Perimeter security is no longer enough

Traditional network-perimeter security assumes anything inside the boundary can be trusted. That assumption breaks down as applications and users move off the corporate network into distributed, cloud-based environments. Zero Trust inverts the model: no user or device is trusted by default, and every access request must be authenticated and authorized before reaching an application or data.

For organizations that need to put Zero Trust controls in place, Ping Identity and Cloudflare Access complement each other. Ping handles identity management—single sign-on, lifecycle and federation—while Cloudflare Access sits in front of applications and enforces per-request access policies.

Enforcing authentication at the application layer

Web applications bring scalability and cost advantages, but they also expand the attack surface. Cloudflare Access policies can require specific types of MFA, check device posture and even evaluate custom logic before granting access. That gives security teams granular control they can manage from a single place, ensuring enforcement is consistent across every protected application.

Ping Identity adds SSO on top: users authenticate once and are then granted access to every application they are authorized to use. That cuts down on password fatigue and simplifies the administrative burden of managing credentials across many systems.

Bringing legacy applications under Zero Trust

Older applications are often the weakest link. They may rely on authentication methods that predate SAML or OIDC, making modern controls like MFA difficult or impossible to bolt on directly. Rewriting them is usually not an option—modifying legacy code to add modern security features is risky, expensive or outright infeasible.

Placing Cloudflare Access in front of those applications sidesteps the problem entirely. Users must pass Cloudflare's policy checks—including MFA and SSO via Ping—before any request reaches the legacy application. The application itself never needs to change. Unauthorized users are blocked at the edge, and the risk of credential theft or account takeover drops without a code rewrite.

PingOne support now generally available

Cloudflare now offers full integration support for PingOne as an identity provider. PingOne customers can connect their identity management setup directly to Cloudflare Access and get a working Zero Trust perimeter around their applications without custom glue code.

SCIM synchronization on the roadmap

Cloudflare has also announced plans to add user and group synchronization via SCIM. Once available, that will let organizations keep identity data in Ping Identity and Cloudflare Access in sync automatically, reducing manual administration and improving the end-user experience when entitlements change.

What the combination covers

Ping Identity and Cloudflare Access together address the two halves of Zero Trust: knowing who is asking and deciding whether to let them in. Ping provides the identity layer—SSO, federation and user management—and Cloudflare Access enforces the access policy at the application edge, with MFA and session checks applied consistently.

For organizations running a cloud-first strategy, the pair offers a practical path to Zero Trust. Security and IT leaders get proactive protection aligned with Zero Trust best practices, as Ping Identity's SVP of Product & Technology Loren Russon notes: “A cloud-native Zero Trust security model has become an absolute necessity as enterprises continue to adopt a cloud-first strategy.”

Cloudflare says it will continue expanding integration with Ping Identity and other identity management providers, giving organizations more options for protecting applications and data without rebuilding them from the ground up.