Microsoft 365 networking partnership opens a direct path for Cloudflare One customers

Cloudflare has joined the Microsoft 365 Networking Partner Program (NPP), and Cloudflare One now qualifies as an optimized on-ramp for customer traffic destined for Microsoft 365. The qualification followed demonstrations that Cloudflare's network can improve user connectivity to Microsoft's productivity suite.

Cloudflare One routes user traffic from devices and offices through Cloudflare's network, which spans more than 250 cities and connects to more than 10,000 networks globally. The service applies intelligent routing and software optimizations to accelerate traffic toward its destination. For Microsoft 365 traffic specifically, the goal is to break out connections as locally and directly as possible, avoiding the extra hops and backhauling that legacy security appliances often introduce.

This direct path matters because much of the traffic users generate on the open internet does not terminate on Cloudflare's own infrastructure. When a destination does not sit on Cloudflare's network—which serves an average of 28M HTTP requests per second—Cloudflare relies on its private backbone and interconnections to carry the traffic. With the Microsoft 365 optimization, Cloudflare identifies Office 365 traffic and steers it toward Microsoft's service endpoints with minimal additional processing.

Securing everything except the trusted route

Optimizing Microsoft 365 traffic does not mean trusting it blindly. While Microsoft-bound connections take the most direct route with little inspection, all other traffic is subject to Cloudflare's Zero Trust security controls, delivered from edge data centers rather than through centralized appliances. Those controls include a next-generation firewall for filtering connection attempts, a fast DNS resolver that checks queries against phishing and malware domain data, and a Secure Web Gateway that can inspect HTTP traffic for data loss, viruses, or isolate browsers for risky sites and categories.

The architecture addresses a fundamental tension of SaaS-delivered work: browsers make any device a workstation, but the same browser can visit malicious lookalike sites or download malware that threatens SaaS-stored data. Cloudflare's layered approach filters at the network level, blocks dangerous domains at the DNS level, and inspects traffic at the HTTP layer—all without slowing the trusted path to Microsoft 365.

Shadow IT visibility and SaaS control

Cloudflare's Zero Trust suite also analyzes and categorizes requests to all applications, producing a Shadow IT report without requiring additional software. Administrators can mark each application as approved, unapproved, or unknown pending investigation. Microsoft 365 traffic is marked approved by default in deployments using the new one-click enablement.

That visibility often reveals that users are working in SaaS platforms the organization has not sanctioned. When appropriate, teams can block requests to those destinations entirely, or restrict specific activities—for example, preventing file uploads to any tool other than OneDrive. In this way, teams using Microsoft 365 can enforce that data stays within the approved productivity suite.

Enabling the optimization

The Microsoft 365 setting in the Cloudflare One dashboard handles the routing decisions when traffic is currently directed through Cloudflare gateways. The setting applies a "Do not inspect" policy to Office 365 connections automatically, so those requests are processed with the least possible overhead even when they enter Cloudflare's network.

Existing customers can enable the feature from the Cloudflare for Teams dashboard:

  1. Navigate to Settings > Network.
  2. For Exclude Office 365 traffic and Bypass Office 365 traffic, click Create entries.

BLOG-842 Embedded Image - Z0FD7u

Microsoft's Networking Partner Program was established to connect customers with networking vendors whose deployment guidance aligns with Microsoft's own connectivity principles for Microsoft 365. With Cloudflare One, organizations using the WARP client can now apply that alignment to their Office 365 traffic while keeping the full security suite active for SaaS apps, on-premises applications, and general internet traffic.