Skip to content

Changelog

New updates and improvements at Cloudflare.

New onboarding guides for Zero Trust

Use our brand new onboarding experience for Cloudflare Zero Trust. New and returning users can now engage with a Get Started tab with walkthroughs for setting up common use cases end-to-end.

Zero Trust onboarding guides

There are eight brand new onboarding guides in total:

  • Securely access a private network (sets up device client and Tunnel)
  • Device-to-device / mesh networking (sets up and connects multiple device clients)
  • Network to network connectivity (sets up and connects multiple WARP Connectors, makes reference to Magic WAN availability for Enterprise)
  • Secure web traffic (sets up device client, Gateway, pre-reqs, and initial policies)
  • Secure DNS for networks (sets up a new DNS location and Gateway policies)
  • Clientless web access (sets up Access to a web app, Tunnel, and public hostname)
  • Clientless SSH access (all the same + the web SSH experience)
  • Clientless RDP access (all the same + RDP-in-browser)

Each flow walks the user through the steps to configure the essential elements, and provides a “more details” panel with additional contextual information about what the user will accomplish at the end, along with why the steps they take are important.

Try them out now in the Zero Trust dashboard!

Cloudy summaries for Access and Gateway Logs

Cloudy, Cloudflare's AI Agent, will now automatically summarize your Access and Gateway block logs.

In the log itself, Cloudy will summarize what occurred and why. This will be helpful for quick troubleshooting and issue correlation.

Cloudy AI summarizes a log

If you have feedback about the Cloudy summary - good or bad - you can provide that right from the summary itself.

New App Library for Zero Trust Dashboard

Cloudflare Zero Trust customers can use the App Library to get full visibility over the SaaS applications that they use in their Gateway policies, CASB integrations, and Access for SaaS applications.

App Library, found under My Team, makes information available about all Applications that can be used across the Zero Trust product suite.

Zero Trust App Library

You can use the App Library to see:

  • How Applications are defined
  • Where they are referenced in policies
  • Whether they have Access for SaaS configured
  • Review their CASB findings and integration status.

Within individual Applications, you can also track their usage across your organization, and better understand user behavior.

Data Security Analytics in the Zero Trust dashboard

Zero Trust now includes Data security analytics, providing you with unprecedented visibility into your organization sensitive data.

The new dashboard includes:

  • Sensitive Data Movement Over Time:

    • See patterns and trends in how sensitive data moves across your environment. This helps understand where data is flowing and identify common paths.
  • Sensitive Data at Rest in SaaS & Cloud:

    • View an inventory of sensitive data stored within your corporate SaaS applications (for example, Google Drive, Microsoft 365) and cloud accounts (such as AWS S3).
  • DLP Policy Activity:

    • Identify which of your Data Loss Prevention (DLP) policies are being triggered most often.
    • See which specific users are responsible for triggering DLP policies.
Data Security Analytics

To access the new dashboard, log in to Cloudflare One and go to Insights on the sidebar.

Cloudflare One Analytics Dashboards and Exportable Access Report

Cloudflare One now offers powerful new analytics dashboards to help customers easily discover available insights into their application access and network activity. These dashboards provide a centralized, intuitive view for understanding user behavior, application usage, and security posture.

![Cloudflare One Analytics Dashboards](~/assets/images/changelog/cloudflare-one/Analytics Dashboards.png)

Additionally, a new exportable access report is available, allowing customers to quickly view high-level metrics and trends in their application access. A preview of the report is shown below, with more to be found in the report:

Cloudflare One Analytics Dashboards

Both features are accessible in the Cloudflare Zero Trust dashboard, empowering organizations with better visibility and control.

New Gateway Analytics in the Cloudflare One Dashboard

Users can now access significant enhancements to Cloudflare Gateway analytics, providing you with unprecedented visibility into your organization's DNS queries, HTTP requests, and Network sessions. These powerful new dashboards enable you to go beyond raw logs and gain actionable insights into how your users are interacting with the Internet and your protected resources.

You can now visualize and explore:

  • Patterns Over Time: Understand trends in traffic volume and blocked requests, helping you identify anomalies and plan for future capacity.
  • Top Users & Destinations: Quickly pinpoint the most active users, enabling better policy enforcement and resource allocation.
  • Actions Taken: See a clear breakdown of security actions applied by Gateway policies, such as blocks and allows, offering a comprehensive view of your security posture.
  • Geographic Regions: Gain insight into the global distribution of your traffic.
Gateway Analytics

To access the new overview, log in to your Cloudflare Zero Trust dashboard and go to Analytics in the side navigation bar.

New Applications Added to Zero Trust

42 new applications have been added for Zero Trust support within the Application Library and Gateway policy enforcement, giving you the ability to investigate or apply inline policies to these applications.

33 of the 42 applications are Artificial Intelligence applications. The others are Human Resources (2 applications), Development (2 applications), Productivity (2 applications), Sales & Marketing, Public Cloud, and Security.

To view all available applications, log in to your Cloudflare Zero Trust dashboard, navigate to the App Library under My Team.

For more information on creating Gateway policies, see our Gateway policy documentation.

New Access Analytics in the Cloudflare One Dashboard

A new Access Analytics dashboard is now available to all Cloudflare One customers. Customers can apply and combine multiple filters to dive into specific slices of their Access metrics. These filters include:

  • Logins granted and denied
  • Access events by type (SSO, Login, Logout)
  • Application name (Salesforce, Jira, Slack, etc.)
  • Identity provider (Okta, Google, Microsoft, onetimepin, etc.)
  • Users (chris@cloudflare.com, sally@cloudflare.com, rachel@cloudflare.com, etc.)
  • Countries (US, CA, UK, FR, BR, CN, etc.)
  • Source IP address
  • App type (self-hosted, Infrastructure, RDP, etc.)
Access Analytics

To access the new overview, log in to your Cloudflare Zero Trust dashboard and find Analytics in the side navigation bar.

Dark Mode for Zero Trust Dashboard

The Cloudflare Zero Trust dashboard now supports Cloudflare's native dark mode for all accounts and plan types.

Zero Trust Dashboard will automatically accept your user-level preferences for system settings, so if your Dashboard appearance is set to 'system' or 'dark', the Zero Trust dashboard will enter dark mode whenever the rest of your Cloudflare account does.

Zero Trust dashboard supports dark mode

To update your view preference in the Zero Trust dashboard:

  1. Log into the Zero Trust dashboard.
  2. Select your user icon.
  3. Select Dark Mode.

To update your view preference in the Core dashboard:

  1. Log into the Cloudflare dashboard.
  2. Go to My Profile
  3. For Appearance, choose Dark.

Configure your Magic WAN Connector to connect via static IP assignment

You can now locally configure your Magic WAN Connector to work in a static IP configuration.

This local method does not require having access to a DHCP Internet connection. However, it does require being comfortable with using tools to access the serial port on Magic WAN Connector as well as using a serial terminal client to access the Connector's environment.

For more details, refer to WAN with a static IP address.