Gateway Enforcement Now Part of Cloudflare Access Policies
Cloudflare has announced that Access policies can now require all traffic to protected applications to be filtered through Cloudflare Gateway. The integration applies to both self-hosted and SaaS applications, and it extends the enforcement of Gateway-based rules to the application login flow itself.
The capability addresses a gap in the Zero Trust model Cloudflare Access was built around. Access checks identity and device posture signals at the edge for every request to protected resources. But those checks only apply after a connection reaches the application. Traffic that happens before that point, or on devices not routed through the corporate network, remained outside the scope of Access policy enforcement.
Closing the Pre-Connection Gap
Cloudflare Gateway was designed to handle that earlier stage. A lightweight agent on user devices proxies all Internet-bound traffic through Cloudflare's network, where it is inspected in one of over 200 data centers. Gateway can block connections to malware destinations, restrict file uploads and downloads, and filter by content category.
With this release, administrators can build Access rules that only permit connections from devices running Gateway in always-on mode. That means a device must be secured and filtered by Gateway before it can reach applications behind Access. The requirement also covers SaaS applications, where Gateway logs every request and connection, giving organizations an audit trail for services like Salesforce, Office 365, and Workday.
The integration also addresses a log integrity concern raised by customers: if a user can log into a SaaS application from a device that bypasses Gateway, the organization loses visibility into that traffic. By adding a Gateway requirement to the Access ruleset that runs during the SSO login flow, administrators can prevent logins from any device that is not connected through Gateway.
User-Based URL Controls for SaaS
Cloudflare also detailed how the integration helps with user-based data controls inside SaaS applications that lack native support for such rules. Gateway can restrict access to specific URLs by user group, which allows policies that only permit certain team members to reach records or dashboards at known URLs.
Previously, that level of control was only effective while the user was running Gateway. If a user connected without it, the policy was lost. The Access integration ensures the Gateway rules are always enforced—if a user is not running Gateway, they cannot log in to the application in the first place.
Availability
The feature is available now in Cloudflare for Teams accounts on the Teams Standard or Teams Enterprise plan. Documentation for getting started is available online. Cloudflare also offers a free Teams plan that includes Gateway DNS filtering and Access for up to 50 users.



