API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-055 · Authentication & identity

Cloudflare Access adds cross-account identity-provider federation

Organisations can configure an identity provider once and share read-only federated connections across recipient Cloudflare accounts.

Cloudflare AccessIdP federationmulti-accountidentity

Previous state

Identity-provider configuration had to be repeated or separately managed across accounts.

Current state

A source account can federate a centrally managed IdP to recipient accounts through read-only bridged connections.

Who needs to care

Multi-account Cloudflare organisations using Access identity providers.

What to do

Choose a source account, govern recipient membership and test lifecycle behaviour as accounts join or leave.

What the source does not prove

Recipient accounts cannot independently edit or delete the federated IdP connection.

Lifecycle history

Dated event sequence

  1. Federation released

    Cross-account read-only IdP sharing became available.

Evidence ledger

First-party sources

  1. 01
    Cloudflare Developers — Cross-account IdP federation

    Official product changelog · 2026-06-04

    Open official source ↗