ST-2026-180 · Authentication & identity
Cloudflare Access for Infrastructure adds independent MFA for SSH with YubiKey PIV
Cloudflare Access for Infrastructure added configurable independent MFA for SSH connections using YubiKey PIV keys on 1 July 2026, with per-application and per-policy controls and an optional MFA session duration.
Previous state
Cloudflare Access independent MFA did not yet support Access for Infrastructure SSH connections.
Current state
Access for Infrastructure can require an enrolled YubiKey PIV key as an independent MFA factor for SSH, with controls set per application or policy and an administrator-defined MFA session duration.
Affected users
Who needs to care
Administrators and users of Cloudflare Access for Infrastructure SSH applications where a hardware-backed independent MFA factor is required.
Required response
What to do
Enroll the required PIV keys, configure independent MFA only on the intended infrastructure applications or policies, set an appropriate MFA session duration, and validate the SSH client flow before relying on the control.
Evidence boundary
What the source does not prove
The first-party changelog establishes independent MFA for Access for Infrastructure SSH using YubiKey PIV keys. It does not claim automatic enablement, support for every protocol or MFA method, or changes to unrelated Access authentication state.
Lifecycle history
Dated event sequence
- Infrastructure independent MFA added
Cloudflare added YubiKey PIV-backed independent MFA for Access for Infrastructure SSH connections with per-application and per-policy controls.
Evidence ledger
First-party sources
- 01Cloudflare Developers — Independent MFA for infrastructure applications
Official Cloudflare Access changelog · 2026-07-01
Open official source ↗