API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-179 · Authentication & identity

Cloudflare IdP becomes the default login for new Zero Trust organizations

Cloudflare changed the default login method for newly created Zero Trust organizations from one-time PIN to the Cloudflare identity provider on 18 June 2026; existing organizations keep their configured login methods.

Cloudflare Zero Trustidentity providerauthenticationone-time PINdefault login

Previous state

New Zero Trust organizations started with one-time PIN as the default login method.

Current state

Newly created Zero Trust organizations receive the Cloudflare identity provider as the default login method, using existing Cloudflare account credentials and restricting authentication to account members.

Who needs to care

Administrators and users of newly created Cloudflare Zero Trust organizations that rely on the initial default identity-provider configuration.

What to do

Review the default login configuration for newly created Zero Trust organizations and explicitly add OTP or a third-party identity provider where required by the organization’s authentication design.

What the source does not prove

The change applies only to newly created Zero Trust organizations. Existing organizations keep their configured login methods, and Cloudflare does not retire OTP or third-party identity providers in this event.

Lifecycle history

Dated event sequence

  1. Cloudflare IdP becomes the default

    Cloudflare changed the default login method for newly created Zero Trust organizations from OTP to the Cloudflare identity provider.

Evidence ledger

First-party sources

  1. 01
    Cloudflare — Cloudflare identity provider is now the default for new accounts

    Official Cloudflare Zero Trust changelog · 2026-06-18

    Open official source ↗