ST-2026-054 · Authentication & identity
Cloudflare becomes the default identity provider for new Zero Trust organisations
New Zero Trust organisations receive Cloudflare's account-backed identity provider as the default login method instead of one-time PIN.
Previous state
New organisations defaulted to one-time PIN unless another identity provider was configured.
Current state
New organisations default to Cloudflare identity with account-member policy controls.
Affected users
Who needs to care
Newly created Cloudflare Zero Trust organisations.
Required response
What to do
Review the default identity provider and restrict login to appropriate account members where required.
Evidence boundary
What the source does not prove
Existing organisations retain their configured methods unless administrators explicitly enable the Cloudflare identity provider.
Lifecycle history
Dated event sequence
- Cloudflare IdP introduced
The account-backed identity provider became configurable.
- New-account default changed
New Zero Trust organisations began receiving the Cloudflare IdP by default.
Evidence ledger
First-party sources
- 01Cloudflare Developers — Cloudflare Access changelog
Official product changelog · 2026-06-18
Open official source ↗