<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008jV2vhCACOkta Classic EngineAuthenticationAnswered2024-04-17T11:52:31.000Z2023-01-31T19:16:31.000Z2023-02-04T00:54:48.000Z

cmjsf (cmjsf) asked a question.

2FA with Cloudflare

I have been trying to setup 2FA for Cloudflare logins using Okta and have run into a roadblock. So far I have created an Authentication Policy for our org and added the Cloudflare integration in Okta. Once I apply the Authentication policy to the Cloudflare app, it does not seem to work. I am fairly new to Okta so any help would be greatly appreciated.


  • Hi @cmjsf (cmjsf)​ , Thank you for reaching out to the Okta Community!

     

    Looking at the Cloudflare integration currently available in the Okta Integration Network, it does not seem this is achievable. While the app is listed, it does not seem to have a SAML SSO functionality, as such Okta MFA cannot be enforced. 

    image 

     

    To clarify: - you create a SWA app which is basically just a credential injection and while triggering SSO from the Okta side (user clicks on assigned app icon) it would ask for MFA if the authentication policy is properly configured BUT there is nothing forcing the user to sign in with Okta. If they know the Cloudflare login url and credentials, they can just bypass Okta as there is not account federation. 

     

     

    I recommend reaching out to their support to discuss SSO options. If their current iteration of the integration does not come with out of the box SAML SSO, perhaps a custom SAML app could be implemented: 

    https://help.okta.com/en-us/Content/Topics/Apps/Apps_App_Integration_Wizard_SAML.htm?cshid=ext_Apps_App_Integration_Wizard-saml

     

     

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

    --------------------------------

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
    Selected as Best
  • Hi @cmjsf (cmjsf)​ , Thank you for reaching out to the Okta Community!

     

    Looking at the Cloudflare integration currently available in the Okta Integration Network, it does not seem this is achievable. While the app is listed, it does not seem to have a SAML SSO functionality, as such Okta MFA cannot be enforced. 

    image 

     

    To clarify: - you create a SWA app which is basically just a credential injection and while triggering SSO from the Okta side (user clicks on assigned app icon) it would ask for MFA if the authentication policy is properly configured BUT there is nothing forcing the user to sign in with Okta. If they know the Cloudflare login url and credentials, they can just bypass Okta as there is not account federation. 

     

     

    I recommend reaching out to their support to discuss SSO options. If their current iteration of the integration does not come with out of the box SAML SSO, perhaps a custom SAML app could be implemented: 

    https://help.okta.com/en-us/Content/Topics/Apps/Apps_App_Integration_Wizard_SAML.htm?cshid=ext_Apps_App_Integration_Wizard-saml

     

     

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

    --------------------------------

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
    Selected as Best
This question is closed.
Loading
2FA with Cloudflare