Cloudflare One adds behavioral risk scoring for Zero Trust users
Cloudflare is rolling out user risk scoring across its Cloudflare One SASE platform, giving security teams an automated way to flag suspicious user behavior without manually parsing through large volumes of log data. The feature, part of the Zero Trust offering, applies AI and machine learning to telemetry already flowing through Cloudflare's network to detect abnormal activity and potential indicators of compromise.
The shift in mindset from "trust but verify" to continuous Zero Trust verification has made contextual access decisions more important than ever. Administrators increasingly need to consider not just what a request contains, but whether it makes sense given factors like the user's typical login location or time of day. Previously, that kind of contextual risk analysis required dedicated staff to dig through logs. Cloudflare's new approach automates it with configurable behavioral rules that generate dynamic risk scores for users.
How user risk scoring works
The Zero Trust user risk scoring engine examines behaviors — actions observed by Cloudflare One that a user takes within the account. When a user performs an action that matches an enabled risk behavior, Cloudflare assigns the user a risk level of Low, Medium, or High. This form of user and entity behavior analytics (UEBA) is designed to help teams detect account compromise, policy violations, and other risky activity in near real time.
Behavior tracking builds on log data already generated within a Zero Trust account. Cloudflare emphasizes that no new user data is collected or stored beyond what already exists in the platform's logs, which remain subject to the same log retention timeframes as before.
One predefined behavior available today is "impossible travel" detection. This triggers when a user logs in from two locations so far apart that the user could not have physically traveled between them in the elapsed time. As an example, a user logging into a Cloudflare Access-protected finance application from Seattle, and then appearing in Sydney minutes later, would be flagged as high risk. If a user triggers multiple risk behaviors, the highest severity level triggered is assigned as the user's score.
Impossible travel detection flags a user as high risk after logins from geographically distant locations occur in quick succession.
Enabling and tuning risk behaviors
All risk behaviors are disabled by default, meaning users won't receive scores until an administrator explicitly decides which behaviors matter to the organization and at what severity. To activate a behavior, an administrator must first make sure the behavior's requirements are satisfied — for example, a DLP profile must exist before the engine can detect a user triggering a high number of DLP policies. Once that prerequisite is confirmed, enabling the behavior is a quick process from the Zero Trust dashboard.
Administrators can also change the default risk level of any behavior, adjusting whether a given action is scored Low, Medium, or High to fit their security posture. For cases where a security team has investigated a user and wants to clear a score, admins can navigate to Risk score > User risk scoring, select the user, and choose "Reset user risk" followed by "Confirm." The user then drops off the risk table until they trigger another behavior.

Risk behaviors are simple to turn on from the Zero Trust dashboard.
Availability
User risk scoring and DLP features ship as part of Cloudflare One, which converges Zero Trust security and network connectivity services under a single control plane. Interested organizations can request access through a consultation or by contacting their Cloudflare account manager.



