Mô-đun 2 — Kết nối nhà cung cấp danh tính
Mục tiêu: Kết nối hệ thống đăng nhập công ty để Cloudflare biết ai mỗi người dùng là và họ thuộc nhóm nào. Đây là nền tảng mà mọi chính sách sau này dựa vào.
|
|
| 👤 Ai làm việc này |
Quản trị viên IT / Identity |
| ⏱️ Thời gian |
~45 phút |
| 🎯 Kết thúc bạn sẽ có |
Người dùng đăng nhập được bằng tài khoản công ty; nút Test hiện email + nhóm của họ |
| ✋ Trước khi bắt đầu |
Quyền quản trị nhà cung cấp danh tính của bạn, và team domain từ Mô-đun 1 |
Trước tiên: sao chép callback URL
Mọi identity provider đều cần giá trị này từ bạn. Ghi lại ngay (thay <team-name>):
https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback
Hướng dẫn này gọi nó là callback URL của bạn. (Google còn cần JavaScript origin: https://<team-name>.cloudflareaccess.com.)
💡 Bạn đang dùng nhà cung cấp nào? Nhảy tới phần của bạn:
Sau đó mọi người làm Phần E — Test và Phần F — MFA.
Phần A — Microsoft Entra ID (Azure AD)
Bạn sẽ làm việc này ở hai nơi: trước ở trung tâm quản trị Microsoft, rồi ở Cloudflare.
A1. Đăng ký ứng dụng trong Microsoft Entra
- 👉 Mở
https://entra.microsoft.com và đăng nhập bằng tài khoản Global Administrator.
- 👉 Ở menu trái: Applications → Enterprise applications.
- 👉 Nhấp + New application (đầu trang).
- 👉 Nhấp + Create your own application (đầu trang).
- 📺 Một bảng mở bên phải. ⌨️ Đặt tên
Cloudflare Access.
- 👉 Chọn tùy chọn "Register an application to integrate with Microsoft Entra ID (App you're developing)".
⚠️ Lưu ý: Đừng chọn ứng dụng gallery/SaaS — bạn đang đăng ký ứng dụng của mình.
- 👉 Nhấp Create.
📺 Bạn sẽ thấy: Trang "Register an application" với phần Redirect URI.
- 👉 Dưới Redirect URI, đặt dropdown nền tảng thành Web.
- ⌨️ Dán callback URL của bạn:
https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- 👉 Nhấp Register.
✅ Điểm kiểm tra: Bạn đang ở trang Overview của ứng dụng.
A2. Sao chép ba giá trị
Trên trang Overview của ứng dụng:
- 📋 Sao chép Application (client) ID → lưu lại.
- 📋 Sao chép Directory (tenant) ID → lưu lại.
Bây giờ tạo secret:
3. 👉 Menu trái của ứng dụng → Certificates & secrets → tab Client secrets → + New client secret.
4. ⌨️ Description: Cloudflare. Đặt hạn dùng (ví dụ 24 tháng).
5. 👉 Nhấp Add.
6. 📋 Sao chép ngay secret Value (không phải "Secret ID") → lưu lại.
⚠️ Lưu ý: Secret Value chỉ hiện một lần. Nếu bạn rời trang, bạn phải xóa nó và tạo cái mới. Ngoài ra, khi hết hạn, mọi đăng nhập dừng — đặt nhắc lịch để gia hạn trước ngày hết hạn.
A3. Cấp quyền (để Cloudflare đọc được nhóm)
-
👉 Menu trái của ứng dụng → API permissions → + Add a permission.
-
👉 Chọn Microsoft Graph → Delegated permissions.
-
⌨️ Tìm và đánh dấu từng quyền trong bảy quyền sau:
| Quyền |
Vì sao |
email |
Email của người dùng |
offline_access |
Giữ phiên được làm mới |
openid |
Đăng nhập chuẩn |
profile |
Thông tin hồ sơ cơ bản |
User.Read |
Đọc người dùng đang đăng nhập |
Directory.Read.All |
Đọc directory của bạn |
GroupMember.Read.All |
Đọc thành viên nhóm (cần cho rule theo nhóm) |
-
👉 Nhấp Add permissions.
-
👉 Nhấp Grant admin consent for [your org] → Yes.
✅ Điểm kiểm tra: Cả bảy quyền hiện "Granted for [your org]" với dấu kiểm xanh.
A4. Thêm Entra ID vào Cloudflare
- 👉 Vào bảng điều khiển Zero Trust (
https://one.dash.cloudflare.com).
- 👉 Settings → Authentication (bạn có thể thấy là Integrations → Identity providers).
- 👉 Dưới Login methods, nhấp Add new.
- 👉 Chọn Azure AD (Microsoft Entra ID).
- ⌨️ Điền:
| Trường |
Dán |
| Application (client) ID |
từ A2 |
| Application (client) Secret |
secret Value từ A2 |
| Directory (tenant) ID |
từ A2 |
- 👉 Bật các tùy chọn sau:
- ✅ Support Groups (để Cloudflare đọc nhóm Entra)
- ✅ Proof Key for Code Exchange (PKCE)
- ✅ Enable SCIM (khuyến nghị — tự đồng bộ user/group và có thể thu hồi quyền khi ai đó bị vô hiệu hóa)
- 👉 Nhấp Save.
✅ Điểm kiểm tra: "Azure AD" giờ xuất hiện trong danh sách phương thức đăng nhập. Bây giờ nhảy tới Phần E — Test.
Phần B — Okta
B1. Tạo ứng dụng trong Okta
- 👉 Đăng nhập Okta admin console.
- 👉 Applications → Applications → Create App Integration.
- 👉 Chọn OIDC - OpenID Connect → Web Application → Next.
- ⌨️ Đặt tên
Cloudflare Access.
- ⌨️ Dưới Sign-in redirect URIs, dán callback URL của bạn:
https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- 👉 Dưới Assignments, chọn ai được dùng (ví dụ "Allow everyone in your organization"), rồi Save.
B2. Sao chép hai giá trị
Trên tab General của ứng dụng:
- 📋 Sao chép Client ID.
- 📋 Sao chép Client secret.
- 📝 Ghi lại Okta domain của bạn (URL bạn đăng nhập, ví dụ
https://my-company.okta.com).
B3. Thêm Okta vào Cloudflare
- 👉 Zero Trust → Settings → Authentication → Add new → Okta.
- ⌨️ Điền:
| Trường Cloudflare |
Giá trị |
| App ID |
Okta Client ID |
| Client secret |
Okta Client secret |
| Okta account URL |
https://my-company.okta.com |
- 👉 Bật Support Groups nếu bạn sẽ dùng rule theo nhóm.
- 👉 Nhấp Save.
⚠️ Lưu ý: Nếu tổ chức bạn có hơn 100 nhóm Okta, bạn cũng phải tạo một read-only Okta API token và dán vào, nếu không tra cứu nhóm sẽ thất bại. (Okta admin → Security → API → Tokens → Create Token.)
✅ Điểm kiểm tra: "Okta" xuất hiện trong phương thức đăng nhập. Bây giờ sang Phần E — Test.
Phần C — Google Workspace
C1. Tạo thông tin OAuth trong Google
- 👉 Mở
https://console.cloud.google.com → chọn hoặc tạo một project.
- 👉 APIs & Services → Credentials → + Create Credentials → OAuth client ID.
- 👉 Application type: Web application.
- ⌨️ Authorized JavaScript origins → thêm:
https://<team-name>.cloudflareaccess.com
- ⌨️ Authorized redirect URIs → thêm callback URL của bạn:
https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- 👉 Nhấp Create.
- 📋 Sao chép Client ID và Client secret.
C2. Thêm Google vào Cloudflare
- 👉 Zero Trust → Settings → Authentication → Add new.
- 👉 Chọn Google (cho mọi Gmail) hoặc Google Workspace (cho tên miền công ty + nhóm).
- ⌨️ Dán Client ID và Client secret.
- Với Google Workspace (để đọc nhóm): làm theo hướng dẫn trên màn hình để cung cấp admin email / domain để Cloudflare đọc được thành viên nhóm.
- 👉 Nhấp Save.
✅ Điểm kiểm tra: "Google Workspace" xuất hiện trong phương thức đăng nhập. Bây giờ sang Phần E — Test.
Phần D — Chưa có IdP doanh nghiệp?
Bạn vẫn có thể tiếp tục và kết nối IdP thật sau.
- Cloudflare là đăng nhập mặc định cho tài khoản mới — người dùng đăng nhập bằng tài khoản Cloudflare.
- Hoặc thêm One-time PIN (OTP): Zero Trust → Settings → Authentication → Add new → One-time PIN. Người dùng nhận mã qua email. Hợp cho nhà thầu và kiểm tra nhanh.
💡 Mẹo: Giữ OTP hoặc đăng nhập Cloudflare bật làm dự phòng ngay cả sau khi bạn thêm IdP doanh nghiệp — đó là lưới an toàn nếu kết nối SSO bao giờ bị đứt.
Phần E — Kiểm tra kết nối (mọi người đều làm)
- 👉 Trong Settings → Authentication → Login methods, tìm nhà cung cấp của bạn trong danh sách.
- 👉 Nhấp nhà cung cấp, rồi nhấp nút Test.
📺 Bạn sẽ thấy: Một tab mới mở, chạy đăng nhập thật với nhà cung cấp của bạn, rồi hiện trang thành công liệt kê danh tính Cloudflare nhận được — email của người dùng và (quan trọng) nhóm của họ.
✅ Điểm kiểm tra — đây là thời điểm then chốt:
- ✅ Đăng nhập thành công.
- ✅ Kết quả hiện email của bạn.
- ✅ Kết quả hiện nhóm của bạn (ví dụ
Engineering, Finance).
⚠️ Nếu thiếu nhóm: quyền/claim nhóm chưa được đặt. Quay lại nhà cung cấp:
- Entra ID: xác nhận
GroupMember.Read.All đã được thêm và admin consent đã cấp (Bước A3), và Support Groups đang bật trong Cloudflare (A4).
- Okta: bật groups claim, và thêm API token nếu bạn có >100 nhóm.
- Google: đảm bảo bạn chọn Google Workspace (không phải Google thường) và đã cấp quyền admin/domain.
Nếu test này không có nhóm, các rule truy cập theo nhóm ở mô-đun sau sẽ không khớp. Sửa điều này trước khi tiếp tục.
Phần F — Bật xác thực đa yếu tố
- 👉 Zero Trust → Access controls → Access settings (menu cũ: Settings → Authentication → Authentication settings).
- 👉 Cấu hình:
| Thiết lập |
Khuyến nghị |
| Allow multi-factor authentication (MFA) |
On |
| Authentication methods |
Chọn các yếu tố đã duyệt của bạn |
| Use identity provider MFA |
On — dùng lại MFA của IdP để người dùng không bị hỏi hai lần |
| Apply global MFA settings by default |
On |
| Authentication duration |
24h (dùng ngắn hơn cho ứng dụng nhạy cảm sau này) |
- 👉 Nhấp Save.
✅ Điểm kiểm tra: MFA được bắt buộc cho các lần đăng nhập về sau.
✅ Hoàn thành Mô-đun 2!
Bây giờ bạn có:
- ✅ Đăng nhập công ty đã kết nối với Cloudflare
- ✅ Một lần Test thành công hiện email và nhóm
- ✅ (Khuyến nghị) SCIM tự đồng bộ đã bật
- ✅ MFA đã bật
- ✅ Một phương thức đăng nhập dự phòng (OTP / Cloudflare) được giữ lại
Khắc phục nhanh
| Vấn đề |
Cách khắc phục |
| Lỗi "Redirect URI mismatch" khi Test |
Callback URL trong IdP không khớp chính xác. Sao chép lại gồm https:// và /cdn-cgi/access/callback, không có khoảng trắng thừa |
| Test hiện email nhưng không có nhóm |
Thiếu quyền/claim nhóm — xem ghi chú ⚠️ ở Phần E |
| "Invalid client secret" |
Secret sai hoặc hết hạn. Tạo cái mới và cập nhật Cloudflare (Entra: A2; Okta/Google: sao chép lại) |
| Người dùng đăng nhập được nhưng bạn không vô hiệu hóa họ được |
Bật SCIM (Entra/Okta) để hủy cấp phát đồng bộ và thu hồi phiên |
| Bị khóa khi kiểm tra SAML |
Dùng đăng nhập OTP/Cloudflare dự phòng (Phần D) để vào lại |
Bạn sẽ cài Cloudflare One Client để thiết bị kết nối an toàn và báo cáo sức khỏe.
Module 2 — Connect Your Identity Provider
Goal: Connect your company login system so Cloudflare knows who each user is and which groups they belong to. This is the foundation every later policy depends on.
|
|
| 👤 Who does this |
IT / Identity administrator |
| ⏱️ Time |
~45 minutes |
| 🎯 You'll finish with |
Users able to sign in with their company account; the Test button showing their email + groups |
| ✋ Before you begin |
Admin access to your identity provider, and your team domain from Module 1 |
First: copy your callback URL
Every identity provider needs this one value from you. Write it down now (replace <team-name>):
https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback
This guide calls it your callback URL. (Google also needs the JavaScript origin: https://<team-name>.cloudflareaccess.com.)
💡 Which provider are you using? Jump to your section:
Then everyone does Part E — Test and Part F — MFA.
Part A — Microsoft Entra ID (Azure AD)
You'll do this in two places: first in Microsoft's admin center, then in Cloudflare.
A1. Register an application in Microsoft Entra
- 👉 Open
https://entra.microsoft.com and sign in with a Global Administrator account.
- 👉 In the left menu: Applications → Enterprise applications.
- 👉 Click + New application (top of the page).
- 👉 Click + Create your own application (top of the page).
- 📺 A panel opens on the right. ⌨️ Name it
Cloudflare Access.
- 👉 Select the option "Register an application to integrate with Microsoft Entra ID (App you're developing)".
⚠️ Watch out: Do not pick a gallery/SaaS app — you're registering your own.
- 👉 Click Create.
📺 What you'll see: A "Register an application" page with a Redirect URI section.
- 👉 Under Redirect URI, set the platform dropdown to Web.
- ⌨️ Paste your callback URL:
https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- 👉 Click Register.
✅ Checkpoint: You're now on the app's Overview page.
A2. Copy three values
On the app Overview page:
- 📋 Copy Application (client) ID → save it.
- 📋 Copy Directory (tenant) ID → save it.
Now create the secret:
3. 👉 Left menu of the app → Certificates & secrets → Client secrets tab → + New client secret.
4. ⌨️ Description: Cloudflare. Set an expiry (e.g. 24 months).
5. 👉 Click Add.
6. 📋 Immediately copy the secret Value (not the "Secret ID") → save it.
⚠️ Watch out: The secret Value is shown only once. If you navigate away, you must delete it and make a new one. Also, when it expires, all logins stop — set a calendar reminder to renew before the expiry date.
A3. Grant permissions (so Cloudflare can read groups)
-
👉 Left menu of the app → API permissions → + Add a permission.
-
👉 Choose Microsoft Graph → Delegated permissions.
-
⌨️ Search for and tick each of these seven permissions:
| Permission |
Why |
email |
The user's email |
offline_access |
Keeps sessions refreshed |
openid |
Standard sign-in |
profile |
Basic profile info |
User.Read |
Read the signed-in user |
Directory.Read.All |
Read your directory |
GroupMember.Read.All |
Read group membership (needed for group rules) |
-
👉 Click Add permissions.
-
👉 Click Grant admin consent for [your org] → Yes.
✅ Checkpoint: All seven permissions show "Granted for [your org]" with green checkmarks.
A4. Add Entra ID to Cloudflare
- 👉 Go to the Zero Trust dashboard (
https://one.dash.cloudflare.com).
- 👉 Settings → Authentication (you may see it as Integrations → Identity providers).
- 👉 Under Login methods, click Add new.
- 👉 Select Azure AD (Microsoft Entra ID).
- ⌨️ Fill in:
| Field |
Paste |
| Application (client) ID |
from A2 |
| Application (client) Secret |
the secret Value from A2 |
| Directory (tenant) ID |
from A2 |
- 👉 Turn on these options:
- ✅ Support Groups (so Cloudflare reads Entra groups)
- ✅ Proof Key for Code Exchange (PKCE)
- ✅ Enable SCIM (recommended — auto-syncs users/groups and can revoke access when someone is disabled)
- 👉 Click Save.
✅ Checkpoint: "Azure AD" now appears in your list of login methods. Now jump to Part E — Test.
Part B — Okta
B1. Create an app in Okta
- 👉 Sign in to your Okta admin console.
- 👉 Applications → Applications → Create App Integration.
- 👉 Choose OIDC - OpenID Connect → Web Application → Next.
- ⌨️ Name it
Cloudflare Access.
- ⌨️ Under Sign-in redirect URIs, paste your callback URL:
https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- 👉 Under Assignments, choose who can use it (e.g. "Allow everyone in your organization"), then Save.
B2. Copy two values
On the app's General tab:
- 📋 Copy Client ID.
- 📋 Copy Client secret.
- 📝 Note your Okta domain (the URL you log in at, e.g.
https://my-company.okta.com).
B3. Add Okta to Cloudflare
- 👉 Zero Trust → Settings → Authentication → Add new → Okta.
- ⌨️ Fill in:
| Cloudflare field |
Value |
| App ID |
Okta Client ID |
| Client secret |
Okta Client secret |
| Okta account URL |
https://my-company.okta.com |
- 👉 Turn on Support Groups if you'll use group-based rules.
- 👉 Click Save.
⚠️ Watch out: If your org has more than 100 Okta groups, you must also create a read-only Okta API token and paste it in, or group lookups will fail. (Okta admin → Security → API → Tokens → Create Token.)
✅ Checkpoint: "Okta" appears in your login methods. Now go to Part E — Test.
Part C — Google Workspace
C1. Create OAuth credentials in Google
- 👉 Open
https://console.cloud.google.com → select or create a project.
- 👉 APIs & Services → Credentials → + Create Credentials → OAuth client ID.
- 👉 Application type: Web application.
- ⌨️ Authorized JavaScript origins → add:
https://<team-name>.cloudflareaccess.com
- ⌨️ Authorized redirect URIs → add your callback URL:
https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- 👉 Click Create.
- 📋 Copy the Client ID and Client secret.
C2. Add Google to Cloudflare
- 👉 Zero Trust → Settings → Authentication → Add new.
- 👉 Choose Google (for any Gmail) or Google Workspace (for your company domain + groups).
- ⌨️ Paste the Client ID and Client secret.
- For Google Workspace (to read groups): follow the on-screen prompt to provide your admin email / domain so Cloudflare can read group membership.
- 👉 Click Save.
✅ Checkpoint: "Google Workspace" appears in your login methods. Now go to Part E — Test.
Part D — No corporate IdP yet?
You can still proceed and connect a real IdP later.
- Cloudflare is the default login for new accounts — users sign in with a Cloudflare account.
- Or add One-time PIN (OTP): Zero Trust → Settings → Authentication → Add new → One-time PIN. Users get a code by email. Good for contractors and quick testing.
💡 Tip: Keep OTP or Cloudflare login enabled as a backup even after you add your corporate IdP — it's your safety net if the SSO connection ever breaks.
Part E — Test your connection (everyone does this)
- 👉 In Settings → Authentication → Login methods, find your provider in the list.
- 👉 Click the provider, then click the Test button.
📺 What you'll see: A new tab opens, runs a real login against your provider, and then shows a success page listing the identity Cloudflare received — the user's email and (importantly) their groups.
✅ Checkpoint — this is the key moment:
- ✅ Login succeeds.
- ✅ The result shows your email.
- ✅ The result shows your groups (e.g.
Engineering, Finance).
⚠️ If groups are missing: your group permissions/claims aren't set. Go back to your provider:
- Entra ID: confirm
GroupMember.Read.All was added and admin consent granted (Step A3), and Support Groups is on in Cloudflare (A4).
- Okta: enable a groups claim, and add the API token if you have >100 groups.
- Google: make sure you chose Google Workspace (not plain Google) and provided admin/domain access.
Without groups in this test, your group-based access rules in later modules will not match. Fix this before continuing.
Part F — Turn on multi-factor authentication
- 👉 Zero Trust → Access controls → Access settings (older menus: Settings → Authentication → Authentication settings).
- 👉 Configure:
| Setting |
Recommended |
| Allow multi-factor authentication (MFA) |
On |
| Authentication methods |
Select your approved factors |
| Use identity provider MFA |
On — re-uses your IdP's MFA so users aren't prompted twice |
| Apply global MFA settings by default |
On |
| Authentication duration |
24h (use shorter for sensitive apps later) |
- 👉 Click Save.
✅ Checkpoint: MFA is enforced for sign-ins going forward.
✅ Module 2 complete!
You now have:
- ✅ Your company login connected to Cloudflare
- ✅ A passing Test showing email and groups
- ✅ (Recommended) SCIM auto-sync enabled
- ✅ MFA turned on
- ✅ A backup login method (OTP / Cloudflare) retained
Quick troubleshooting
| Problem |
Fix |
| "Redirect URI mismatch" error during Test |
The callback URL in your IdP doesn't exactly match. Re-copy it including https:// and /cdn-cgi/access/callback, no trailing space |
| Test shows email but no groups |
Group permission/claim missing — see the ⚠️ note in Part E |
| "Invalid client secret" |
The secret is wrong or expired. Create a new one and update Cloudflare (Entra: A2; Okta/Google: re-copy) |
| Users can log in but you can't disable them |
Enable SCIM (Entra/Okta) so deprovisioning syncs and revokes sessions |
| Locked out testing SAML |
Use your backup OTP/Cloudflare login (Part D) to get back in |
You'll install the Cloudflare One Client so devices connect securely and report their health.
Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev
Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev