Cloudflare and CrowdStrike unite Zero Trust and endpoint defense
Cloudflare has expanded its partnership with CrowdStrike, adding multiple new integrations that link Cloudflare's Zero Trust suite with CrowdStrike's endpoint detection and response (EDR) and incident response capabilities. The goal is to give security teams a unified way to assess device health, enforce access policies, and accelerate threat remediation across endpoints, applications, and networks.
The integrations are designed to plug into existing technology stacks rather than require rip-and-replace deployments. Joint customers can now use CrowdStrike's Falcon platform and Cloudflare's network together to verify device posture before granting access, share telemetry for faster threat detection, and respond to active attacks more quickly.
Device posture checks at the edge
Cloudflare Access already determines whether a user should reach an application by checking identity, device posture, location, multifactor method, and other attributes on every request against Cloudflare's global network, which spans more than 250 cities in over 100 countries and blocks an average of 76 billion cyber threats daily. Cloudflare Gateway applies similar controls when users connect to the broader internet, filtering and logging traffic at the nearest data center rather than back-hauling it to a central location.
With the new CrowdStrike integration, administrators can layer CrowdStrike's Zero Trust Assessment (ZTA) scores into those Access and Gateway policies. ZTA provides continuous, real-time posture assessments across all endpoints regardless of location, network, or user. The scores enable conditional policies based on device health and compliance, and are re-evaluated with every connection request, making access decisions adaptive to the device's current state.
Organizations can require a minimum ZTA score or agent version before granting access. Because these checks work across the entire Zero Trust platform, they can be combined with other policies involving Browser Isolation, tenant control, antivirus, or any other part of a Cloudflare deployment.
Telemetry sharing and incident response
Cloudflare joined the CrowdXDR Alliance in December 2021, enabling security signals from Cloudflare's network to be correlated with CrowdStrike's endpoint protection. The combined telemetry helps mutual customers identify and mitigate threats anywhere across their network, rather than in isolated silos.
CrowdStrike also serves as one of Cloudflare's incident response partners. Its response team handles active under-attack situations, helping customers contain the incident and restore web properties and networks. The partnership is meant to enable rapid remediation and minimize downtime when an attack occurs.
"The speed in which a company is able to identify, investigate and remediate a threat heavily determines how it will fare in the end," said Thomas Etheridge, Senior Vice President, CrowdStrike Services. "Our partnership with Cloudflare provides companies the ability to take action rapidly and contain exposure at the time of an attack, enabling them to get back on their feet and return to business as usual as quickly as possible."
Setting up the integration
Customers using Cloudflare's Zero Trust suite can add CrowdStrike as a device posture provider in the dashboard under Settings → Devices → Device Posture Providers. The required details from the CrowdStrike dashboard are the Client ID, Client Secret, REST API URL, and Customer ID.
Once the posture provider is created, administrators can define specific device posture checks that require devices to meet a certain ZTA score threshold. These checks can then be used to build conditional Access and Gateway policies that allow or deny access to applications, networks, or sites. Administrators can choose to block or isolate users or user groups with malicious or insecure devices.
"The CrowdStrike Falcon platform secures customers through verified access controls, helping customers reduce their attack surface and simplify, empower and accelerate their Zero Trust journey," said Michael Sentonas, Chief Technology Officer, CrowdStrike. "By expanding our partnership with Cloudflare, we are making it easier for joint customers to strengthen their Zero Trust security posture across all endpoints and their entire corporate network."
Roadmap
Cloudflare plans to deepen the integration in the coming months by allowing customers to correlate Cloudflare logs with Falcon telemetry for timely detection and mitigation of sophisticated threats. Documentation for enabling the CrowdStrike integration is available on Cloudflare's developers site.



