Cloudflare One expands Zero Trust with endpoint security checks

Cloudflare has extended its Cloudflare One platform with new integrations for VMware Carbon Black, CrowdStrike, and SentinelOne, joining its existing Tanium integration. The additions let Cloudflare for Teams customers use signals from their endpoint security vendors to make allow or deny decisions for application access.

Cloudflare One combines network services (Magic WAN, Magic Transit) with Cloudflare for Teams, which is built on a Zero Trust architecture. Instead of trusting connections to corporate resources, every request is intercepted and verified against administrator-defined criteria before access is granted. Access decisions are based on user identity and permissions checked against a customer's identity provider, with traffic running over Cloudflare's global network rather than a traditional VPN backhaul.

Why device posture matters

Remote work has pushed more users onto personal devices that lack enterprise anti-malware or endpoint protection. An infected or unpatched device can expose sensitive applications, violate compliance rules, or spread malware to production systems. Device posture signals — operating system version, patch date, disk encryption status, installed applications, and malware scan status — help IT teams identify at-risk devices across the fleet.

With the new integrations, Cloudflare for Teams can base access decisions on those signals. For example, an access policy can require that a device's serial number matches the company inventory and that a CrowdStrike or VMware Carbon Black agent is actively running before granting access to a protected resource. The WARP client handles encryption and already checks attributes like serial number and device location; the partner integrations add the endpoint security layer on top.

How the integrations work

All integrations begin with securing applications through Cloudflare Access. Setup steps vary by vendor.

Tanium

Tanium requires no extra client software on user devices. Admins input a Tanium certificate in the Cloudflare for Teams Dashboard and enable Endpoint Identity in their Tanium instance. Tanium then appears as a policy check in the Teams Dashboard for any application.

VMware Carbon Black, CrowdStrike, and SentinelOne

These vendors require the WARP client to be deployed on devices, ideally through an MDM solution, though direct download is also available. Configuration happens in the Teams Dashboard under My Team → Devices → Device posture. The dashboard pre-populates values that match typical installations.

Once configured, administrators build rules based on the chosen provider and apply them to applications like any other Access policy. WARP checks whether the endpoint security software is running on the device and relays the status to Access, which then allows or denies the connection. Layered checks, such as MFA and user identity, can be added to the same policy to block credential theft and other malicious access attempts.

Roadmap

Future releases will pull in additional signals, including risk scores from CrowdStrike and VMware Carbon Black, for finer-grained access control. Cloudflare also plans to onboard additional endpoint security vendors.