Gateway policies that follow the user, not just the device
Cloudflare Gateway’s HTTP filtering, introduced during Zero Trust Week, proxies all Internet-bound traffic from enrolled devices through Cloudflare’s network, where organization-wide rules can block data loss and protect team members. But uniform rules rarely fit real organizations. A marketing team may need social media access, a finance group may warrant extra protection, and security teams often must trace activity back to a single user after an incident.
Gateway now lets administrators build policies around a user’s identity and correlate that identity with entries in the HTTP activity logs. The feature reuses the identity provider (IdP) integration already configured for Cloudflare Access, so no separate setup is required.
Fine-grained enforcement with rule precedence
Previously, DNS and HTTP policies applied equally to every user. Gateway’s new identity-based rules change that. For example, an organization-wide content policy might restrict social media, but the marketing team needs to manage campaigns from corporate devices. An administrator can create a rule that always allows the marketing team to reach social media, then add a second rule blocking social media for everyone else. Dragging the block rule below the marketing rule gives it lower precedence, ensuring users outside marketing are evaluated against the stricter policy.
Identity integration and rule attributes
Gateway leverages the IdP integration used by Cloudflare Access to add identity to both rules and logs. Customers can connect one or more providers, including corporate options like Okta and Azure AD alongside public providers like GitHub and LinkedIn. When users first launch the WARP client, they authenticate with a configured provider. After login, Gateway attributes each connection to that user’s identity.
Depending on IdP capabilities, rules can be built on:
- User email
- User group names*
- SAML attributes
- Device ID
*Some IdPs use group email in place of a group name.
User-level visibility in activity logs
Policy enforcement is only half the equation. Gateway’s activity logs now let administrators filter HTTP traffic by specific users and device IDs. This visibility supports both routine auditing and more urgent scenarios—identifying users attempting to bypass content policies, or isolating devices that may be compromised. Administrators can keep pace with evolving threats while maintaining a clear view of user and data activity.
Browser isolation for high-risk users
Cloudflare also announced its isolated remote browser, designed to protect against zero-day threats unknown to threat intelligence. When integrated with Gateway, organizations can route individual users through the remote browser. For example, an employee in finance who interacts with procurement or fund disbursement systems could be prevented from using a native browser for public Internet traffic, with that traffic forced into an isolated browser instead. Internal systems would still use the native browser. Administrators can create an isolate rule alongside other Gateway policies, protecting against known threats while guarding against everything else—without requiring users to switch between browsers or client apps.
Browser Isolation is available in private beta, with a wait list for interested teams.
Availability and roadmap
Identity-based Gateway policies are available at no additional cost to any Gateway Standard or Teams customer. Cloudflare plans to extend these capabilities from individual remote users to branch offices and data centers. Ongoing work includes network-level rules, in-line anti-virus scanning, and data loss prevention.



