API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-054 · Authentication & identity

Cloudflare becomes the default identity provider for new Zero Trust organisations

New Zero Trust organisations receive Cloudflare's account-backed identity provider as the default login method instead of one-time PIN.

Cloudflare Accessidentity providerZero Trustdefault

Previous state

New organisations defaulted to one-time PIN unless another identity provider was configured.

Current state

New organisations default to Cloudflare identity with account-member policy controls.

Who needs to care

Newly created Cloudflare Zero Trust organisations.

What to do

Review the default identity provider and restrict login to appropriate account members where required.

What the source does not prove

Existing organisations retain their configured methods unless administrators explicitly enable the Cloudflare identity provider.

Lifecycle history

Dated event sequence

  1. Cloudflare IdP introduced

    The account-backed identity provider became configurable.

  2. New-account default changed

    New Zero Trust organisations began receiving the Cloudflare IdP by default.

Evidence ledger

First-party sources

  1. 01
    Cloudflare Developers — Cloudflare Access changelog

    Official product changelog · 2026-06-18

    Open official source ↗