Cloudflare Extends WARP Deployment to Leading MDM Platforms
Cloudflare has announced new partnerships with mobile device management (MDM) vendors Microsoft Intune, Ivanti, JumpCloud, Kandji, and Hexnode. The goal is to streamline how organizations deploy Cloudflare WARP, the agent that encrypts device traffic to Cloudflare's edge network, as part of a Zero Trust security strategy.
Alongside the partnerships, Cloudflare is publishing deeper documentation for deploying WARP with these MDM tools, giving administrators a guided process for enrolling entire device fleets. This builds on the Cloudflare for Teams platform, which replaces legacy security perimeters with access controls and Secure Web Gateway capabilities delivered from Cloudflare's global network.
Why MDM Matters for Distributed Workforces
Mobile Device Management (MDM), also referred to as Unified Endpoint Management (UEM), centralizes the administration of an organization's devices from a single platform. This is particularly important now that remote and hybrid work is the norm. Consider a growing consultancy that begins with a bring-your-own-device policy and transitions to corporate-issued hardware. As the workforce expands nationwide and clients raise data-handling requirements, the CEO needs answers to questions like: Are all devices updated and uncompromised? Can a lost laptop be wiped remotely to prevent data leaks?
MDM solutions handle these tasks—configuring user permissions, rolling out OS updates, installing software, and providing IT teams with visibility across managed and unmanaged devices—all without requiring a trip to an IT help desk.
Flexible Deployment Options for WARP
Cloudflare WARP enables identity- and posture-aware policy enforcement at the endpoint. The client has been optimized for varied deployment approaches, works across Windows, macOS, Linux, Chrome OS, iOS, and Android, and shares a consistent set of parameters regardless of how it is installed. This gives admins a uniform experience whether they are deploying manually or through an MDM.
The documentation illustrates common Windows deployment scenarios, which differ mainly by command-line arguments:
- Authenticate users with the organization's Teams configuration: For full traffic routing through WARP, which is necessary for HTTP filtering, Browser Isolation, and device posture features, users must be authenticated to a Teams organization.
- Silent install with service tokens: If identity isn't required, service tokens can be used to enable the same traffic routing without presenting the client's initial UI prompt.
- Graceful handling of restricted tunnel environments: For employees in regions where tunneled encryption isn't permitted, a deployment mode can allow them to turn off WARP while still enforcing the company's DNS filtering rules.
Partner Integrations Take Shape
Cloudflare's new MDM partnerships are intended to ensure that WARP is compatible with the tools organizations already use for endpoint management.
- Microsoft: The collaboration aims to strengthen security posture for joint customers while supporting productivity in a Zero Trust world.
- Hexnode: Sees ZTNA adoption as a prerequisite for enterprise endpoint management and views this integration as a step forward.
- Ivanti: Emphasizes the need to accelerate Zero Trust across the many devices employees use, with the partnership improving IT and employee experiences.
- JumpCloud: Notes that the combination of identity, device, and network security is foundational to a Zero Trust approach.
- Kandji: Focuses on enabling IT teams to deploy Cloudflare network security across Apple fleets via device management software, at any scale.
Getting Started with MDM Deployments
Administrators can start with current documentation for deploying Cloudflare for Teams via:
- Microsoft Intune
- Kandji
- JumpCloud
- Hexnode
The Ivanti deployment guide is slated to arrive soon. For organizations using an MDM vendor not on the list, Cloudflare points to its MDM Partnerships page for contact options.



