Lộ trình đang học Current learning path Current learning path

Cloudflare One Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.

Về trang lộ trình Track home Track home

Phần 1: Kiến trúc và tài khoản Part 1: Architecture and account Part 1: Architecture and account · Bài 1/3 Lesson 1/3 មេរៀន 1/3

Kiến trúc và quy trình onboarding Architecture & workflow Architecture & workflow

Kiến trúc & quy trình

Bản đồ trực quan của toàn bộ dự án: cái gì bạn đang xây (kiến trúc tham chiếu) và thứ tự bạn xây (quy trình onboarding). Mỗi khối được gắn với mô-đun (M1, M2, …) phụ trách, để bạn nhảy thẳng sang phần hướng dẫn.


Kiến trúc tham chiếu

Bức tranh đầy đủ của những gì bạn đang xây. Nó bảo vệ cả hai chiều: người, thiết bị và chi nhánh của bạn đi ra (xương sống chính), và AI crawler đi vào nội dung của bạn (làn phía dưới) — tất cả trên một mạng toàn cầu, với mặt phẳng quản trị chạy ngang phía trên.

Kiến trúc tham chiếu Cloudflare Zero Trust đầy đủ: mặt phẳng quản trị và quan sát phía trên; nguồn và on-ramp bên trái đi qua lớp bảo mật SASE của Cloudflare (danh tính và posture, Access/ZTNA, Gateway SWG, Shadow IT, Browser Isolation, DLP, kiểm soát AI/MCP/AI Gateway, kiểm soát egress, Magic Firewall) tới đích bên phải; và làn Agentic Internet chiều vào phía dưới cho kiểm soát AI crawler.
Kiến trúc tham chiếu đầy đủ — mặt phẳng quản trị (trên), xương sống Zero Trust chiều ra (giữa), và làn Agentic Internet chiều vào (dưới). Huy hiệu gắn từng khối với mô-đun tương ứng.

Cách đọc sơ đồ

  • Trên — Mặt phẳng quản trị & quan sát: các kiểm soát xuyên suốt — identity providers của bạn (Entra ID / Okta / Google + SCIM, M2), quản trị viên & vai trò (least-privilege + break-glass, M1b), và quan sát (Logpush → SIEM, Analytics, Radar).
  • Trái — Nguồn & on-ramp: mọi thứ kết nối tới Cloudflare — thiết bị được quản lý (WARP), BYOD, không quản lý/clientless, AI agent / MCP client, chi nhánh (Cloudflare WAN Appliance), và trung tâm dữ liệu/cloud (IPsec · GRE · CNI · Mesh).
  • Giữa — Một mạng toàn cầu của Cloudflare (SASE): mỗi request đi qua toàn bộ lớp bảo mật trong một lượt gần người dùng — danh tính & posture, ZTNA (Access), Gateway SWG, phát hiện Shadow IT, Browser Isolation, DLP, AI Controls · MCP Portals · AI Gateway, kiểm soát egress, và Magic Firewall.
  • Phải — Đích: internet & SaaS, ứng dụng nội bộ của bạn (qua Tunnel/ZTNA), và AI model & MCP server — tất cả được truy cập an toàn.
  • Dưới — Chiều vào (Agentic Internet): chiều còn lại — AI crawler & bot đánh vào nội dung công khai của bạn, được quản trị bởi AI Crawl Control · WAF · AI Security for Apps (allow / block / charge), để bạn thậm chí có thể kiếm tiền từ truy cập bằng Pay Per Crawl (M7d).

Quy trình onboarding

Thứ tự triển khai. Mỗi phase xây trên phase trước, và quy tắc vàng áp dụng xuyên suốt: pilot → validate → expand.

Quy trình onboarding Cloudflare Zero Trust qua sáu phase — Nền tảng, Thiết bị, Access, Lọc web, Dữ liệu và AI, Mạng — kết thúc bằng Go-live.
Quy trình onboarding — sáu phase từ nền tảng tài khoản đến kết nối mạng, rồi go-live.

Các phase

  1. Foundation — tài khoản, quản trị viên, danh tính (M1 · M1b · M2)
  2. Devices — đăng ký Cloudflare One Client, hồ sơ thiết bị, posture (M3 · M3b · M3c)
  3. Access — xuất bản ứng dụng nội bộ sau ZTNA, kết nối mạng (M4 · M4b)
  4. Web filtering — Gateway, kiểm soát egress/IP, Browser Isolation, Shadow IT (M5 · M5b · M5c · M5d)
  5. Data & AI — DLP, kiểm soát AI, bảo mật AI & MCP (M6 · M7 · M7b)
  6. Network — kết nối văn phòng và trung tâm dữ liệu bằng Cloudflare WAN (M8)

Sau đó go-live: truyền log tới SIEM, xác nhận với nhóm pilot, mở rộng toàn công ty, và gỡ VPN cũ.


Bảo mật AI & MCP — defense in depth

Quản trị AI là một phần hạng nhất của nền tảng này, không phải phần phụ. Khi nhân viên dùng công cụ AI và các MCP agent tự hành kết nối tới hệ thống của bạn, Cloudflare áp dụng bốn lớp cho mọi tương tác AI — khám phá những gì đang được dùng, kiểm soát ứng dụng, bảo vệ nội dung đưa vào prompt, và quản trị chính các agent — cùng một lớp WAF riêng cho các ứng dụng AI bạn xây.

Bảo mật AI và MCP defense-in-depth: user và AI agent đi qua bốn lớp — khám phá shadow AI, kiểm soát AI app, bảo vệ prompt bằng DLP, quản trị MCP agent — trước khi tới AI model và MCP server.
Bảo mật AI & MCP — bốn lớp defense-in-depth giữa user/agent và nhà cung cấp AI, cộng AI Security for Apps (WAF) cho AI mà bạn xây.

Bốn lớp

  1. Discover shadow AI — tìm mọi ứng dụng AI đang dùng và ai đang dùng (M5d)
  2. Control AI apps — cho phép công cụ đã duyệt với guardrail; chặn hoặc cách ly phần còn lại (M7 · M5c)
  3. Protect prompts — DLP quét những gì người dùng gõ vào AI để tìm PII, secret và mã nguồn (M6 · M7)
  4. Govern MCP agents — MCP portal đặt agent sau Access với Managed OAuth và ghi log theo từng công cụ (M7b)

Và với các ứng dụng AI bạn xây và công khai, AI Security for Apps (WAF) bổ sung phát hiện prompt-injection và chủ đề không an toàn. Hướng dẫn đầy đủ: Mô-đun 5d · Mô-đun 7 · Mô-đun 7b.


Bản đồ mô-đun

Mô-đun Phủ Trong sơ đồ
M1 · Account setup Tài khoản + tổ chức Zero Trust Workflow · Phase 1
M1b · Account administration Vai trò, thành viên, break-glass Workflow · Phase 1
M2 · Identity provider Đăng nhập doanh nghiệp + nhóm Architecture · Identity
M3 · Device enrollment WARP / Cloudflare One Client Architecture · on-ramp
M3b · Device profiles Thiết lập client theo nhóm Architecture · on-ramp
M3c · Posture checks Tín hiệu sức khỏe thiết bị Architecture · Identity
M4 · ZTNA (Access) Truy cập theo ứng dụng, thay VPN Architecture · Access
M4b · Connectors Tunnel, Mesh & Appliance Architecture · on-ramp
M5 · Gateway DNS / Network / HTTP + TLS Architecture · Gateway
M5b · Egress policies Egress chuyên dụng, phiên bản IP Architecture · Gateway
M5c · Browser Isolation Trình duyệt từ xa (RBI) Architecture · RBI
M5d · Shadow IT & AI adoption Khám phá & quản trị ứng dụng SaaS/AI AI security · layer 1
M6 · DLP Phát hiện & ngăn mất dữ liệu Architecture · DLP
M7 · AI controls Quản trị việc dùng AI AI security · layer 2–3
M7b · Secure AI & MCP MCP server + portal AI security · layer 4
M8 · Cloudflare WAN Kết nối chi nhánh & trung tâm dữ liệu Architecture · on-ramp

👉 Mới đến? Bắt đầu với Mô-đun 1 — Thiết lập tài khoản.

Architecture & Workflow

A visual map of the whole project: what you're building (the reference architecture) and the order you build it in (the onboarding workflow). Every box is tagged with the module (M1, M2, …) that covers it, so you can jump straight to the how-to.


Reference architecture

The complete picture of what you're building. It secures both directions: your people, devices, and sites reaching out (the main spine), and AI crawlers reaching in to your content (the bottom lane) — all on one global network, with a management plane across the top.

Cloudflare Zero Trust complete reference architecture: a management and observability plane on top; sources and on-ramps on the left connecting through Cloudflare's SASE security stack (identity & posture, Access/ZTNA, Gateway SWG, Shadow IT, Browser Isolation, DLP, AI controls/MCP/AI Gateway, egress control, Magic Firewall) to destinations on the right; and an inbound Agentic Internet lane for AI crawler control at the bottom.
Complete reference architecture — management plane (top), outbound Zero Trust spine (middle), and the inbound Agentic Internet lane (bottom). Badges map each element to its module.

How to read it

  • Top — Management & observability plane: the cross-cutting controls — your identity providers (Entra ID / Okta / Google + SCIM, M2), admins & roles (least-privilege + break-glass, M1b), and observability (Logpush → SIEM, Analytics, Radar).
  • Left — Sources & on-ramps: everything that connects to Cloudflare — managed devices (WARP), BYOD, unmanaged/clientless, AI agents / MCP clients, branch offices (Cloudflare WAN Appliance), and data centers/cloud (IPsec · GRE · CNI · Mesh).
  • Center — Cloudflare's one global network (SASE): each request passes through the full security stack in a single pass close to the user — identity & posture, ZTNA (Access), Gateway SWG, Shadow IT discovery, Browser Isolation, DLP, AI Controls · MCP Portals · AI Gateway, egress control, and Magic Firewall.
  • Right — Destinations: the internet & SaaS, your private apps (via Tunnel/ZTNA), and AI models & MCP servers — all reached securely.
  • Bottom — Inbound (the Agentic Internet): the other direction — AI crawlers & bots hitting your public content, governed by AI Crawl Control · WAF · AI Security for Apps (allow / block / charge), so you can even monetize access with Pay Per Crawl (M7d).

Onboarding workflow

The order to deploy in. Each phase builds on the last, and the golden rule applies throughout: pilot → validate → expand.

Cloudflare Zero Trust onboarding workflow across six phases — Foundation, Devices, Access, Web filtering, Data & AI, Network — ending in Go-live.
Onboarding workflow — six phases from account foundation to network connectivity, then go-live.

The phases

  1. Foundation — account, admins, identity (M1 · M1b · M2)
  2. Devices — enroll the Cloudflare One Client, device profiles, posture (M3 · M3b · M3c)
  3. Access — publish private apps behind ZTNA, connect networks (M4 · M4b)
  4. Web filtering — Gateway, egress/IP control, Browser Isolation, Shadow IT (M5 · M5b · M5c · M5d)
  5. Data & AI — DLP, AI controls, secure AI & MCP (M6 · M7 · M7b)
  6. Network — connect offices and data centers with Cloudflare WAN (M8)

Then go-live: stream logs to your SIEM, validate with a pilot group, expand company-wide, and retire the old VPN.


AI & MCP security — defense in depth

Governing AI is a first-class part of this platform, not an afterthought. As employees adopt AI tools and autonomous MCP agents connect to your systems, Cloudflare applies four layers to every AI interaction — discover what's used, control the apps, protect what goes into prompts, and govern the agents themselves — with a separate WAF layer for the AI apps you build.

Cloudflare AI and MCP security defense-in-depth: users and AI agents pass through four layers — discover shadow AI, control AI apps, protect prompts with DLP, govern MCP agents — before reaching AI models and MCP servers.
AI & MCP security — four defense-in-depth layers between users/agents and AI providers, plus AI Security for Apps (WAF) for the AI you build.

The four layers

  1. Discover shadow AI — find every AI app in use and who's using it (M5d)
  2. Control AI apps — allow approved tools with guardrails; block or isolate the rest (M7 · M5c)
  3. Protect prompts — DLP scans what users type into AI for PII, secrets, and source code (M6 · M7)
  4. Govern MCP agents — MCP portals put agents behind Access with Managed OAuth and per-tool logging (M7b)

And for AI applications you build and expose, AI Security for Apps (WAF) adds prompt-injection and unsafe-topic detection. Full walkthroughs: Module 5d · Module 7 · Module 7b.


Module map

Module Covers In the diagrams
M1 · Account setup Account + Zero Trust org Workflow · Phase 1
M1b · Account administration Roles, members, break-glass Workflow · Phase 1
M2 · Identity provider Corporate login + groups Architecture · Identity
M3 · Device enrollment WARP / Cloudflare One Client Architecture · on-ramp
M3b · Device profiles Per-group client settings Architecture · on-ramp
M3c · Posture checks Device health signals Architecture · Identity
M4 · ZTNA (Access) Per-app access, replaces VPN Architecture · Access
M4b · Connectors Tunnel, Mesh & Appliance Architecture · on-ramp
M5 · Gateway DNS / Network / HTTP + TLS Architecture · Gateway
M5b · Egress policies Dedicated egress, IP version Architecture · Gateway
M5c · Browser Isolation Remote browser (RBI) Architecture · RBI
M5d · Shadow IT & AI adoption Discover & govern SaaS/AI apps AI security · layer 1
M6 · DLP Detect & stop data loss Architecture · DLP
M7 · AI controls Govern AI usage AI security · layer 2–3
M7b · Secure AI & MCP MCP servers + portals AI security · layer 4
M8 · Cloudflare WAN Connect sites & data centers Architecture · on-ramp

👉 New here? Start with Module 1 — Account Setup.

Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev

Lưu ý (best practices) Note (best practices) Note (best practices)

Ưu tiên một hoặc hai use case (thay VPN, rồi SWG) và layer phần còn lại. Rollout SASE thất bại thường vì bật mọi thứ cùng lúc. Prioritize one or two use cases (VPN replacement, then SWG) and layer the rest. Failed SASE rollouts usually turn everything on at once. Prioritize one or two use cases (VPN replacement, then SWG) and layer the rest. Failed SASE rollouts usually turn everything on at once.

Nguồn: Source: Source: Kiến trúc tham chiếu SASE SASE reference architecture SASE reference architecture ↗

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.

Kiến trúc tham chiếu Reference architecture ស្ថាបត្យកម្មយោង Cloudflare One Cloudflare One Cloudflare One

Reference Architecture using Cloudflare SASE with Microsoft Reference Architecture using Cloudflare SASE with Microsoft Reference Architecture using Cloudflare SASE with Microsoft

/reference-architecture/architectures/cloudflare-sase-with-microsoft

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Sơ đồ kiến trúc Reference architecture diagram គំនូសស្ថាបត្យកម្មយោង Cloudflare One Cloudflare One Cloudflare One

Zero Trust và hạ tầng desktop ảo (VDI) Zero Trust and Virtual Desktop Infrastructure Zero Trust and Virtual Desktop Infrastructure

Hướng dẫn dùng Zero Trust với VDI — cải thiện so với remote access web app truyền thống, bảo mật cao hơn.

This document provides a reference and guidance for using Cloudflare's Zero Trust services. It offers a vast improvement over remote access to web applications with greater security.

This document provides a reference and guidance for using Cloudflare's Zero Trust services. It offers a vast improvement over remote access to web applications with greater security.

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Tạo và bảo mật một agent wrapper AI bằng cách sử dụng AI Gateway và Zero Trust Create and secure an AI agent wrapper using AI Gateway and Zero Trust ការបង្កើតនិងការសុវត្ថិភាព agent wrapper AI ដោយប្រើ AI Gateway និង Zero Trust

Hướng dẫn này giải thích cách sử dụng Cloudflare AI Gateway và Zero Trust để tạo ra một trang web đóng gói chức năng và an toàn cho một đại lý AI.

This tutorial explains how to use Cloudflare AI Gateway and Zero Trust to create a functional and secure website wrapper for an AI agent.

វគ្គបណ្តុះបណ្តាលនេះបង្ហាញពីរបៀបដើម្បីប្រើ Cloudflare AI Gateway និង Zero Trust ដើម្បីបង្កើតវគ្គបណ្តុះបណ្តាលគេហទំព័រដែលមានប្រសិទ្ធិភាពនិងសុវត្ថិភាពសម្រាប់អេក្រង់ AI ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Tích hợp Microsoft MCAS với Cloudflare Zero Trust Integrate Microsoft MCAS with Cloudflare Zero Trust ការរួមបញ្ចូល Microsoft MCAS ជាមួយ Cloudflare Zero Trust

Với cuộc gọi MCAS API, bạn có thể quản lý một danh mục URL có chứa các URL bị chặn. Sử dụng đầu ra để tạo danh sách tên máy chủ có thể được sử dụng bởi chính sách Gateway HTTP để chặn chúng.

With an MCAS API call, you can manage a URL category that contains the blocked URLs. Use the output to create a Hostname List that can be used by Gateway HTTP policies to block them.

ជាមួយនឹងការទូរស័ព្ទ MCAS API អ្នកអាចគ្រប់គ្រងអាសយដ្ឋាន URL ដែលមានអាសយដ្ឋាន URL ដែលត្រូវបានកាត់បន្ថយ។ ប្រព័ន្ធ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម

Xem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs Cloudflare Developer docs

Sơ đồ kiến trúc tham chiếu (Cloudflare Docs) Architecture diagrams (Cloudflare Docs) Architecture diagrams (Cloudflare Docs)

Hình 1: Chỉ traffic đã qua mạng Cloudflare và policy liên quan mới được phép vào ứng dụng SaaS.

Truy cập SaaS an toàn với SASE Secure access to SaaS applications with SASE Secure access to SaaS applications with SASE

Zero Trust cho SaaS: policy theo identity, device posture và network context qua Cloudflare One. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications.

Thuật ngữ: Concepts: Concepts: SASE · Gateway · Access · Device posture · SaaS

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · SASE / Cloudflare One Secure Access Service Edge (SASE) Secure Access Service Edge (SASE)

Sản phẩm liên quan Related products Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths