Cloudflare and Microsoft Expand Zero Trust Integrations

Cloudflare is extending its partnership with Microsoft to address the challenges CIOs face when combining multiple security solutions. Four new integrations between Azure AD and Cloudflare Zero Trust aim to reduce risk through increased automation, allowing security teams to shift attention from implementation and maintenance to threat response.

Zero Trust fundamentals

The Zero Trust model replaces the traditional "castle and moat" security perimeter with a "never trust, always verify" approach. Instead of granting access to everything once a user passes through a VPN, Zero Trust requires individual authorization for each application—much like needing a key for every locked room rather than just the main entrance.

Key elements include identity (who is requesting access, e.g., Azure AD), applications (a SAP instance or custom app on Azure), policies (rules governing who can access what), and devices (endpoints managed by tools like Microsoft Intune). As digital transformation accelerates and workforces become increasingly distributed, applying security checks to every user and resource request has become essential.

Cloudflare’s Zero Trust Network Access (ZTNA) product treats internal and on-premise applications like SaaS applications, providing employees with a consistent access flow. Cloudflare Access functions as a unified reverse proxy, ensuring every request is authenticated, authorized, and encrypted.

Existing Azure AD integrations

Thousands of customers already use Azure AD with Cloudflare Access. Previous partnership work addressed two key scenarios:

  • Legacy on-premise applications: Through Azure AD's Secure Hybrid Access partnership, customers can apply SSO authentication to legacy applications without additional development. Cloudflare Access adds a security and performance layer in front of these applications.
  • Applications hosted on Microsoft Azure: Joint customers integrate Azure AD with Cloudflare Zero Trust and build rules based on user identity, group membership, and Conditional Access policies. Cloudflare Tunnel, available through Azure Marketplace, exposes Azure-hosted apps without opening them to the public internet.

Microsoft recognized this work with the Security Software Innovator award at the 2022 Microsoft Security Excellence Awards. The new announcements extend these capabilities based on customer feedback.

Four new integrations

Per-application conditional access

Azure AD administrators can now define Conditional Access policies—using parameters like user risk level, sign-in risk, device platform, location, and client apps—and enforce them per application within Cloudflare Access. This allows security teams to apply stricter controls to sensitive systems like payroll while using more lenient policies for general-purpose tools like internal wikis. Both application groups and their associated Azure AD Conditional Access policies plug into Cloudflare Zero Trust without code changes.

SCIM group synchronization

SCIM (System for Cross-domain Identity Management) ensures user identities stay current across both platforms. Changes to Azure AD groups now automatically reflect in Cloudflare Access policies, eliminating manual policy reviews when user attributes change. When a user is deprovisioned in Azure AD, their access across Cloudflare Access and Gateway is revoked near real time, reducing the security risk of stale credentials.

Risky user isolation

Azure AD categorizes users as low, medium, or high risk based on factors including employment type, sign-in behavior, and credential leaks. Cloudflare now supports integrating these Azure AD risk groups with Cloudflare Browser Isolation. High-risk users—such as contractors—automatically receive access through an isolated browser session. When a user's risk classification improves, the isolation policy no longer applies.

Government Cloud support

Through the Secure Hybrid Access program, Government Cloud (GCC) customers will soon be able to integrate Azure AD with Cloudflare Zero Trust. This provides centralized identity and access management while connecting government workloads to the Cloudflare global network rather than exposing them directly to the internet. Users will authenticate with Azure AD credentials and connect via Cloudflare Tunnel.

“Digital transformation has created a new security paradigm resulting in organizations accelerating their adoption of Zero Trust,” said Botond Szakács, Director at Swiss Re. “The Cloudflare Zero Trust and Azure Active Directory joint solution has been a growth enabler for Swiss Re by easing Zero Trust deployments across our workforce allowing us to focus on our core business.”

“Cloudflare has developed robust product integrations with Microsoft to help security and IT leaders prevent attacks proactively, dynamically control policy and risk, and increase automation in alignment with zero trust best practices,” added Joy Chik, President of Identity & Network Access at Microsoft.

Getting started

A reference architecture document covering these integrations is available to help organizations begin their Zero Trust deployment. A joint webinar with Microsoft also demonstrates how to implement the solution. Cloudflare is continuing to develop additional capabilities for the combined offering based on customer requirements.