Parent-child DNS policy management for multi-tenant environments
Cloudflare is announcing a new integration between its DNS Filtering solution (Cloudflare Gateway) and its Partner Tenant platform. The integration introduces parent-child account configurations designed for Managed Service Providers (MSPs) and large organizations that need to enforce corporate-wide security policies while allowing customization at the business unit or account level.
The Tenant platform, launched in 2019, lets Cloudflare partners create and manage millions of customer accounts. Cloudflare Gateway, which launched in 2020, has expanded from protecting personal networks to Fortune 500 enterprise deployments. This new integration adds the policy hierarchy that MSPs need when managing large, multi-tenant deployments.
Why MSPs need tiered policy structure
MSPs are third-party companies that remotely manage IT infrastructure and end-user systems for their customers. Many CIOs outsource security operations to MSPs to free internal teams for strategic work while gaining access to competitively priced security expertise. A key criterion in selecting an MSP is whether that provider can deliver modern, cost-effective security solutions that scale across a distributed, hybrid-work environment.
DNS filtering is often the first Zero Trust service MSPs deploy because it offers rapid time-to-value. It works by using the Domain Name System to block access to malicious websites, protecting users from ransomware, malware, phishing, and other Internet threats. Filtering policies are typically set at the organizational level, but many deployments require independent management at the account or business-unit level—which demands a parent-child policy hierarchy.
Tiered Zero Trust accounts
With individual accounts for each end customer, MSPs can fully manage deployments or offer a self-service portal backed by Cloudflare configuration APIs. But pushing updates to a single policy across thousands of child accounts was previously a scalability problem—what should be one API call required one call per end customer account.
The new model introduces a top-level, or parent, account. MSPs set global policies on the parent account that apply to all DNS queries before subsequent end customer (child) policies are evaluated. Each child account can further refine DNS filtering to meet its own needs without affecting other child accounts.
Child accounts retain full Gateway functionality. Each can create its own custom block page, upload its own certificates for displaying those pages, and set up its own DNS endpoints (IPv4, IPv6, DoH, and DoT) via Gateway locations. Default limits on policies, locations, or lists are the same for parent and child accounts as for standard non-MSP Gateway accounts.
How partners are using the feature
US federal government
Cloudflare and Accenture Federal Services (AFS) were selected in 2022 by CISA and the Department of Homeland Security to build a protective DNS solution for more than 100 civilian agencies. The joint solution uses Cloudflare's protective DNS resolver to filter DNS queries from government offices while streaming events to Accenture's platform for unified administration and log storage.
AFS offers each department a central interface to adjust DNS filtering policies, built on Cloudflare's Tenant platform and Gateway client APIs. CISA operates as the parent account, setting global policies, while individual agencies—the child accounts—can bypass select global policies and set their own default block pages.
The implementation required two enhancements to Cloudflare's DNS location handling. First, CISA wanted to assign dedicated IPv4 resolver addresses from the parent account to child accounts, so all agencies share the same default IPv4 addresses and onboarding is simpler. Second, CISA wanted fail-closed behavior: if a DNS query did not match any configured location, it would be dropped, ensuring only authorized IPv4 networks access the protective service. IPv6, DoH, and DoT endpoints required no special handling, since those are customized per DNS location.
Malwarebytes
Malwarebytes integrated Cloudflare Gateway into its Nebula platform to provide a DNS filtering module. Nebula is a cloud-hosted security operations solution that manages malware and ransomware incidents from alert to resolution. The new module lets Malwarebytes customers filter on content categories and apply policy rules to groups of devices.
Cloudflare's solution uses DNS-over-HTTP (DoH) to segment users across unique locations, with a unique token per device to track device IDs and apply the correct policies. The integration was completed through the Tenant API for alignment with Malwarebytes' existing workflow, and was designed to allow future expansion into additional Zero Trust services like Cloudflare Browser Isolation.
Large global ISP
Cloudflare is also working with a large global ISP that uses the Tenant and Gateway APIs to offer DNS filtering as part of a family security solution. The service was implemented with minimal engineering effort and reached over one million accounts in its first year.
Partner roadmap: what MSPs can expect
Managed service providers have become a critical line of defense for organizations navigating a threat landscape that does not discriminate by company size. Smaller teams, in particular, often lack the dedicated security staff and tooling required to maintain a strong security posture. MSPs fill that gap by supplying expertise and advanced security infrastructure that meaningfully lowers risk for their clients.
Cloudflare has outlined several improvements designed to make its Zero Trust platform more manageable for MSP partners operating at scale. The roadmap includes:
- A refreshed tenant management dashboard that simplifies account and user administration.
- Extended multi-tenant configurations across the entire Zero Trust product set, easing deployment of secure hybrid work solutions for multiple customers.
- An expanded user roles and access model for MSP partners, enabling hierarchical access that makes it easier for partner teams to support and manage numerous accounts.
The driving goal behind these changes is straightforward: preserve Cloudflare's reputation for ease of use while positioning the platform as the go-to Zero Trust option for service and security providers. Because Zero Trust at Cloudflare functions as a composable, unified platform, the combination of individual products, features, and the partner network is what delivers the full security value to end customers.
For organizations interested in exploring MSP partnerships or testing the technology directly, Cloudflare offers two entry points:
- Details on the MSP partner program are available at https://www.cloudflare.com/partners/services.
- Organizations can start with DNS Filtering and Zero Trust at no cost by signing up for 50 free seats here.



