API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-180 · Authentication & identity

Cloudflare Access for Infrastructure adds independent MFA for SSH with YubiKey PIV

Cloudflare Access for Infrastructure added configurable independent MFA for SSH connections using YubiKey PIV keys on 1 July 2026, with per-application and per-policy controls and an optional MFA session duration.

Cloudflare AccessAccess for Infrastructureindependent MFASSHYubiKey PIV

Previous state

Cloudflare Access independent MFA did not yet support Access for Infrastructure SSH connections.

Current state

Access for Infrastructure can require an enrolled YubiKey PIV key as an independent MFA factor for SSH, with controls set per application or policy and an administrator-defined MFA session duration.

Who needs to care

Administrators and users of Cloudflare Access for Infrastructure SSH applications where a hardware-backed independent MFA factor is required.

What to do

Enroll the required PIV keys, configure independent MFA only on the intended infrastructure applications or policies, set an appropriate MFA session duration, and validate the SSH client flow before relying on the control.

What the source does not prove

The first-party changelog establishes independent MFA for Access for Infrastructure SSH using YubiKey PIV keys. It does not claim automatic enablement, support for every protocol or MFA method, or changes to unrelated Access authentication state.

Lifecycle history

Dated event sequence

  1. Infrastructure independent MFA added

    Cloudflare added YubiKey PIV-backed independent MFA for Access for Infrastructure SSH connections with per-application and per-policy controls.

Evidence ledger

First-party sources

  1. 01
    Cloudflare Developers — Independent MFA for infrastructure applications

    Official Cloudflare Access changelog · 2026-07-01

    Open official source ↗