Mô-đun 3c — Kiểm tra posture thiết bị
Mục tiêu: Xác minh thiết bị khỏe mạnh và đáng tin — đĩa đã mã hóa, firewall bật, hệ điều hành mới nhất, đang chạy EDR của bạn, thuộc công ty — và dùng các tín hiệu đó trong chính sách Access và Gateway để chỉ thiết bị tuân thủ mới tới được tài nguyên nhạy cảm.
|
|
| 👤 Ai làm việc này |
Đội Security / endpoint |
| ⏱️ Thời gian |
~40 phút |
| 🎯 Kết thúc bạn sẽ có |
Các kiểm tra posture dùng lại được, chặn truy cập, được đánh giá liên tục trên mọi yêu cầu |
| ✋ Trước khi bắt đầu |
Mô-đun 3 xong (thiết bị đã đăng ký ở Gateway with WARP). Kiểm tra nâng cao/bên thứ ba cần Enterprise. |
🧭 Vì sao posture quan trọng. Danh tính trả lời "người dùng này là ai?" Posture trả lời "thiết bị họ đang dùng có an toàn để tin không?" Zero Trust cần cả hai. Một kiểm tra posture là tín hiệu dùng lại được bạn định nghĩa một lần và tham chiếu trên nhiều chính sách Access và Gateway — và vì Cloudflare đánh giá nó trên mọi yêu cầu, ngay khi thiết bị rơi khỏi tuân thủ (firewall tắt, đĩa giải mã, hệ điều hành lỗi thời), truy cập bị cắt tự động.
💡 Phần này mở rộng Phần E của Mô-đun 3. Mô-đun 3 thêm một kiểm tra đơn giản; đây là bộ công cụ đầy đủ.
Hai loại kiểm tra posture
| Loại |
Tín hiệu đến từ |
Ví dụ |
Gói |
| WARP client checks |
Cloudflare One Client trên thiết bị |
Mã hóa đĩa, firewall, phiên bản hệ điều hành, file/app có mặt, số serial, client certificate, antivirus |
Gói Free có phần cơ bản; thêm trên gói trả phí |
| Service provider checks (service-to-service, S2S) |
Một nền tảng bảo mật bên thứ ba qua API |
CrowdStrike, SentinelOne, Microsoft Intune, Tanium, Carbon Black, Kolide… |
Enterprise |
Bạn xây cả hai ở cùng một chỗ và tham chiếu chúng theo cùng cách trong chính sách.
Phần A — Các kiểm tra WARP client có sẵn
Chúng đến thẳng từ Cloudflare One Client — không cần công cụ bên thứ ba.
| Kiểm tra |
Nó xác minh gì |
Hệ điều hành điển hình |
| Disk encryption |
Một số/tất cả đĩa đã được mã hóa (BitLocker, FileVault…) |
Win / macOS / Linux |
| Firewall |
Một firewall đang chạy |
Win / macOS |
| OS version |
Hệ điều hành ở/trên một phiên bản (với độ chi tiết build/revision) |
Win / macOS / Linux / iOS / Android |
| Antivirus (mới hơn, Windows) |
Có chương trình antivirus — tùy chọn đã cập nhật |
Win |
| Application check |
Một tiến trình cụ thể đang chạy (ví dụ agent EDR của bạn) |
Win / macOS / Linux |
| File check |
Một file cụ thể tồn tại (ví dụ dấu hiệu tuân thủ) |
Win / macOS / Linux |
| Domain joined |
Thiết bị đã join domain Microsoft AD của bạn |
Win |
| Device serial number |
Serial khớp danh sách thiết bị công ty của bạn |
Win / macOS / Linux |
| Unique Client ID |
Khớp UUID do MDM gán |
iOS / Android / ChromeOS / desktop |
| Client certificate |
Có client cert hợp lệ được cài (ghim danh tính thiết bị) |
Win / macOS / Linux / iOS / Android |
| Require WARP |
Thiết bị đang kết nối qua Cloudflare One Client |
Tất cả |
| Require Gateway |
Lưu lượng đang chảy qua Gateway |
Tất cả |
💡 Mẹo mạnh về client certificate: kiểm tra cert hỗ trợ biến mẫu — ${serial_number} và ${device_uuid} — ở cả Common Name và Subject Alternative Name, để bạn có thể ghim chứng chỉ vào một danh tính thiết bị cụ thể.
Phần B — Tạo một kiểm tra WARP client
Hãy xây kiểm tra "disk encrypted" (lặp lại mẫu này cho bất kỳ kiểm tra nào ở trên).
- 👉 Trong bảng điều khiển, vào Settings → WARP Client → Device posture (hoặc Reusable components → Posture checks).
- 👉 Nhấp Add new → chọn Disk encryption.
- ⌨️ Đặt tên rõ ràng, ví dụ
Disk encrypted.
- 👉 Chọn các operating systems mà kiểm tra áp dụng.
- 👉 Đặt check frequency (tần suất client đánh giá lại, ví dụ mỗi 5 phút).
- 👉 Cấu hình chi tiết (với Disk encryption: đĩa nào phải được mã hóa).
- 👉 Nhấp Save.
📺 Bạn sẽ thấy: kiểm tra được liệt kê dưới Device posture, đang đánh giá các thiết bị đã đăng ký, mỗi thiết bị hiện compliant / non-compliant.
✅ Điểm kiểm tra: thiết bị pilot của bạn báo compliant cho kiểm tra (giả sử đĩa thực sự đã được mã hóa).
⭐ Thực hành tốt — kiểm tra OS version: yêu cầu phiên bản mới nhất bạn đã kiểm thử, không phải bản mới tuyệt đối. Một bản phát hành hệ điều hành trong ngày có thể khóa cả đội thiết bị ngay khi nó ra mắt.
Phần C — Thêm kiểm tra bên thứ ba (service provider) (Enterprise)
Đưa tín hiệu từ EDR/MDM bạn đã chạy vào quyết định truy cập của Cloudflare.
- 👉 Vào Settings → WARP Client → Device posture → Add new.
- 👉 Chọn nhà cung cấp của bạn — ví dụ CrowdStrike, SentinelOne, Microsoft Intune (Endpoint Manager), Tanium, Carbon Black, Kolide.
- 👉 Làm theo các lời nhắc riêng của nhà cung cấp: dán API credentials / client ID + secret từ bảng quản trị của nền tảng đó để Cloudflare truy vấn trạng thái thiết bị.
- ⌨️ Đặt evaluation criteria — ví dụ CrowdStrike Zero Trust Assessment (ZTA) score ≥ 50, hoặc Intune compliant = true.
- 👉 Save và xác nhận tích hợp kết nối được.
💡 Cách hoạt động: Cloudflare khớp thiết bị (theo serial, ID hoặc email) với API của nhà cung cấp và lấy điểm rủi ro / trạng thái tuân thủ — nên "thiết bị không có mối đe dọa theo CrowdStrike" trở thành điều kiện bạn có thể yêu cầu.
⚠️ Lưu ý Gateway: hầu hết kiểm tra service-provider hoạt động trong chính sách cả Access lẫn Gateway, nhưng Tanium không được hỗ trợ trong chính sách Gateway — chỉ trong Access. Hãy lập kế hoạch quanh điều đó nếu Tanium là nguồn sự thật của bạn.
Phần D — Dùng posture trong chính sách
Một kiểm tra posture không làm gì cho đến khi một chính sách tham chiếu nó. Hai nơi:
Trong chính sách Access (theo ứng dụng) — Mô-đun 4
- 👉 Access → Applications → ứng dụng của bạn → Policies → sửa/thêm.
- 👉 Thêm quy tắc Require → Selector Device Posture → chọn (các) kiểm tra của bạn, ví dụ
Disk encrypted + CrowdStrike ZTA ≥ 50.
Trong chính sách mạng Gateway (rộng) — Mô-đun 5
- 👉 Gateway → Firewall Policies → Network → Add a policy.
- 👉 Selector Device Posture → kiểm tra của bạn → Action (ví dụ Block nếu non-compliant).
Ví dụ mẫu — "kỹ sư chỉ vào production từ thiết bị khỏe mạnh":
| Quy tắc |
Selector |
Value |
| Include |
IdP Groups |
Engineering |
| Require |
Device Posture |
Disk encrypted |
| Require |
Device Posture |
Firewall on |
| Require |
Device Posture |
CrowdStrike ZTA ≥ 50 |
💡 Dùng lại theo thiết kế: định nghĩa Disk encrypted một lần và thêm vào bao nhiêu ứng dụng/chính sách tùy ý. Cập nhật kiểm tra, và mọi chính sách tham chiếu nó cũng cập nhật — gói các kiểm tra phổ biến vào một Access Group để dùng lại một cú nhấp.
Phần E — Đánh giá lại liên tục (lợi ích Zero Trust)
Posture không phải cổng một lần lúc đăng nhập. Cloudflare kiểm tra lại trên mọi yêu cầu, nên:
- Nếu người dùng tắt firewall hoặc EDR gắn cờ thiết bị giữa phiên, truy cập tới ứng dụng được bảo vệ bị thu hồi tự động — không chờ lần đăng nhập tiếp theo.
- Khi họ sửa xong, truy cập được khôi phục ở lần kiểm tra thành công tiếp theo.
Đây là điều làm "never trust, always verify" trở thành thật: tin cậy được kiếm lại liên tục, không được cấp một lần.
Phần F — Xác minh
- 👉 Dashboard: My Team → Devices → mở một thiết bị → xem tín hiệu posture (compliant / non-compliant theo từng kiểm tra).
- 👉 Trên thiết bị (CLI):
warp-cli posture
- 👉 Kiểm tra thực thi: trên thiết bị tuân thủ, vào một ứng dụng bị chặn bởi posture — được. Rồi phá một tín hiệu (ví dụ tắt firewall trên máy thử) và thử lại — truy cập phải bị từ chối trong cửa sổ đánh giá lại.
✅ Điểm kiểm tra: thiết bị tuân thủ đi qua; thiết bị trượt một kiểm tra bắt buộc bị chặn, và bạn thấy quyết định trong Logs → Access (hoặc nhật ký Gateway).
✅ Mô-đun 3c hoàn tất!
Bạn hiện có:
- ✅ Hiểu WARP client checks so với service-provider checks
- ✅ Một hoặc nhiều kiểm tra posture dùng lại được đã định nghĩa
- ✅ (Enterprise) Tín hiệu EDR/MDM bên thứ ba nuôi quyết định truy cập
- ✅ Posture được yêu cầu trong chính sách Access và/hoặc Gateway
- ✅ Tin rằng thiết bị không tuân thủ bị cắt liên tục, không chỉ lúc đăng nhập
Khắc phục sự cố nhanh
| Vấn đề |
Cách xử lý |
| Selector Device Posture thiếu trong chính sách |
Tạo ít nhất một kiểm tra posture trước (Phần B) — selector chỉ xuất hiện sau đó |
| Thiết bị hiện non-compliant bất ngờ |
Kiểm tra phạm vi hệ điều hành + tiêu chí (ví dụ đĩa nào phải được mã hóa); xác nhận client là phiên bản gần đây |
| Kiểm tra bên thứ ba không bao giờ khớp |
Kiểm tra lại API credentials và việc Cloudflare khớp được thiết bị (serial/ID/email) trên nền tảng đó |
| Kiểm tra Tanium hoạt động trong Access nhưng không trong Gateway |
Đúng như kỳ vọng — Tanium không được hỗ trợ trong chính sách Gateway; dùng nó trong Access (Phần C) |
| Kiểm tra OS-version khóa mọi người ra |
Bạn yêu cầu phiên bản quá mới — đặt thành bản mới nhất bạn đã đủ điều kiện, không phải bản mới tuyệt đối (Phần B) |
| Thay đổi posture chưa phản ánh |
Chờ khoảng đánh giá lại, hoặc tắt/bật client; xác minh bằng warp-cli posture |
Đặt ứng dụng nội bộ sau Access và yêu cầu các kiểm tra posture này để vào.
Module 3c — Device Posture Checks
Goal: Verify that a device is healthy and trusted — disk encrypted, firewall on, latest OS, running your EDR, company-owned — and use those signals in Access and Gateway policies so only compliant devices reach sensitive resources.
|
|
| 👤 Who does this |
Security / endpoint team |
| ⏱️ Time |
~40 minutes |
| 🎯 You'll finish with |
Reusable posture checks that gate access, re-evaluated continuously on every request |
| ✋ Before you begin |
Module 3 done (devices enrolled in Gateway with WARP). Advanced/third-party checks need Enterprise. |
🧭 Why posture matters. Identity answers "who is this user?" Posture answers "is the device they're on safe to trust?" Zero Trust needs both. A posture check is a reusable signal you define once and reference across many Access and Gateway policies — and because Cloudflare evaluates it on every request, the moment a device falls out of compliance (firewall off, disk decrypted, OS out of date), its access is cut automatically.
💡 This expands Part E of Module 3. Module 3 added one simple check; here's the full toolkit.
Two kinds of posture check
| Type |
Signal comes from |
Examples |
Plan |
| WARP client checks |
The Cloudflare One Client on the device |
Disk encryption, firewall, OS version, file/app present, serial number, client certificate, antivirus |
Free tier has basics; more on paid |
| Service provider checks (service-to-service, S2S) |
A third-party security platform via API |
CrowdStrike, SentinelOne, Microsoft Intune, Tanium, Carbon Black, Kolide… |
Enterprise |
You build both in the same place and reference them the same way in policies.
Part A — The built-in WARP client checks
These come straight from the Cloudflare One Client — no third-party tools needed.
| Check |
What it verifies |
Typical OS |
| Disk encryption |
Some/all disks are encrypted (BitLocker, FileVault…) |
Win / macOS / Linux |
| Firewall |
A firewall is running |
Win / macOS |
| OS version |
OS is at/above a version (with build/revision granularity) |
Win / macOS / Linux / iOS / Android |
| Antivirus (newer, Windows) |
An antivirus program is present — optionally up to date |
Win |
| Application check |
A specific process is running (e.g. your EDR agent) |
Win / macOS / Linux |
| File check |
A specific file exists (e.g. a compliance marker) |
Win / macOS / Linux |
| Domain joined |
Device is joined to your Microsoft AD domain |
Win |
| Device serial number |
Serial matches your list of company devices |
Win / macOS / Linux |
| Unique Client ID |
Matches an MDM-assigned UUID |
iOS / Android / ChromeOS / desktop |
| Client certificate |
A valid client cert is installed (pins device identity) |
Win / macOS / Linux / iOS / Android |
| Require WARP |
Device is connected via the Cloudflare One Client |
All |
| Require Gateway |
Traffic is flowing through Gateway |
All |
💡 Client certificate power tip: the cert check supports template variables — ${serial_number} and ${device_uuid} — in both the Common Name and the Subject Alternative Name, so you can pin a certificate to a specific device identity.
Part B — Create a WARP client check
Let's build a "disk encrypted" check (repeat the pattern for any check above).
- 👉 In the dashboard, go to Settings → WARP Client → Device posture (or Reusable components → Posture checks).
- 👉 Click Add new → choose Disk encryption.
- ⌨️ Give it a clear name, e.g.
Disk encrypted.
- 👉 Select the operating systems it applies to.
- 👉 Set the check frequency (how often the client re-evaluates it, e.g. every 5 minutes).
- 👉 Configure the specifics (for Disk encryption: which disks must be encrypted).
- 👉 Click Save.
📺 What you'll see: the check listed under Device posture, evaluating your enrolled devices, each showing compliant / non-compliant.
✅ Checkpoint: your pilot device reports compliant for the check (assuming its disk is actually encrypted).
⭐ Best practice — OS version checks: require the latest version you've already tested, not the absolute newest. A same-day OS release could otherwise lock your whole fleet out the moment it ships.
Part C — Add a third-party (service provider) check (Enterprise)
Feed signals from an EDR/MDM you already run into Cloudflare's access decisions.
- 👉 Go to Settings → WARP Client → Device posture → Add new.
- 👉 Choose your provider — e.g. CrowdStrike, SentinelOne, Microsoft Intune (Endpoint Manager), Tanium, Carbon Black, Kolide.
- 👉 Follow the provider-specific prompts: paste the API credentials / client ID + secret from that platform's admin console so Cloudflare can query device state.
- ⌨️ Set the evaluation criteria — e.g. CrowdStrike Zero Trust Assessment (ZTA) score ≥ 50, or Intune compliant = true.
- 👉 Save and confirm the integration connects.
💡 How it works: Cloudflare matches the device (by serial, ID, or email) against the provider's API and pulls its risk score / compliance state — so "device is free of threats per CrowdStrike" becomes a condition you can require.
⚠️ Gateway caveat: most service-provider checks work in both Access and Gateway policies, but Tanium is not supported in Gateway policies — only in Access. Plan around that if Tanium is your source of truth.
Part D — Use posture in a policy
A posture check does nothing until a policy references it. Two places:
In an Access policy (per-application) — Module 4
- 👉 Access → Applications → your app → Policies → edit/add.
- 👉 Add a Require rule → Selector Device Posture → choose your check(s), e.g.
Disk encrypted + CrowdStrike ZTA ≥ 50.
In a Gateway network policy (broad) — Module 5
- 👉 Gateway → Firewall Policies → Network → Add a policy.
- 👉 Selector Device Posture → your check → Action (e.g. Block if non-compliant).
Worked example — "engineers reach production only from a healthy device":
| Rule |
Selector |
Value |
| Include |
IdP Groups |
Engineering |
| Require |
Device Posture |
Disk encrypted |
| Require |
Device Posture |
Firewall on |
| Require |
Device Posture |
CrowdStrike ZTA ≥ 50 |
💡 Reusable by design: define Disk encrypted once and add it to as many apps/policies as you like. Update the check, and every policy referencing it updates too — bundle common checks into an Access Group for one-click reuse.
Part E — Continuous re-evaluation (the Zero Trust payoff)
Posture isn't a one-time gate at login. Cloudflare re-checks it on every request, so:
- If a user disables their firewall or an EDR flags the device mid-session, its access to protected apps is revoked automatically — no waiting for the next login.
- When they fix it, access is restored on the next successful check.
This is what makes "never trust, always verify" real: trust is re-earned continuously, not granted once.
Part F — Verify
- 👉 Dashboard: My Team → Devices → open a device → review its posture signals (compliant / non-compliant per check).
- 👉 On the device (CLI):
warp-cli posture
- 👉 Test enforcement: on a compliant device, reach a posture-gated app — it works. Then break a signal (e.g. turn off the firewall on a test box) and retry — access should be denied within the re-evaluation window.
✅ Checkpoint: compliant devices pass; a device failing a required check is blocked, and you can see the decision in Logs → Access (or Gateway logs).
✅ Module 3c complete!
You now have:
- ✅ An understanding of WARP client checks vs service-provider checks
- ✅ One or more reusable posture checks defined
- ✅ (Enterprise) A third-party EDR/MDM signal feeding access decisions
- ✅ Posture required in Access and/or Gateway policies
- ✅ Confidence that non-compliant devices are cut off continuously, not just at login
Quick troubleshooting
| Problem |
Fix |
| Device Posture selector missing in a policy |
Create at least one posture check first (Part B) — the selector only appears afterward |
| Device shows non-compliant unexpectedly |
Check the OS scope + criteria (e.g. which disks must be encrypted); confirm the client is a recent version |
| Third-party check never matches |
Re-check the API credentials and that Cloudflare can match the device (serial/ID/email) in that platform |
| Tanium check works in Access but not Gateway |
Expected — Tanium isn't supported in Gateway policies; use it in Access (Part C) |
| OS-version check locked everyone out |
You required a too-new version — set it to the latest you've qualified, not the absolute newest (Part B) |
| Posture change not reflected |
Wait for the re-evaluation interval, or toggle the client off/on; verify with warp-cli posture |
Put a private app behind Access and require these posture checks for entry.
Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev
Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev