Periodic reauthentication comes to Cloudflare ZTNA

Cloudflare has made Zero Trust client-based sessions generally available, extending session enforcement from web applications to TCP connections and UDP flows. The feature, first beta-tested during CIO Week 2021, lets administrators require users to reauthenticate at defined intervals before accessing protected network resources.

The core problem: Cloudflare's Zero Trust Network Access (ZTNA) client forwards all traffic from a user's machine to Cloudflare before it reaches the Internet, including traffic destined for internal IPs and hostnames that often host sensitive business applications. Those applications were traditionally protected by VPNs. Unlike VPNs, Cloudflare's ZTNA gives administrators granular policy control over who can reach specific resources. But once a machine was enrolled, the client session persisted indefinitely — an unnecessary risk for lost or stolen laptops, shared workstations, and personal devices.

How session enforcement works

With client-based sessions, a user must reauthenticate with their identity provider before accessing a protected resource. The authentication pop-up appears only when the user attempts to reach such a resource, so users do not see unnecessary prompts. Administrators configure how often reauthentication is required per resource. The system relies on the user's last successful authentication, which is stored and evaluated against any ZTNA policy that has a session configured.

Zero Trust client sessions

Beta findings and planned improvements

During the beta phase, Cloudflare worked with early customers and its own security team to identify weaknesses. Two main issues surfaced before the general availability release: intrusive pop-ups and reliance on browser-based authentication, which is not always possible on certain machines and operating systems.

For pop-ups, Cloudflare developed strategies to present authentication prompts without being disruptive. Future versions will give users more control over when they receive authentication notifications. For environments where browser-based authentication is unavailable, Cloudflare plans to add an option for authenticating directly from the Zero Trust client.

Looking ahead, Cloudflare intends to add support for step-up multifactor authentication and automated enrollment via certificates and Service Tokens. Setup instructions are available in the Cloudflare Zero Trust dashboard documentation.

Sesiones de cliente Zero Trust Embedded Image - rYfvWu