Device trust meets zero-trust: Cloudflare for Teams adds Tanium endpoint checks

Cloudflare Access launched two years ago with a simple premise: replace the castle-and-moat VPN model with identity-based enforcement running on Cloudflare’s edge network. Instead of trusting anyone inside a firewall, Access requires every request to be authenticated against policies built by administrators. Identity is checked continuously, not just at the initial VPN handshake, and every request is logged for audit.

The gap in that model has always been the endpoint itself. A user with valid credentials and 2FA can log in from any device — a personal iPad, a compromised corporate laptop, a machine that fails compliance checks. Identity alone can’t tell an organization whether the device making the request is managed, patched, or healthy.

That changes today. Cloudflare for Teams customers can now integrate Tanium’s endpoint management platform with Cloudflare Access, adding device posture checks alongside existing user authentication.

Closing the device gap

Cloudflare Access has always secured applications in a zero-trust fashion. Rather than trusting any user inside a private network, it evaluates each request against administrator-defined rules. Those checks happen at Cloudflare’s network, spread across data centers in over 200 cities, so performance doesn’t suffer for the added scrutiny.

Behind the scenes, administrators configure which users may reach which tools. When a user requests access, they authenticate through an identity provider, and Cloudflare checks that login against the approved list. Up until now, that login was the only factor in the decision.

With Tanium’s integration, policy decisions now have a second dimension: device health. Tanium’s unified platform runs agents on corporate devices that continuously evaluate and monitor endpoint status. Fifty percent of the Fortune 100 and four of five U.S. military branches rely on Tanium for endpoint visibility and control.

Tanium’s single agent replaces multiple legacy approaches to endpoint management and security. IT teams use it for inventory, configuration, and performance monitoring; security teams use it for detection and response, patch updates, and data risk enforcement.

Set up in 10 minutes

The integration is designed to be straightforward. Configuring Tanium as a device posture provider inside Cloudflare for Teams takes about 10 minutes, after which administrators can write Access policies that require both SSO login and a managed, healthy Tanium-monitored device.

Setup involves three steps:

Tanium’s endpoint security meets Cloudflare for Teams Embedded Image - 03vZZA

Administrators add Tanium as an authentication mechanism in the Cloudflare for Teams UI, providing their Tanium public certificate and the endpoint used for device validation. Cloudflare Access can then query the device’s health during connection evaluation without exposing it to impersonation risk.

Tanium’s endpoint security meets Cloudflare for Teams Embedded Image - QIpxfO

The Windows Cloudflare for Teams public certificate is copied into the Tanium deployment. That certificate ensures only the organization’s unique Cloudflare for Teams account can query endpoint data from the Tanium agent.

Finally, administrators add device posture rules to their Cloudflare Access policies. When a user connects to a protected resource, Cloudflare’s network verifies the user’s identity provider login and confirms they’re coming from a Tanium-monitored healthy device.

For the end user, the check is seamless. Access runs in all of Cloudflare’s data centers worldwide, keeping enforcement decisions within 100ms of 99% of the Internet-connected population. Direct integration with the Tanium agent means the evaluation doesn’t require a round trip to the Tanium administrative layer.

Available now

Organizations get defense in depth for corporate applications when Tanium and Access work together. All Cloudflare for Teams customers with a Tanium deployment can add device posture to their policies today at no additional cost.

Cloudflare is standing by to assist with the setup, and documentation is available from both Cloudflare for Teams and Tanium’s endpoint identity guides.