Lộ trình đang học Current learning path Current learning path

Cloudflare One Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.

Về trang lộ trình Track home Track home

Phần 1: Kiến trúc và tài khoản Part 1: Architecture and account Part 1: Architecture and account · Bài 2/3 Lesson 2/3 មេរៀន 2/3

Tạo account, team name và Cloudflare One Create the account, team name, and Cloudflare One Create the account, team name, and Cloudflare One

Mô-đun 1 — Thiết lập tài khoản

Mục tiêu: Tạo tài khoản Cloudflare, chạy thiết lập Cloudflare One, chọn tên nhóm cố định, xác nhận đăng nhập được và thêm một quản trị viên dự phòng.

👤 Ai làm việc này Quản trị viên IT / Identity
⏱️ Thời gian ~30 phút
🎯 Kết thúc bạn sẽ có Một tổ chức Cloudflare One (Zero Trust) hoạt động tại https://<team-name>.cloudflareaccess.com mà bạn đã đăng nhập được
✋ Trước khi bắt đầu Một email công việc, thông tin thanh toán và tên nhóm đã chọn (từ danh sách điều kiện tiên quyết)

💡 Nếu bạn đã có tài khoản Cloudflare, hãy chuyển đến Phần B.


Trước tiên, ba từ bạn sẽ thấy ở khắp nơi

Trước khi nhấp bất cứ gì, đây là các thuật ngữ — chúng loại bỏ 90% sự bối rối về sau.

Thuật ngữ Ý nghĩa đơn giản Ví dụ
Account (Tài khoản) Vùng chứa thanh toán + quản trị của bạn trong Cloudflare. Chứa tên miền, thiết lập và thành viên. Tài khoản "Acme Corp"
Team / organization (Nhóm/tổ chức) Phiên bản Cloudflare One (Zero Trust) bên trong tài khoản đó. Tổ chức Zero Trust của Acme
Team name (Tên nhóm) Nhãn ngắn, duy nhất bạn chọn cho nhóm. Nó trở thành URL đăng nhập của bạn. acme
Team domain (Tên miền nhóm) URL tạo từ tên nhóm, nơi người dùng đăng nhập và truy cập ứng dụng được bảo vệ. acme.cloudflareaccess.com

📺 Hai bảng điều khiển bạn sẽ dùng:

  • Bảng điều khiển tài khoản — https://dash.cloudflare.com — thanh toán, thành viên, tên miền (những thứ phạm vi toàn tài khoản).
  • Bảng điều khiển Cloudflare One — https://dash.cloudflare.com/one/ (cũng vào được qua Zero Trust ở thanh bên) — mọi thứ Zero Trust: danh tính, thiết bị, Access, Gateway, DLP, v.v.

Hướng dẫn này cho biết bạn đang ở bảng nào tại mỗi bước.


Phần A — Tạo tài khoản Cloudflare của bạn

Bước 1 — Đăng ký

  1. 👉 Mở trình duyệt và truy cập https://dash.cloudflare.com/sign-up
  2. ⌨️ Nhập email công việc và một mật khẩu mạnh.
  3. 👉 Nhấp Sign Up.

📺 Bạn sẽ thấy: Xác nhận tài khoản đã được tạo, và một email xác minh trong hộp thư.

Bước 2 — Xác minh email

  1. 👉 Mở email từ Cloudflare ("Verify your email address").
  2. 👉 Nhấp liên kết xác minh.

⚠️ Lưu ý: Một số thao tác về sau (như mời thành viên) yêu cầu email đã được xác minh. Đừng bỏ qua bước này.

✅ Điểm kiểm tra: Bạn đã đăng nhập ở trang chủ bảng điều khiển Cloudflare. Nếu nó nhắc "thêm một website", bạn có thể bỏ qua — Zero Trust không cần tên miền để bắt đầu.

Bước 3 — Bật xác thực hai yếu tố (làm ngay bây giờ)

  1. 👉 Góc trên bên phải → nhấp biểu tượng hồ sơ → My Profile.
  2. 👉 Mở tab Authentication.
  3. 👉 Dưới Two-Factor Authentication, nhấp Add và làm theo hướng dẫn để thiết lập ứng dụng authenticator.

⚠️ Lưu ý: Vì Cloudflare hiện là phương thức đăng nhập mặc định cho các tổ chức Zero Trust mới (Phần C), bảo mật tài khoản Cloudflare của bạn chính là bảo mật Zero Trust. Bảo vệ tài khoản này bằng 2FA là bắt buộc — hãy làm trước khi tiếp tục.


Phần B — Chạy thiết lập Cloudflare One

Bước 4 — Mở Cloudflare One

  1. 👉 Trong menu trái của bảng điều khiển, nhấp Zero Trust (mở bảng điều khiển Cloudflare One). (Hoặc truy cập trực tiếp https://dash.cloudflare.com/one/.)

📺 Bạn sẽ thấy: Màn hình thiết lập Cloudflare One, yêu cầu bạn chọn tên nhóm và chọn gói.

Bước 5 — Chọn tên nhóm ⚠️ cái này cố định

  1. ⌨️ Nhập tên nhóm đã chọn (vd. acme). Chỉ dùng chữ thường, số và dấu gạch nối.
  2. 👉 Nhấp Next.

📺 Điều này nghĩa là: URL đăng nhập của tổ chức bạn nay là https://acme.cloudflareaccess.com (thay acme bằng của bạn). Người dùng vào URL này để đăng nhập và truy cập các ứng dụng bạn bảo vệ. Bạn cũng sẽ nhập tên nhóm khi đăng ký thiết bị ở Mô-đun 3.

⚠️ Lưu ý: Đổi tên nhóm về sau sẽ làm hỏng mọi URL đăng nhập đã lưu, cấu hình ứng dụng và đăng ký thiết bị. Chọn một tên bạn sẽ giữ lâu dài — thường là tên viết tắt công ty. Bạn có thể xem (và đổi cẩn thận) sau tại Cloudflare One → Settings.

✅ Điểm kiểm tra: Ghi tên miền nhóm của bạn ở đây để dùng cho mọi mô-đun sau: https://________________.cloudflareaccess.com

Bước 6 — Chọn gói

  1. 👉 Chọn gói của bạn:
    • Free — tuyệt cho việc đánh giá và Mô-đun 1–5 (tối đa 50 chỗ/người dùng).
    • Pay-as-you-go — tính phí theo từng chỗ vượt mức miễn phí.
    • Enterprise — cần cho DLP (Mô-đun 6), kiểm soát AI nâng cao (Mô-đun 7), device posture nâng cao và Cloudflare WAN (Mô-đun 8). Enterprise được sắp xếp qua đội ngũ quản lý tài khoản Cloudflare.
  2. 👉 Nhấp Next / Proceed to payment.
  3. ⌨️ Nhập thông tin thanh toán và xác nhận.

💡 Mẹo: Cần phương thức thanh toán kể cả với Free — bạn sẽ không bị tính phí ở gói Free. Một "chỗ" (seat) bị dùng bởi mỗi người dùng xác thực hoặc đăng ký thiết bị; bạn xem mức dùng chỗ sau tại Cloudflare One → Settings → Account.

✅ Điểm kiểm tra: Bạn đến trang Cloudflare One Overview (URL chứa /one/). Đây là bảng điều khiển bạn dùng cho mọi mô-đun còn lại. 🎉


Phần C — Đăng nhập của bạn đã hoạt động (Cloudflare làm nhà cung cấp danh tính mặc định)

Đây là điểm tiết kiệm thời gian lớn cho tài khoản mới: khi bạn tạo một tổ chức Zero Trust mới, Cloudflare tự động tự thiết lập làm nhà cung cấp danh tính mặc định. Nghĩa là nhóm của bạn có thể đăng nhập bằng thông tin tài khoản Cloudflare hiện có — không cần PIN một lần, không cần thiết lập bên thứ ba, không cần cấu hình gì để bắt đầu. (Điều này thay thế One-time PIN làm mặc định vào năm 2026.)

Bạn sẽ kết nối nhà cung cấp danh tính doanh nghiệp (Entra ID / Okta / Google) ở Mô-đun 2 để dùng thực tế — nhưng ngay bây giờ bạn đã có thể kiểm tra rằng việc xác thực hoạt động.

Bước 7 — Xem phương thức đăng nhập mặc định của bạn

  1. 👉 Trong Cloudflare One, vào Settings → Authentication (hoặc Integrations → Identity providers).
  2. 📺 Bạn sẽ thấy: Cloudflare đã có sẵn trong Login methods / Your identity providers — được thêm tự động cho bạn.

Bước 8 — (Khuyến nghị) Giới hạn đăng nhập chỉ cho thành viên tài khoản của bạn

Theo mặc định, bất kỳ người dùng Cloudflare nào cũng có thể xác thực qua phương thức đăng nhập Cloudflare. Hãy siết chặt:

  1. 👉 Nhấp vào nhà cung cấp danh tính Cloudflare.
  2. 👉 Bật Restrict to account members — giờ chỉ người dùng là thành viên tài khoản Cloudflare của bạn mới xác thực được theo cách này.
  3. 👉 Nhấp Save.

💡 Mẹo: Bạn sẽ thêm nhân viên thực làm thành viên tài khoản ở Phần E và Mô-đun 2. Với nhà thầu/bên ngoài, bạn cũng có thể bật One-time PIN (mã qua email) làm phương thức bổ sung — đăng nhập Cloudflare và OTP chạy song song để người dùng chọn.

Bước 9 — Kiểm tra trải nghiệm đăng nhập

  1. 👉 Mở cửa sổ trình duyệt riêng tư/ẩn danh và truy cập tên miền nhóm của bạn: https://acme.cloudflareaccess.com (dùng tên nhóm của bạn).
  2. 📺 Bạn sẽ thấy: Trang đăng nhập của tổ chức bạn, đề nghị Cloudflare làm phương thức đăng nhập.
  3. 👉 Đăng nhập bằng tài khoản Cloudflare của bạn.

✅ Điểm kiểm tra: Bạn xác thực được tại tên miền nhóm. Tổ chức Zero Trust của bạn hoạt động trước cả khi bạn kết nối một IdP doanh nghiệp. 🎉


Phần D — Xác nhận tên nhóm và tham quan các thiết lập quan trọng

Bước 10 — Xác nhận tên nhóm và tên miền

  1. 👉 Trong Cloudflare One, vào Settings → Custom Pages (hoặc Settings → Account / General, tùy phiên bản bảng điều khiển).
  2. 📺 Bạn sẽ thấy: Tên miền nhóm của bạn hiển thị là <team-name>.cloudflareaccess.com.

✅ Điểm kiểm tra: Khớp với những gì bạn ghi ở Bước 5.

Bước 11 — Tham quan nhanh: các thiết lập bạn sẽ quay lại

Bây giờ chưa cần đổi — chỉ cần biết chúng ở đâu:

Thiết lập Ở đâu Bạn dùng ở
Tên nhóm / tên miền Settings → Custom Pages / Account Mô-đun này
Authentication (phương thức đăng nhập) Settings → Authentication · Integrations → Identity providers Mô-đun 2
WARP Client / thiết lập thiết bị Settings → WARP Client Mô-đun 3
Custom Pages (trang đăng nhập/chặn có thương hiệu) Settings → Custom Pages Trước khi vận hành
Network / TLS decryption Settings → Network Mô-đun 6
Logs / Logpush Logs → Logpush Bước 13

💡 Mẹo: Gắn thương hiệu cho trang đăng nhập và trang chặn (Settings → Custom Pages) trước khi triển khai cho người dùng — tạo niềm tin và giảm ticket "cái này có thật không?".


Phần E — Thêm quản trị viên và tài khoản dự phòng (break-glass)

Bây giờ bạn là quản trị viên duy nhất. Thêm một bản dự phòng để một cấu hình sai trong tương lai không bao giờ khóa cả tổ chức của bạn ra ngoài.

Bước 12 — Thêm Super Administrator thứ hai

  1. 👉 Chuyển sang bảng điều khiển tài khoản: https://dash.cloudflare.com
  2. 👉 Trên bên phải → biểu tượng hồ sơ → Manage Account → Members.
  3. 👉 Nhấp Invite.
  4. ⌨️ Nhập email của một đồng nghiệp đáng tin (hoặc hộp thư break-glass dùng chung, bảo mật của IT).
  5. 👉 Chọn vai trò Super Administrator - All Privileges.
  6. 👉 Nhấp Continue to summary → Invite.

📺 Bạn sẽ thấy: Người đó xuất hiện trong danh sách Members là Pending cho đến khi họ chấp nhận lời mời qua email.

✅ Điểm kiểm tra: Danh sách Members hiển thị ít nhất hai Super Administrator (bạn + bản dự phòng).

⚠️ Lưu ý: Lưu thông tin tài khoản break-glass ở nơi an toàn và riêng biệt (trình quản lý mật khẩu / vault). Nếu bạn tự khóa mình bằng một chính sách, đây là cách quay lại.

👥 Cần nhiều hơn vài quản trị viên, hoặc muốn chia nhiệm vụ (thanh toán vs. bảo mật vs. chỉ đọc)? Vai trò, mời vs. Direct Add, nhóm người dùng, token API cấp tài khoản và Organizations đều có trong trang đi kèm: 1b — Quản trị tài khoản & vai trò.


Phần F — Bật ghi log (để thấy điều gì đang xảy ra)

  1. 👉 Trong Cloudflare One, vào Logs → Logpush (hoặc Settings → Logs).
  2. 💡 Nếu bạn có SIEM hoặc kho log (Splunk, S3, Cloudflare R2, v.v.), nhấp Add a Logpush job và làm theo hướng dẫn để truyền log Access và Gateway đến đó. Nếu chưa có, bạn vẫn xem log trong bảng điều khiển — ghi chú để thiết lập trước khi vận hành.

✅ Điểm kiểm tra: Hoặc đã có một Logpush job, hoặc bạn đã ghi chú thiết lập trước khi vận hành.


✅ Hoàn thành Mô-đun 1!

Bây giờ bạn có:

  • ✅ Một tài khoản Cloudflare an toàn với 2FA
  • ✅ Một tổ chức Cloudflare One (Zero Trust) hoạt động
  • ✅ Tên miền nhóm cố định của bạn: https://<team-name>.cloudflareaccess.com
  • ✅ Đăng nhập hoạt động (Cloudflare làm IdP mặc định), có thể giới hạn cho thành viên tài khoản
  • ✅ Một Super Administrator dự phòng (break-glass)

Khắc phục nhanh

Vấn đề Cách khắc phục
Không nhận được email xác minh Kiểm tra thư rác; ở trang đăng nhập nhấp Resend verification
Cứ nhắc "thêm website" Bỏ qua — Zero Trust không cần tên miền. Nhấp Zero Trust ở thanh bên để tiếp tục
Không mời được thành viên Bạn phải là Super Administrator có email đã xác minh — xác minh email (Bước 2)
Tính năng gói bị mờ Một số tính năng cần Enterprise (DLP, Cloudflare WAN); điều này bình thường ở Free — cứ tiếp tục và nâng cấp sau
Bất kỳ ai có tài khoản Cloudflare đều đăng nhập được Bật Restrict to account members ở nhà cung cấp danh tính Cloudflare (Bước 8)
Không tìm thấy Settings trong Cloudflare One Cuộn xuống cuối menu trái; trên màn hình hẹp dùng biểu tượng menu ☰

👉 Tiếp theo: Mô-đun 1b — Quản trị tài khoản & vai trò (chuyên sâu tùy chọn)

Hoặc chuyển thẳng đến Mô-đun 2 — Nhà cung cấp danh tính để kết nối đăng nhập doanh nghiệp của bạn.

Module 1 — Account Setup

Goal: Create your Cloudflare account, run the Cloudflare One setup, choose your permanent team name, confirm your login works, and add a backup administrator.

👤 Who does this IT / Identity administrator
⏱️ Time ~30 minutes
🎯 You'll finish with A live Cloudflare One (Zero Trust) organization at https://<team-name>.cloudflareaccess.com that you can already log in to
✋ Before you begin A work email, billing details, and your chosen team name (from the prerequisites checklist)

💡 If you already have a Cloudflare account, skip to Part B.


First, three words you'll see everywhere

Before you click anything, here's the vocabulary — it removes 90% of the confusion later.

Term Plain meaning Example
Account Your billing + admin container in Cloudflare. Holds domains, settings, and members. "Acme Corp" account
Team / organization Your Cloudflare One (Zero Trust) instance inside that account. Acme's Zero Trust org
Team name The short, unique label you pick for your team. It becomes your login URL. acme
Team domain The URL built from your team name, where users sign in and reach secured apps. acme.cloudflareaccess.com

📺 The two dashboards you'll use:

  • Account dashboard — https://dash.cloudflare.com — billing, members, domains (account-wide things).
  • Cloudflare One dashboard — https://dash.cloudflare.com/one/ (also reachable via Zero Trust in the sidebar) — everything Zero Trust: identity, devices, Access, Gateway, DLP, etc.

This guide tells you which one you're in at each step.


Part A — Create your Cloudflare account

Step 1 — Sign up

  1. 👉 Open a browser and go to https://dash.cloudflare.com/sign-up
  2. ⌨️ Enter your work email and a strong password.
  3. 👉 Click Sign Up.

📺 What you'll see: A confirmation that your account was created, and a verification email in your inbox.

Step 2 — Verify your email

  1. 👉 Open the email from Cloudflare ("Verify your email address").
  2. 👉 Click the verification link.

⚠️ Watch out: Some later actions (like inviting members) require a verified email. Don't skip this.

✅ Checkpoint: You're signed in on the Cloudflare dashboard home page. If it prompts you to "add a website," you can ignore that — Zero Trust doesn't require a domain to start.

Step 3 — Turn on two-factor authentication (do this now)

  1. 👉 Top-right corner → click your profile icon → My Profile.
  2. 👉 Open the Authentication tab.
  3. 👉 Under Two-Factor Authentication, click Add and follow the prompts to set up an authenticator app.

⚠️ Watch out: Because Cloudflare is now the default login method for new Zero Trust orgs (Part C), your Cloudflare account security is your Zero Trust security. Protecting this account with 2FA is not optional — do it before going further.


Part B — Run the Cloudflare One setup

Step 4 — Open Cloudflare One

  1. 👉 In the dashboard's left menu, click Zero Trust (this opens the Cloudflare One dashboard). (Or go directly to https://dash.cloudflare.com/one/.)

📺 What you'll see: The Cloudflare One onboarding/setup screen, asking you to choose a team name and select a plan.

Step 5 — Choose your team name ⚠️ this is permanent

  1. ⌨️ Enter your chosen team name (e.g. acme). Use lowercase letters, numbers, and hyphens only.
  2. 👉 Click Next.

📺 What this means: Your organization's sign-in URL is now https://acme.cloudflareaccess.com (replace acme with yours). Users hit this URL to sign in and to reach the apps you secure. You'll also enter the team name when enrolling devices in Module 3.

⚠️ Watch out: Changing the team name later breaks every saved login URL, app configuration, and device enrollment. Choose a name you'll keep — usually your company's short name. You can view (and, with care, change) it later under Cloudflare One → Settings.

✅ Checkpoint: Write your team domain here so you have it for every later module: https://________________.cloudflareaccess.com

Step 6 — Choose a plan

  1. 👉 Select your plan:
    • Free — great for evaluating and for Modules 1–5 (up to 50 seats/users).
    • Pay-as-you-go — per-seat billing beyond the free tier.
    • Enterprise — required for DLP (Module 6), advanced AI controls (Module 7), advanced device posture, and Cloudflare WAN (Module 8). Enterprise is arranged with your Cloudflare account team.
  2. 👉 Click Next / Proceed to payment.
  3. ⌨️ Enter your billing/payment details and confirm.

💡 Tip: A payment method is required even on Free — you will not be charged on the Free plan. A "seat" is consumed by each user who authenticates or enrolls a device; you can see seat usage later under Cloudflare One → Settings → Account.

✅ Checkpoint: You land on the Cloudflare One Overview page (URL contains /one/). This is the dashboard you'll use for every remaining module. 🎉


Part C — Your login already works (Cloudflare as your default identity provider)

Here's the big time-saver for new accounts: when you create a new Zero Trust organization, Cloudflare automatically sets itself up as your default identity provider. That means your team can sign in with their existing Cloudflare account credentials — no one-time PINs, no third-party setup, nothing to configure to get started. (This replaced One-time PIN as the default in 2026.)

You'll connect your corporate identity provider (Entra ID / Okta / Google) in Module 2 for real production use — but you can already test that authentication works right now.

Step 7 — See your default login method

  1. 👉 In Cloudflare One, go to Settings → Authentication (or Integrations → Identity providers).
  2. 📺 What you'll see: Cloudflare already listed under Login methods / Your identity providers — added for you automatically.

By default, any Cloudflare user could authenticate against the Cloudflare login method. Tighten this:

  1. 👉 Click the Cloudflare identity provider.
  2. 👉 Enable Restrict to account members — now only users who are members of your Cloudflare account can authenticate this way.
  3. 👉 Click Save.

💡 Tip: You'll add real employees as account members in Part E and Module 2. For contractors/externals, you can also enable One-time PIN (email code) as an additional method — Cloudflare login and OTP can run side by side so users choose.

Step 9 — Test the sign-in experience

  1. 👉 Open a private/incognito browser window and go to your team domain: https://acme.cloudflareaccess.com (use your team name).
  2. 📺 What you'll see: Your organization's sign-in page, offering Cloudflare as a login method.
  3. 👉 Sign in with your Cloudflare account.

✅ Checkpoint: You can authenticate at your team domain. Your Zero Trust org is live and usable before you've even connected a corporate IdP. 🎉


Part D — Confirm your team name and tour key settings

Step 10 — Confirm team name and domain

  1. 👉 In Cloudflare One, go to Settings → Custom Pages (or Settings → Account / General, depending on your dashboard version).
  2. 📺 What you'll see: Your Team domain shown as <team-name>.cloudflareaccess.com.

✅ Checkpoint: It matches what you wrote down in Step 5.

Step 11 — Quick tour: the settings you'll return to

You don't need to change these now — just know where they live:

Setting Where You'll use it in
Team name / domain Settings → Custom Pages / Account This module
Authentication (login methods) Settings → Authentication · Integrations → Identity providers Module 2
WARP Client / device settings Settings → WARP Client Module 3
Custom Pages (branded login/block pages) Settings → Custom Pages Before go-live
Network / TLS decryption Settings → Network Module 6
Logs / Logpush Logs → Logpush Step 13

💡 Tip: Brand your login and block pages (Settings → Custom Pages) before rolling out to users — it builds trust and cuts "is this real?" helpdesk tickets.


Part E — Add administrators and a break-glass account

Right now you're the only administrator. Add a backup so a future misconfiguration can never lock your whole org out.

Step 12 — Add a second Super Administrator

  1. 👉 Switch to the account dashboard: https://dash.cloudflare.com
  2. 👉 Top-right → profile icon → Manage Account → Members.
  3. 👉 Click Invite.
  4. ⌨️ Enter a trusted colleague's email (or a shared, secured IT break-glass mailbox).
  5. 👉 Choose the role Super Administrator - All Privileges.
  6. 👉 Click Continue to summary → Invite.

📺 What you'll see: The person appears in the Members list as Pending until they accept the emailed invitation.

✅ Checkpoint: The Members list shows at least two Super Administrators (you + the backup).

⚠️ Watch out: Store the break-glass account's credentials somewhere safe and separate (a password manager / vault). If you ever lock yourself out with a policy, this is how you get back in.

👥 Need more than a couple of admins, or want to split duties (billing vs. security vs. read-only)? Roles, invitations vs. Direct Add, user groups, account-owned API tokens, and Organizations are all covered in the companion page: 1b — Account administration & roles.


Part F — Turn on logging (so you can see what's happening)

  1. 👉 In Cloudflare One, go to Logs → Logpush (or Settings → Logs).
  2. 💡 If you have a SIEM or log store (Splunk, S3, Cloudflare R2, etc.), click Add a Logpush job and follow the prompts to stream Access and Gateway logs to it. If you don't have one yet, you can still view logs in the dashboard — note this to set up before go-live.

✅ Checkpoint: Either a Logpush job exists, or you've noted to set it up before go-live.


✅ Module 1 complete!

You now have:

  • ✅ A secure Cloudflare account with 2FA
  • ✅ A live Cloudflare One (Zero Trust) organization
  • ✅ Your permanent team domain: https://<team-name>.cloudflareaccess.com
  • ✅ A working login (Cloudflare as default IdP), optionally restricted to account members
  • ✅ A backup Super Administrator (break-glass)

Quick troubleshooting

Problem Fix
Didn't get the verification email Check spam; on the sign-in page click Resend verification
"Add a website" keeps prompting Ignore it — Zero Trust doesn't require a domain. Click Zero Trust in the sidebar to continue
Can't invite members You must be a Super Administrator with a verified email — verify your email (Step 2)
Greyed-out plan features Some features need Enterprise (DLP, Cloudflare WAN); that's expected on Free — continue and upgrade later
Anyone with a Cloudflare account can sign in Enable Restrict to account members on the Cloudflare identity provider (Step 8)
Can't find Settings in Cloudflare One Scroll to the bottom of the left menu; on narrow screens use the ☰ menu icon

👉 Next: Module 1b — Account Administration & Roles (optional deep-dive)

Or skip straight to Module 2 — Identity Provider to connect your corporate login.

Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.

Tutorial Tutorial Tutorial Application Services Application Services Application Services

Thay đổi tên máy chủ của bạn (Cài đặt đầy đủ) Change your nameservers (Full setup) ប្តូរឈ្មោះម៉ាស៊ីនមេរបស់អ្នក (ការដំឡើងពេញលេញ)

Nếu bạn muốn sử dụng Cloudflare làm nhà cung cấp chính của bạn DNS và quản lý các bản ghi của bạn DNS, miền của bạn nên sử dụng cài đặt đầy đủ.

If you want to use Cloudflare as your primary DNS provider and manage your DNS records, your domain should be using a full setup.

ប្រសិនបើអ្នកចង់ប្រើ Cloudflare ជាអ្នកផ្តល់សេវា DNS ចម្បងរបស់អ្នក និងគ្រប់គ្រងកំណត់ត្រា DNS របស់អ្នក ដែនរបស់អ្នកគួរតែប្រើការដំឡើងពេញលេញ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Application Services Application Services Application Services

Chuyển đổi full setup sang partial setup Convert full setup to partial setup ការផ្លាស់ប្តូរការដំឡើងពេញលេញទៅការដំឡើងផ្នែកមួយ

Chuyển đổi một thiết lập DNS đầy đủ thành một thiết lập CNAME một phần.

Convert a full DNS setup to a partial CNAME setup.

ការផ្លាស់ប្តូរការដំឡើងពេញលេញ DNS ទៅការដំឡើង CNAME ផ្នែកមួយ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Application Services Application Services Application Services

Chuyển đổi full setup sang secondary setup Convert full setup to secondary setup ការផ្លាស់ប្តូរការដំឡើងពេញលេញទៅក្នុងការដំឡើងខ្ពស់

Nếu ban đầu bạn đã cấu hình một thiết lập đầy đủ, sau đó bạn có thể chuyển đổi vùng của mình để sử dụng chuyển vùng đến (Cloudflare là thứ cấp).

If you initially configured a full setup you can later convert your zone to use incoming zone transfers (Cloudflare as secondary).

ប្រសិនបើអ្នកបានកំណត់ការដំឡើងពេញលេញជាលើកដំបូងអ្នកអាចផ្លាស់ប្តូរតំបន់របស់អ្នកបន្ទាប់មកដើម្បីប្រើសម្រាប់ការផ្លាស់ប្តូរតំបន់ចូល (Cloudflare ជាផ្នែកមួយ) ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Application Services Application Services Application Services

Chuyển đổi cài đặt một phần sang cài đặt đầy đủ Convert partial setup to full setup ការផ្លាស់ប្តូរការដំឡើងផ្នែកមួយទៅនឹងការដំឡើងពេញលេញ

Nếu ban đầu bạn thiết lập một miền một phần trên Cloudflare, sau đó bạn có thể di chuyển nó sang thiết lập đầy đủ.

If you initially set up a partial domain on Cloudflare, you can later migrate it to a full setup.

ប្រសិនបើអ្នកចាប់ផ្តើមបង្កើតទីផ្សារផ្នែកមួយនៅលើ Cloudflare អ្នកអាចដំណើរការវាទៅជាការបង្កើតពេញលេញបន្ទាប់មក។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម

Xem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs Cloudflare Developer docs

Sản phẩm liên quan Related products Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths