Cloudflare and Microsoft Extend Joint Zero Trust Coverage

Cloudflare and Microsoft have deepened their partnership to give joint customers a global Zero Trust security perimeter for applications hosted on Azure or running on-premises. The integration pairs Azure Active Directory's identity and access management with Cloudflare's network and Access service, addressing the shifting security boundary created by distributed workforces.

Cloudflare partners with Microsoft to protect joint customers with a Global Zero Trust Network

Why Zero Trust Matters Now

The traditional castle-and-moat security model is giving way to architectures where every user and resource is verified regardless of location. As companies increasingly rely on Azure's cloud portfolio, Zero Trust has become a core part of their cloud and SaaS strategy.

Cloudflare Access sits in front of both Azure-hosted and on-premise applications, acting as an on-ramp to Cloudflare's global network—spanning more than 250 cities—and the rest of the Internet. Every request is evaluated for security, including user identity, regardless of where the user or application resides.

Performance is a key element of the offering. Cloudflare processes an average of over 32 million HTTP requests per second for its customers. When applications are not hosted on Cloudflare's network, the company's private backbone and connections with more than 10,000 networks globally route users efficiently.

How Cloudflare Access Works

Cloudflare Access is Cloudflare's Zero Trust Network Access (ZTNA) solution. When internal applications on Azure or on-premises are protected by Access, they behave like SaaS applications for employees, who log in with a consistent and simple flow. Access acts as a unified reverse proxy that authenticates, authorizes, and encrypts every request.

Identity integration is built in: Access works out of the box with major identity providers, including Azure Active Directory, so existing policies and users carry over for conditional access to web applications. Administrators can, for example, restrict an internal kanban board to employees only or lock down a finance application, excluding contractors.

Device-level control is also available using TLS with Client Authentication, which limits connections to devices holding a valid client certificate signed by the corporate CA. Access verifies both the device certificate and user credentials before granting entry.

BLOG-968 Embedded Image - Daic8U

For added protection, Cloudflare Tunnel keeps internal applications from being exposed to the public Internet. The tunnel connects the Azure environment directly to Cloudflare's network, so the application has no publicly accessible IP address.

Coverage for Legacy Applications

Cloudflare is now an Azure Active Directory secure hybrid access partner, enabling centralized management for legacy on-premise applications that traditionally required code changes to support modern authentication. With Azure AD secure hybrid access, joint customers can deploy Access as an additional security layer in front of those applications without significant development work.

BLOG-968 Embedded Image - uJ90eQ

Once integrated, customers gain access to Azure AD features including:

  1. Multi-factor authentication (MFA)
  2. Single sign-on (SSO)
  3. Passwordless authentication
  4. Unified user access management
  5. Azure AD Conditional Access and device trust
BLOG-968 Embedded Image - VdFmVf

Two Integration Paths

Joint customers can secure their Azure-hosted or on-premise applications through two integrations:

1. Cloudflare Access integration with Azure AD. Administrators can integrate Azure AD with Cloudflare Zero Trust and define access policies based on user identity, group membership, and Azure AD Conditional Access policies. Users authenticate with their Azure AD credentials, and additional policy controls—such as device posture, network, and location—are available. Setup typically takes under a few hours.

BLOG-968 Embedded Image - luPFwC

2. Cloudflare Tunnel integration with Azure. Cloudflare Tunnel can expose applications running on the Microsoft Azure platform. A prebuilt Cloudflare Linux image is available on the Azure Marketplace, and deploying it to an Azure resource group simplifies connecting Azure applications to Cloudflare's network.

Looking Ahead

Cloudflare says its next steps involve strengthening integrations with Microsoft Azure over the coming months, allowing customers to further implement a SASE perimeter. Existing Cloudflare Zero Trust users interested in the Azure integration can consult Cloudflare's developer documentation or contact their Cloudflare CSM or AE for guidance.