Device Enrollment Checks Now Available in Cloudflare Access
Cloudflare Access administrators can now build Zero Trust rules that restrict application connections to corporate-managed devices. The new device posturing capability works alongside existing Access rules based on identity, multifactor method, or geographic location, and can be combined with any of them in the same policy.
The feature addresses a common request from organizations moving to a Zero Trust model: blocking access from devices the enterprise neither owns nor manages. For companies with fully remote teams, an employee logging into a sensitive application from an unmanaged tablet creates a data-loss vector. Others face compliance requirements that mandate work be performed only on corporate hardware. Cloudflare is positioning the feature for teams of all sizes, including those without a dedicated mobile device manager (MDM) today.
Why Device Identity Matters
Enterprises that issue hardware maintain control over that fleet. Administrators can assign, inspect, manage, and revoke devices through inventory tools or even a spreadsheet. Personal devices enjoy none of that visibility—by design—and that same lack of control creates risk when those devices hold corporate data or reach corporate applications.
Traditional single sign-on (SSO) and SaaS logins do not close that gap. Reused passwords work the same from any machine, and even hardware-based multifactor like a security key can be plugged into a personal laptop. The enforcement point, Cloudflare argues, must include the device itself, not just the user's credentials.
How Device Enforcement Works
Setup requires a serial number list and the Cloudflare for Teams client, and typically takes around 20 minutes.
The process begins by importing serial numbers of corporate devices. Administrators can upload lists in bulk, enter entries manually in the Teams Dashboard, or push new serial numbers via the API—useful for automating onboarding when hardware is purchased. Most asset and inventory management systems support easy export of serial numbers.
Next, deploy the WARP client on the managed machines. Users can install it themselves, or teams can roll it out through an MDM platform. Once WARP is running, it gathers hardware details, matches the device serial number against the managed list, and the Cloudflare edge makes an allow/deny decision on each request in real time.
The check works at the point of login and for every ongoing request. Even if a user installs WARP and moves a hard key to a personal device, they remain blocked: the serial number is not on the corporate list.
Access policies can now enforce corporate-device-only rules across both self-managed and SaaS applications, with all session activity logged. The Cloudflare for Teams agent reports inventory data to the edge, and rules can be extended to existing inventory systems, from a simple spreadsheet to an MDM API.
Availability
The feature is live in the Teams Dashboard for current customers, and a setup guide is available. New teams can sign up for a free Teams account supporting up to 50 users to trial the device-restriction policies.



