Making the Zero Trust front door feel like yours

More than 10,000 organizations use Cloudflare Access to let employees, partners, and contractors reach the applications they need. As that user base grows from small teams to some of the world’s largest enterprises, the screens those users see during authentication are becoming an important part of the experience. Cloudflare is introducing customizable pages for Access, covering the login screen, block pages, and the application launcher.

Where Access shows up

Most teams start replacing a virtual private network with Cloudflare Access for one of two reasons: their VPN trusts too much by default, or maintaining it has become a burden. With Access, administrators connect protected resources through a Cloudflare Tunnel, existing DNS infrastructure, or forced SaaS application logins, then layer granular Zero Trust rules on top to decide who reaches what.

To the end user, Access should behave like a quiet security guard checking identity and device posture at every door. But when users do interact with Access, those moments matter. The screens they see should help them make decisions, not just block or admit them silently.

BLOG-1673 Embedded Image - hyHj0x

Access supports multiple identity providers at once, which is useful when working with contractors or acquired teams, and it can be configured per application. When users arrive, Access needs to know which provider to send them to for initial authentication, so it presents a selection screen with guiding text that administrators can set.

BLOG-1673 Embedded Image - jjplo5

Once teams move their applications behind Access, the service becomes the front door to daily work. The Access Application Launcher presents users with all the applications they can reach, letting them click any tile to launch it.

BLOG-1673 Embedded Image - k2Uv6E

When a user does not have the right permissions, Access displays a block page instead of a generic browser error or a dropped connection, so the user understands what happened and why.

Why the pages need to change

Large enterprises adopting a Zero Trust VPN replacement face a different communication challenge than small teams. CIOs and CSOs deploying Access to tens of thousands of employees and contractors need to anticipate questions from users who have never heard of Cloudflare. Those users don’t need to know the vendor powering their access. They just need to reach their tools securely.

To support that, administrators need more room to communicate, and Cloudflare’s branding needs to step aside.

What can be customized

With the release of Access page customization, administrators will be able to modify:

  • The login screen
  • Access denied (block) errors
  • The Access Application Launcher

What’s next

Page customization in Cloudflare Access is being built on the same template that reverse proxy customers already use to modify pages shown to end users. Cloudflare is looking for customers interested in participating in a closed beta to provide feedback as the configuration option is refined. Interested teams can sign up here.