion. We believe this recognition validates our commitment to build SASE “the right way,” converging network and security services on a composable, programmable connectivity cloud.

KuppingerCole Analysts logo
Cloudflare named a "Leader" in 2023 KuppingerCole Leadership Compass for SASE

Through its 2023 SASE market analysis, KuppingerCole Analysts AG cited several Cloudflare strengths such as our large globally distributed presence and sophisticated traffic acceleration, massive backbone capacity, 100% uptime guarantee, and innovative Remote Browser Isolation.

What our customers are saying

“Cloudflare Access was a game-changer for Bitso. It made Zero Trust much easier. We now manage access to internal resources more efficiently, ensuring the right people have the right level of access to the right resources, regardless of their location, device or network.”

Cybersecurity Lead, Bitso

TOP ACCESS USE CASES

Cloudflare Access provides simple, secure user access to your internal resources — without a VPN

security-shield-protection-230x301-664b7d5
Augment / replace your VPN

Offload critical applications for better security and an improved user experience.

multiple users icon
Manage third-party access

Authenticate third-party users (like contractors) with clientless options, social identity providers, and more.

Code Web approved - orange
Empower developers

Ensure privileged technical users can access critical infrastructure — without performance trade-offs.

Helping organizations worldwide progress toward Zero Trust


Access control features across full Zero Trust platform
Free Plan
Best for teams under 50 users or enterprise proof-of-concept tests.

$0 forever
Get started
Pay-as-you-go
Best for teams over 50 users solving narrow SSE use cases and do not require enterprise support services.

$7/user/month
Get started
Contract Plan
Best for organizations building toward a full-featured SSE or SASE deployment that also desire maximum support.

Annual custom price per user
Talk to an expert

Access Controls (included in Zero Trust Platform)

Usage
50 user limit
No user limit
No user limit

Support and services
Support and services
Support options vary by plan type. Various professional advisory and hands-on implementation services available as add-on to Contract plans.
Community forums and Discord server
Chat and ticket support
Phone, chat, and ticket support; professional services available (add-on)

Customizable access policies
Customizable access policies
Custom application and private network policies, plus policy tester. Supports temporary authentication, purpose justification, and any IdP-provided auth method.

Protect access to all your apps and private networks
Protect access to all your apps and private networks
Protect self-hosted, SaaS, and non-web (SSH, VNC, RDP) apps, internal IPs and hostnames, or any arbitrary L4-7 TCP or UDP traffic.

Authentication via Identity Providers (IdPs)
Authentication via Identity Providers (IdPs)
Authenticate via enterprise and social IdPs, including multiple IdPs concurrently. Can also use generic SAML and OIDC connectors.

Identity-based context
Identity-based context
Configure contextual access based on IdP groups, geolocation, device posture, session duration, external APIs, etc.

Device posture integration
Device posture integration
Verify device posture using third-party endpoint protection provider integrations.

Clientless access option
Clientless access option
Clientless access for web apps and browser-based SSH or VNC

Browser-based SSH and VNC
Browser-based SSH and VNC
Privileged SSH and VNC access through in-browser terminal

Split tunneling
Split tunneling
Split tunneling for local or VPN connectivity

Application launcher
Application launcher
Customizable app launcher for all apps, including bookmarks to apps outside of Access

Token authentication
Token authentication
Service token support for automated services

Internal DNS support
Internal DNS support
Configure local domain fallback. Define an internal DNS resolver to resolve private network requests.

Infrastructure-as-code automation (via Terraform)
Infrastructure-as-code automation (via Terraform)
Automate deployment of Cloudflare resources and connections.

mTLS authentication
mTLS authentication
Certificate-based auth for IoT and other mTLS use cases

Resources

Resources card - Thin top orange line  - image
Cloudflare Access is the fastest Zero Trust proxy

See how performance tests validated Cloudflare’s ZTNA service as 50-75% faster than our competition.

Read the blog post
Resources card - Thin top orange line  - image
Augment or replace your VPN with Cloudflare

Learn how to offload key applications from traditional VPNs to Cloudflare Access.

Read the blog post
Resources card - Thin top orange line  - image
Secure contractor access with Zero Trust

See how ZTNA makes connecting third-party users (like contractors and partners) secure and simple.

Download the whitepaper

Get Cloudflare Access for your enterprise

1 Gartner, Voice of the Customer for Zero Trust Network Access, by Peer Contributors, 30 January 2024.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the US and internationally, MAGIC QUADRANT and PEER INSIGHTS are registered trademarks and The GARTNER PEER INSIGHTS CUSTOMERS’ CHOICE badge is a trademark and service mark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.

Gartner® Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product, or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.