Cloudflare Zero Trust
Time Required
1 Hour
Difficulty
Easy
Required Knowledge
SSH
Set up Zero Trust
Browse to https://one.dash.cloudflare.com/
Follow the onscreen steps to create a Zero Trust organization
When prompted select the Free Zero Trust plan - you will still need to provide payment details
Set up your first Access Policy
Administrator / your policy
In this step, we will create your generic access policy. This policy will be configured to allow only your email address to access resources
Open your Zero Trust dashboard, https://one.dash.cloudflare.com/
On the left, select Access Controls > Policies
Click on Add a policy
Basic Information:
Policy Name
Your name or 'administrator'
Action
Allow
Add rules:
Selector
Emails
Value
Your email address and/or the list of other 'administrators'
Click on Save
Friends and Family Policy
In this step, we will create your generic 'friends' access policy. This policy will be configured to allow your specific friends, email email address, to access certain applications
This policy set is useful for specific items that you want to lock down to specific people
Open your Zero Trust dashboard, https://one.dash.cloudflare.com/
On the left, select Access Controls > Policies
Click on Add a policy
Basic Information:
Policy Name
Friends and Family
Action
Allow
Add rules:
Selector
Emails
Value
A list of email addresses you wish to allow
Click on Save
Everyone Policy
In this step, we will create your generic 'everony' access policy. This policy will be configured to allow ANYONE to authenticate
Any applications using the policy will be accessible to the public internet - use this with caution
Open your Zero Trust dashboard, https://one.dash.cloudflare.com/
On the left, select Access Controls > Policies
Click on Add a policy
Basic Information:
Policy Name
Public Internet
Action
Allow
Add rules:
Selector
Everyone
Click on Save
Set up Wildcard application
This is your 'default' application for your site. Anything set to use policy tld_default in Dockflare will use this application for its Authentication
Open your Zero Trust dashboard, https://one.dash.cloudflare.com/
On the left, select Access Controls > Applications
Click on Add Application
Select Self Hosted
Application name: Your Domain name
Click on 'Add public hostname'
Subdomain: *
Select your first domain
Access policies: Select existing, then select your Administrator policy
Click on Next
Click on Next
Click on Save
Repeat for each domain
Now all of your subdomains are secured. If you wish to secure your root domain (eg example.com), follow the same but leave subdomain (Bi) blank
Last updated