ST-2026-179 · Authentication & identity
Cloudflare IdP becomes the default login for new Zero Trust organizations
Cloudflare changed the default login method for newly created Zero Trust organizations from one-time PIN to the Cloudflare identity provider on 18 June 2026; existing organizations keep their configured login methods.
Previous state
New Zero Trust organizations started with one-time PIN as the default login method.
Current state
Newly created Zero Trust organizations receive the Cloudflare identity provider as the default login method, using existing Cloudflare account credentials and restricting authentication to account members.
Affected users
Who needs to care
Administrators and users of newly created Cloudflare Zero Trust organizations that rely on the initial default identity-provider configuration.
Required response
What to do
Review the default login configuration for newly created Zero Trust organizations and explicitly add OTP or a third-party identity provider where required by the organization’s authentication design.
Evidence boundary
What the source does not prove
The change applies only to newly created Zero Trust organizations. Existing organizations keep their configured login methods, and Cloudflare does not retire OTP or third-party identity providers in this event.
Lifecycle history
Dated event sequence
- Cloudflare IdP becomes the default
Cloudflare changed the default login method for newly created Zero Trust organizations from OTP to the Cloudflare identity provider.
Evidence ledger
First-party sources
- 01Cloudflare — Cloudflare identity provider is now the default for new accounts
Official Cloudflare Zero Trust changelog · 2026-06-18
Open official source ↗