---
title: Cloudflare One Changelog
image: https://edgetunnel-b2h.pages.dev/cf-twitter-card.png
---

> Documentation Index  
> Fetch the complete documentation index at: https://edgetunnel-b2h.pages.dev/changelog/llms.txt  
> Use this file to discover all available pages before exploring further. 

[Skip to content](#%5Ftop) 

# Changelog

New updates and improvements at Cloudflare.

[ Subscribe to RSS ](https://edgetunnel-b2h.pages.dev/changelog/rss/index.xml) [ View RSS feeds ](https://edgetunnel-b2h.pages.dev/fundamentals/new-features/available-rss-feeds/) 

Cloudflare One

![hero image](https://edgetunnel-b2h.pages.dev/_astro/hero.CVYJHPAd_26AMqX.svg) 

May 07, 2026
1. ### [Self-serve provisioning of Cloudflare One Virtual Appliance via API](https://edgetunnel-b2h.pages.dev/changelog/post/2026-05-07-virtual-appliance-self-serve-api/)  
[ Cloudflare One Appliance ](https://edgetunnel-b2h.pages.dev/cloudflare-wan/configuration/appliance/)[ Cloudflare One ](https://edgetunnel-b2h.pages.dev/cloudflare-one/)[ Cloudflare WAN ](https://edgetunnel-b2h.pages.dev/cloudflare-wan/)  
You can now create, rotate, and delete Cloudflare One Virtual Appliance instances and their license keys directly via the API and Terraform.

  * Create a virtual appliance and receive a license key: `POST /accounts/{account_id}/magic/connectors` with `device.provision_license: true`.
  * Rotate the license key for an existing virtual appliance: `PATCH /accounts/{account_id}/magic/connectors/{connector_id}` with `provision_license: true`. The previous key is immediately and irrevocably revoked.
  * Delete a virtual appliance to release the associated licensed device.  
The license key is returned in the response only once, at create or rotate time. Copy and store it securely.  
For details, refer to [Configure a Cloudflare One Virtual Appliance](https://edgetunnel-b2h.pages.dev/cloudflare-wan/configuration/appliance/configure-virtual-appliance/).

May 06, 2026
1. ### [Cloudy Summaries in PhishNet O365](https://edgetunnel-b2h.pages.dev/changelog/post/2026-05-06-cloudy-summaries-in-phishnet%5Fo365/)  
[ Email security ](https://edgetunnel-b2h.pages.dev/cloudflare-one/email-security/)  
PhishNet users can now access **Cloudy summaries** directly within the email investigation experience. When reviewing a message in PhishNet, users will see an AI-generated summary that provides additional context and key details about the email.  
These summaries help users quickly understand the nature of a message without needing to manually parse through headers, body content, and detection signals. Cloudy surfaces the most relevant information so users can make faster, more informed decisions about suspicious emails.

**These summaries are not trained on customer data.** They are generated using the outputs of our existing detection models and analysis systems.  
This feature is available for PhishNet with Office 365\. Support for Gmail will be available by the end of the quarter.

May 06, 2026
1. ### [IPv6 CIDR routes for Cloudflare Mesh](https://edgetunnel-b2h.pages.dev/changelog/post/2026-05-06-mesh-ipv6-routes/)  
[ Cloudflare One ](https://edgetunnel-b2h.pages.dev/cloudflare-one/)  
[Cloudflare Mesh](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-mesh/) nodes now support IPv6 CIDR routes. You can advertise both IPv4 and IPv6 subnets through your Mesh nodes, making IPv6-only or dual-stack private networks reachable from any enrolled device.  
![IPv6 CIDR routes on a Mesh node in the Cloudflare dashboard](https://edgetunnel-b2h.pages.dev/_astro/mesh-ipv6-routes.CC-jlZkw_Z16Puzf.webp)  
To add an IPv6 route, follow the same steps as [adding an IPv4 route](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-mesh/routes/#add-a-route) — enter the IPv6 CIDR (for example, `fd00::/64`) when configuring the route in the [dashboard ↗](https://dash.cloudflare.com/?to=/:account/mesh) or via the API.

Apr 30, 2026
1. ### [Post-quantum IPsec interoperability with third-party devices](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-30-ipsec-post-quantum-third-party/)  
[ Cloudflare One ](https://edgetunnel-b2h.pages.dev/cloudflare-one/)[ Cloudflare WAN ](https://edgetunnel-b2h.pages.dev/cloudflare-wan/)  
Cloudflare IPsec now supports post-quantum key agreement with compatible third-party devices. [Cisco ↗](https://www.cisco.com/) and [Fortinet ↗](https://www.fortinet.com/) are the first third-party vendors validated to interoperate with Cloudflare IPsec using ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism).  
Post-quantum IPsec uses [RFC 9370 ↗](https://datatracker.ietf.org/doc/rfc9370/) and [draft-ietf-ipsecme-ikev2-mlkem ↗](https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-mlkem/) to negotiate hybrid key agreement during the IKEv2 `IKE_INTERMEDIATE` phase. This combines classical Diffie-Hellman (Group 20) with ML-KEM-768 or ML-KEM-1024 to protect against [harvest-now, decrypt-later ↗](https://en.wikipedia.org/wiki/Harvest%5Fnow,%5Fdecrypt%5Flater) attacks.  
Key details:

  * Compatible with Cisco 8000 Series Secure Routers with IOS XR Release 26.1.1 and Fortinet FortiOS 7.6.6 and later.
  * Uses ML-KEM-768 or ML-KEM-1024 as an additional Key Exchange to DH Group 20.
  * Follows RFC 9370 and draft-ietf-ipsecme-ikev2-mlkem standards.
  * No additional licensing required.  
Post-quantum IPsec with third-party devices is now generally available with confirmed interoperability for the platforms listed above. Cloudflare intends to support interoperability with more vendors as they build out support for draft-ietf-ipsecme-ikev2-mlkem. Contact your account team to discuss support for additional vendors.  
For supported key exchange methods and the list of validated platforms, refer to [GRE and IPsec tunnels](https://edgetunnel-b2h.pages.dev/cloudflare-wan/reference/gre-ipsec-tunnels/#tested-third-party-vendor-interoperability).

Apr 30, 2026
1. ### [Classify sensitive content with Data Classification](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-30-data-classification/)  
[ Data Loss Prevention ](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/)  
Cloudflare DLP now includes **Data Classification**, which lets administrators organize and label sensitive content using labels, templates, and reusable data classes.  
With Data Classification, administrators can define labels such as sensitivity schemas and levels, and data tag groups and tags. Administrators can also build from Cloudflare-managed templates and create reusable data classes that combine detection entries, other data classes, sensitivity levels, and data tags.  
You can then use those classifications in custom DLP profiles to identify the severity of sensitive content, understand where it exists, and apply that logic consistently across DLP profiles.  
For more information, refer to [Data Classification](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/data-classification/).

Apr 30, 2026
1. ### [New predefined detection entries are available](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-30-standalone-predefined-detection-entries/)  
[ Data Loss Prevention ](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/)  
Cloudflare DLP now includes new predefined detection entries.  
The expanded catalog includes detections for specific credential types, webhooks, addresses, tax identifiers, national IDs, financial data, and crypto wallets.  
Examples include `GitHub PAT`, `OpenAI API Key`, `Slack Webhook`, `Discord Webhook`, `US Physical Address`, and `Bitcoin Wallet`.  
For the full list, refer to [Predefined detection entries](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/detection-entries/predefined-detection-entries/).

Apr 29, 2026
1. ### [Digital experience tests to authenticated resources and enhanced configuration](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-29-dex-tests-to-auth/)  
[ Digital Experience Monitoring ](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/dex/)  
[Digital experience tests](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/dex/tests/) now support testing applications protected by Cloudflare Access or third-party authentication. All authentication secrets are managed via [Cloudflare Secret Store](https://edgetunnel-b2h.pages.dev/secrets-store/).  
Digital experience tests also have enhanced configuration options including:

  * New HTTP methods (DELETE, PATCH, POST, PUT)
  * Secret Store headers, custom plain text headers, and custom request bodies
  * Advanced settings: follow redirects, response bodies, response headers, and allow untrusted certificates  
![Digital experience test configuration for Cloudflare Access applications](https://edgetunnel-b2h.pages.dev/_astro/dex_test_auth_config.CD3G3zb__o7m7g.webp)![Digital experience enhanced test configuration](https://edgetunnel-b2h.pages.dev/_astro/dex_test_enhanced_config.Nsv7Vcob_ppxh5.webp)

Apr 29, 2026
1. ### [Gateway Authorization Proxy and hosted PAC files are now generally available](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-29-gateway-authorization-proxy-pac-files-ga/)  
[ Gateway ](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/)  
The [Gateway Authorization Proxy](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#authorization-endpoint) and [hosted PAC files](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#create-a-hosted-pac-file) are now generally available for all plan types.  
Authorization proxy endpoints add an identity-aware option alongside the existing [source IP proxy endpoints](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#source-ip-endpoint), using [Cloudflare Access](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/policies/) authentication to verify who a user is before applying Gateway filtering — without installing the [Cloudflare One Client](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/devices/cloudflare-one-client/). Cloudflare-hosted PAC files let you create and distribute PAC files directly from Cloudflare One on Cloudflare's global network.  
These features are ideal for environments where deploying a device client is not an option, such as virtual desktops (VDI) or compliance-restricted endpoints.  
To get started, refer to the [proxy endpoints documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/).

Apr 28, 2026
1. ### [Internet outage notifications for devices](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-28-dex-internet-outage-notification/)  
[ Digital Experience Monitoring ](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/dex/)  
[Digital Experience](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/dex/) will display a dashboard notification when an Internet outage or traffic anomaly may impact a [Cloudflare One Client](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) device based on its geographic location or network connection.  
This Internet outage and traffic anomaly data is pulled from [Cloudflare Radar ↗](https://radar.cloudflare.com/). All Internet outage and traffic anomaly observations can be viewed in the [Radar Outage Center ↗](https://radar.cloudflare.com/outage-center).  
![Digital Experience Monitoring dashboard notification for Internet outage impacting Cloudflare One Client devices](https://edgetunnel-b2h.pages.dev/_astro/dex_radar_ux_notification.CpdrUVYA_ZSzgIe.webp)![Digital Experience Monitoring dashboard analytics for Internet outage impacting Cloudflare One Client devices](https://edgetunnel-b2h.pages.dev/_astro/dex_radar_analytics.GaPxWM6C_2jLyzS.webp)

Apr 28, 2026
1. ### [Cloudflare One Client speed tests](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-28-dex-speed-test/)  
[ Digital Experience Monitoring ](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/dex/)  
IT teams can now remotely run speed tests from the [Cloudflare One Client](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) to Cloudflare's network edge.  
Each speed test includes the following metrics:

  * Internet speed: download and upload throughput
  * Latency: download, upload, unloaded latency, and jitter
  * Network quality score: video streaming, webchat/real-time communication (RTC)  
In the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), go to **Zero Trust** \> **Insights** \> **Digital experience** \> **Diagnostics** and select **Run diagnostics** to use the feature today.  
![Cloudflare One client speed test result](https://edgetunnel-b2h.pages.dev/_astro/dex_speed_test.DukupcRs_gXUVw.webp)

Apr 28, 2026
1. ### [Create and manage DLP detection entries outside of profiles](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-28-detection-entries-outside-profiles/)  
[ Data Loss Prevention ](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/)  
You can now create, view, and manage DLP detection entries outside of profiles.  
Detection entries are no longer hidden inside individual profiles. Administrators can manage detection entries directly from the **Detection entries** section and use them in custom DLP profiles.  
For more information, refer to [Configure detection entries](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/detection-entries/configure-detection-entries/).

Apr 28, 2026
1. ### [Detect PII records with a new predefined DLP profile](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-28-pii-record-profile/)  
[ Data Loss Prevention ](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/)  
Cloudflare DLP now includes a new predefined profile designed to detect PII records that contain multiple types of personal data: **Personally Identifiable Information (PII) Record**.  
Most predefined and custom DLP profiles match when any enabled detection entry matches. The **Personally Identifiable Information (PII) Record** profile is different. It only matches when at least three unique detection entries are found in close proximity, which reduces false positives from standalone values that may not represent a real PII record.  
Detection entries included in the profile:

  * AU Passport Number
  * American Express Card Number
  * Diners Club Card Number
  * US Driver's License Number
  * Email Address
  * Full Name
  * US Mailing Address
  * Mastercard Card Number
  * US Individual Tax Identification Number (ITIN)
  * US Passport Number
  * US Phone Number
  * Union Pay Card Number
  * United States SSN Numeric Detection
  * Visa Card Number  
For more information, refer to [predefined DLP profiles](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/dlp-profiles/predefined-profiles/).

Apr 24, 2026
1. ### [Network Session Logs now available for all on-ramps](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-24-nsl-all-onramps/)  
[ Gateway ](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/)[ Cloudflare One ](https://edgetunnel-b2h.pages.dev/cloudflare-one/)  
[Zero Trust Network Session Logs](https://edgetunnel-b2h.pages.dev/logs/logpush/logpush-job/datasets/account/zero%5Ftrust%5Fnetwork%5Fsessions/) are now generated for all traffic proxied through Cloudflare Gateway, regardless of on-ramp type. This includes traffic from [proxy endpoints (PAC files)](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) and [Browser Isolation](https://edgetunnel-b2h.pages.dev/cloudflare-one/remote-browser-isolation/) egress — on-ramps that previously did not generate session logs.  
Customers who already consume the `zero_trust_network_sessions` dataset via [Logpush](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/logs/logpush/) or [Log Explorer](https://edgetunnel-b2h.pages.dev/log-explorer/) may see increased log volume if they use these on-ramps.  
For field definitions, refer to [Zero Trust Network Session Logs](https://edgetunnel-b2h.pages.dev/logs/logpush/logpush-job/datasets/account/zero%5Ftrust%5Fnetwork%5Fsessions/). For traffic analysis, refer to [Network session analytics](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/analytics/network-sessions/).

Apr 23, 2026
1. ### [AAGUID restrictions and AMR matching for Access independent MFA](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-23-independent-mfa-aaguid-amr/)  
[ Access ](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/policies/)  
[Independent MFA](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/access-settings/independent-mfa/) in Cloudflare Access now supports two additional organization-level controls:

  * **[Restrict authenticators by AAGUID](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/access-settings/independent-mfa/#restrict-authenticators-by-aaguid)** — Limit enrollment to a specific set of WebAuthn authenticators using their [AAGUID ↗](https://fidoalliance.org/specs/fido-v2.0-id-20180227/fido-registry-v2.0-id-20180227.html#authenticator-attestation-guid). This is useful for organizations that require FIPS-validated security keys or company-issued hardware. AAGUIDs are managed through a new [List](https://edgetunnel-b2h.pages.dev/cloudflare-one/reusable-components/lists/) type.
  * **[AMR matching](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/access-settings/independent-mfa/#use-identity-provider-mfa)** — Skip the independent MFA prompt when the identity provider has already performed an equivalent MFA. Access reads the `amr` claim defined in [RFC 8176 ↗](https://datatracker.ietf.org/doc/html/rfc8176) and matches supported values such as `hwk`, `otp`, and `fpt` to the authenticator types allowed on the application or policy. This prevents users from having to complete MFA twice when their identity provider already enforces it.  
To get started, refer to [Independent MFA](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/access-settings/independent-mfa/).

Apr 21, 2026
1. ### [Country rules supported in Unified Routing](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-21-unified-routing-geoip-country-rules/)  
[ Cloudflare Network Firewall ](https://edgetunnel-b2h.pages.dev/cloudflare-network-firewall/)[ Magic Transit ](https://edgetunnel-b2h.pages.dev/magic-transit/)[ Cloudflare WAN ](https://edgetunnel-b2h.pages.dev/cloudflare-wan/)  
[Cloudflare Advanced Network Firewall](https://edgetunnel-b2h.pages.dev/cloudflare-network-firewall/) Country rules are now supported for accounts using [Unified Routing](https://edgetunnel-b2h.pages.dev/cloudflare-wan/reference/traffic-steering/#unified-routing-mode-beta) mode. This feature requires a Cloudflare Advanced Network Firewall subscription.  
You can create firewall rules that match traffic based on source or destination country to enforce geographic access policies across your network.  
This is the first of the Cloudflare Advanced Network Firewall features to become available in Unified Routing. Support for additional features - IP Lists, ASN Lists, Threat Intel Lists, IDS, Rate Limiting, SIP, and Managed Rulesets - is planned.  
For the full list of current beta limitations, refer to [Traffic steering beta limitations](https://edgetunnel-b2h.pages.dev/cloudflare-wan/reference/traffic-steering/#beta-limitations).

Apr 20, 2026
1. ### [Network session analytics dashboard](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-20-network-session-analytics/)  
[ Cloudflare One ](https://edgetunnel-b2h.pages.dev/cloudflare-one/)[ Gateway ](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/)  
The new [Network session analytics](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/analytics/network-sessions/) dashboard is now available in Cloudflare One. This dashboard provides visibility into your network traffic patterns, helping you understand how traffic flows through your Cloudflare One infrastructure.  
![Cloudflare One Network Session Analytics](https://edgetunnel-b2h.pages.dev/_astro/cf1-network-session-analytics.Gl90hEcp_MuWRb.webp)  
#### What you can do with Network session analytics

  * **Analyze geographic distribution**: View a world map showing where your network traffic originates, with a list of top locations by session count.
  * **Monitor key metrics**: Track session count, total bytes transferred, and unique users.
  * **Identify connection issues**: Analyze connection close reasons to troubleshoot network problems.
  * **Review protocol usage**: See which network protocols (TCP, UDP, ICMP) are most used.  
#### Dashboard features

  * **Summary metrics**: Session count, bytes total, and unique users
  * **Traffic by location**: World map visualization and location list with top traffic sources
  * **Top protocols**: Breakdown of TCP, UDP, ICMP, and ICMPv6 traffic
  * **Connection close reasons**: Insights into why sessions terminated (client closed, origin closed, timeouts, errors)  
#### How to access

  1. Log in to [Cloudflare One ↗](https://dash.cloudflare.com).
  2. Go to **Zero Trust** \> **Insights** \> **Dashboards**.
  3. Select **Network session analytics**.  
For more information, refer to the [Network session analytics documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/analytics/network-sessions/).

Apr 17, 2026
1. ### [Homepage and sign-out for MCP server portals](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-17-mcp-portal-homepage-and-sign-out/)  
[ Access ](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/policies/)  
[MCP server portals](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/ai-controls/mcp-portals/) display a homepage when users visit the portal domain in a browser.  
![MCP server portal homepage showing connection status and setup instructions](https://edgetunnel-b2h.pages.dev/_astro/portals-homepage-disconnected.BHbOwayQ_Z1G37WD.webp)  
The homepage shows:

  * The portal name and organization branding
  * The MCP endpoint URL with a copy button
  * Per-client connection instructions for Claude Desktop, Workers AI Playground, OpenCode, Windsurf, and other MCP clients  
Authenticated users see their email address and a **Sign out** button. Selecting **Sign out** revokes all portal-level OAuth grants, deletes upstream server OAuth states, and redirects through Cloudflare Access logout. A confirmation page shows a summary of the revoked sessions.  
For more information, refer to [MCP server portals](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/ai-controls/mcp-portals/#portal-homepage).

Apr 15, 2026
1. ### [Independent MFA for Access applications](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-15-independent-mfa/)  
[ Access ](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/policies/)  
Cloudflare Access now supports independent multi-factor authentication (MFA), allowing you to enforce MFA requirements without relying on your identity provider (IdP). With per-application and per-policy configuration, you can enforce stricter authentication methods like hardware security keys on sensitive applications without requiring them across your entire organization. This reduces the risk of MFA fatigue for your broader user population while adding additional security where it matters most.  
This feature also addresses common gaps in IdP-based MFA, such as inconsistent MFA policies across different identity providers or the need for additional security layers beyond what the IdP provides.  
Independent MFA supports the following authenticator types:

  * **Authenticator application** — Time-based one-time passwords (TOTP) using apps like Google Authenticator, Microsoft Authenticator, or Authy.
  * **Security key** — Hardware security keys such as YubiKeys.
  * **Biometrics** — Built-in device authenticators including Apple Touch ID, Apple Face ID, and Windows Hello.  
Note  
Infrastructure applications do not yet support independent MFA.  
#### Configuration levels  
You can configure MFA requirements at three levels:

| Level            | Description                                                    |
| ---------------- | -------------------------------------------------------------- |
| **Organization** | Enforce MFA by default for all applications in your account.   |
| **Application**  | Require or turn off MFA for a specific application.            |
| **Policy**       | Require or turn off MFA for users who match a specific policy. |  
Settings at lower levels (policy) override settings at higher levels (organization), giving you granular control over MFA enforcement.  
#### User enrollment  
Users enroll their authenticators through the [App Launcher](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/access-settings/app-launcher/). To help with onboarding, administrators can share a direct enrollment link: `<your-team-name>.cloudflareaccess.com/AddMfaDevice`.  
To get started with Independent MFA, refer to [Independent MFA](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/access-settings/independent-mfa/).

Apr 15, 2026
1. ### [New, streamlined creation experience for Access Applications and Gateway Policies](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-15-new-rule-and-application-builders/)  
[ Cloudflare One ](https://edgetunnel-b2h.pages.dev/cloudflare-one/)  
The Cloudflare One dashboard now features redesigned builders for two core workflows: creating Gateway policies and configuring self-hosted Access applications.  
#### Gateway rule builder  
The Gateway rule builder now features a redesigned user experience, bringing it in line with the Access policy builder experience. Improvements include:

  * **Streamlined UX** with clearer states and improved user interactions
  * **Wirefilter editing** for viewing and editing Gateway rules directly from wirefilter expressions
  * **Preview state** to review the impact of your policy in a simple graphic  
![New Gateway rule builder](https://edgetunnel-b2h.pages.dev/_astro/gateway-rule-builder.BxvzsN8s_Z2q9xKY.webp)  
For more information, refer to [Traffic policies](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/).  
#### Access application builder for self-hosted apps  
The self-hosted Access application builder now offers a simplified creation workflow with fewer steps from setup to save. Improvements include:

  * **New application selection experience** that makes choosing the right application type before you begin easier.
  * **Streamlined creation flow** with fewer clicks to build and save an application
  * **Inline policy creation** for building Access policies directly within the application creation flow
  * **Preview state** to understand how your policies enforce user access before saving  
![New Access application builder](https://edgetunnel-b2h.pages.dev/_astro/access-application-builder.B__yqGin_Z2pRlHk.webp)  
For more information, refer to [self-hosted applications](https://edgetunnel-b2h.pages.dev/cloudflare-one/access-controls/applications/http-apps/).

Apr 15, 2026
1. ### [Last seen timestamp for Cloudflare One Client devices is more consistent](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-15-dex-consistent-last-seen-timestamps/)  
[ Digital Experience Monitoring ](https://edgetunnel-b2h.pages.dev/cloudflare-one/insights/dex/)  
The last seen timestamp for [Cloudflare One Client](https://edgetunnel-b2h.pages.dev/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) devices is now more consistent across the dashboard. IT teams will see more consistent information about the most recent client event between a device and Cloudflare's network.

Apr 14, 2026
1. ### [DLP account-level settings](https://edgetunnel-b2h.pages.dev/changelog/post/2025-04-14-account-level-dlp-settings/)  
[ Data Loss Prevention ](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/)  

**Account-level DLP settings are now available** in Cloudflare One. You can now configure advanced DLP settings at the account level, including OCR, AI context analysis, and payload masking. This provides consistent enforcement across all DLP profiles and simplifies configuration management.  
Key changes:

  * **Consistent enforcement**: Settings configured at the account level apply to all DLP profiles
  * **Simplified migration**: Settings enabled on any profile are automatically migrated to account level
  * **Deprecation notice**: Profile-level advanced settings will be deprecated in a future release

**Migration details:**  
During the migration period, if a setting is enabled on any profile, it will automatically be enabled at the account level. This means profiles that previously had a setting disabled may now have it enabled if another profile in the account had it enabled.  
Settings are evaluated using OR logic - a setting is enabled if it is turned on at either the account level or the profile level. However, profile-level settings cannot be enabled when the account-level setting is off.  
For more details, refer to the [DLP settings documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/dlp-settings/).

Apr 14, 2026
1. ### [Introducing Cloudflare Mesh](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-14-cloudflare-mesh/)  
[ Cloudflare One ](https://edgetunnel-b2h.pages.dev/cloudflare-one/)  
[Cloudflare Mesh](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-mesh/) is now available ([blog post ↗](https://blog.cloudflare.com/mesh/)). Mesh connects your services and devices with post-quantum encrypted networking, allowing you to route traffic privately between servers, laptops, and phones over TCP, UDP, and ICMP.  
![Cloudflare Mesh network map showing nodes and devices connected through Cloudflare](https://edgetunnel-b2h.pages.dev/_astro/mesh-network-map.CED6jNHK_ZlOsym.webp)  
#### What Cloudflare Mesh does

  * Assigns a private [Mesh IP](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-mesh/#mesh-ips) to every enrolled device and node.
  * Enables any participant to reach any other participant by IP — including client-to-client, without deploying any infrastructure.
  * Supports [CIDR routes](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-mesh/routes/) for subnet routing through Mesh nodes.
  * Supports [high availability](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-mesh/high-availability/) with active-passive replicas for nodes with routes.
  * All traffic flows through Cloudflare, so [Gateway network policies](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/network-policies/), [device posture checks](https://edgetunnel-b2h.pages.dev/cloudflare-one/reusable-components/posture-checks/), and access rules apply to every connection.  
#### What changed

  * **WARP Connector** is now **Cloudflare Mesh**. Existing WARP Connectors are now called mesh nodes. All existing deployments continue to work — no migration required.
  * **Peer-to-peer connectivity** is now called **Mesh connectivity** and is part of the Cloudflare Mesh documentation.
  * **Mesh node limit** increased from 10 to **50 per account**.
  * New [dashboard experience ↗](https://dash.cloudflare.com/?to=/:account/mesh) at **Networking** \> **Mesh** with an interactive network map, node management, route configuration, diagnostics, and a setup wizard.  
#### Get started  
Refer to the [Cloudflare Mesh documentation](https://edgetunnel-b2h.pages.dev/cloudflare-one/networks/connectors/cloudflare-mesh/) to set up your first Mesh network.

Apr 14, 2026
1. ### [Detect Cloudflare API tokens with DLP](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-14-cloudflare-api-token-detections/)  
[ Data Loss Prevention ](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/)  
The **Credentials and Secrets** DLP profile now includes three new predefined entries for detecting Cloudflare API credentials:

| Entry name                         | Token prefix | Detects                   |
| ---------------------------------- | ------------ | ------------------------- |
| Cloudflare User API Key            | cfk\_        | User-scoped API keys      |
| Cloudflare User API Token          | cfut\_       | User-scoped API tokens    |
| Cloudflare Account Owned API Token | cfat\_       | Account-scoped API tokens |  
These detections target the new [Cloudflare API credential format](https://edgetunnel-b2h.pages.dev/fundamentals/api/get-started/token-formats/), which uses a structured prefix and a CRC32 checksum suffix. The identifiable prefix makes it possible to detect leaked credentials with high confidence and low false positive rates — no surrounding context such as `Authorization: Bearer` headers is required.  
Credentials generated before this format change will not be matched by these entries.  
#### How to enable Cloudflare API token detections

  1. In the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), go to **Zero Trust** \> **DLP** \> **DLP Profiles**.
  2. Select the **Credentials and Secrets** profile.
  3. Turn on one or more of the new Cloudflare API token entries.
  4. Use the profile in a Gateway HTTP policy to log or block traffic containing these credentials.  
Example policy:

| Selector    | Operator | Value                     | Action |
| ----------- | -------- | ------------------------- | ------ |
| DLP Profile | in       | _Credentials and Secrets_ | Block  |  
You can also enable individual entries to scope detection to specific credential types — for example, enabling **Account Owned API Token** detection without enabling **User API Key** detection.  
For more information, refer to [predefined DLP profiles](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/dlp-profiles/predefined-profiles/).

Apr 14, 2026
1. ### [Configure how sensitive data appears in DLP payload logs](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-14-configurable-payload-log-masking/)  
[ Gateway ](https://edgetunnel-b2h.pages.dev/cloudflare-one/traffic-policies/)[ Data Loss Prevention ](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/)  
You can now configure how sensitive data matches are displayed in your DLP payload match logs — giving your incident response team the context they need to validate alerts without compromising your security posture.  
To get started, go to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), select **Zero Trust** \> **Data loss prevention** \> **DLP settings** and find the **Payload log masking** card.  
Previously, all DLP payload logs used a single masking mode that obscured matched data entirely and hid the original character count, making it difficult to distinguish true positives from false positives. This update introduces three options:

  * **Full Mask (default):** Masks the match while preserving character count and visual formatting (for example, `***-**-****` for a Social Security Number). This is an improvement over the previous default, which did not preserve character count.
  * **Partial Mask:** Reveals 25% of the matched content while masking the remainder (for example, `***-**-6789`).
  * **Clear Text:** Stores the full, unmasked violation for deep investigation (for example, `123-45-6789`).

**Important:** The masking level you select is applied at detection time, before the payload is encrypted. This means the chosen format is what your team will see after decrypting the log with your private key — the existing encryption workflow is unchanged.

**Applies to all enabled detections:** When a masking level other than Full Mask is selected, it applies to all sensitive data matches found within a payload window — not just the match that triggered the policy. Any data matched by your enabled DLP detection entries will be masked at the selected level.  
For more information, refer to [DLP logging options](https://edgetunnel-b2h.pages.dev/cloudflare-one/data-loss-prevention/dlp-policies/logging-options/#log-the-payload-of-matched-rules).

Apr 10, 2026
1. ### [Canvas Remoting optimizes performance for productivity applications](https://edgetunnel-b2h.pages.dev/changelog/post/2026-04-10-canvas-remoting-performance/)  
[ Browser Isolation ](https://edgetunnel-b2h.pages.dev/cloudflare-one/remote-browser-isolation/)  
Remote Browser Isolation now supports **Canvas Remoting**, improving performance for HTML5 Canvas applications by sending vector draw commands instead of rasterized bitmaps.  
#### Key improvements

  * **10x bandwidth reduction:** Microsoft Word and other Office apps use 90% less bandwidth
  * **Smooth performance:** Google Sheets maintains consistent 30fps rendering
  * **Responsive terminals:** Web-based development environments and AI notebooks work in real-time
  * **Zero configuration:** Enabled by default for all Browser Isolation customers  
#### How it works  
Instead of sending rasterized bitmaps for every Canvas update, Browser Isolation now:

  1. Captures Canvas draw commands at the source
  2. Converts them to lightweight vector instructions
  3. Renders Canvas content on the client  
This reduces bandwidth from hundreds of kilobytes per second to tens of kilobytes per second.  
#### Managing Canvas Remoting  
To temporarily disable for troubleshooting:

  * Right-click the isolated webpage background
  * Select **Disable Canvas Remoting**
  * Re-enable the same way by selecting **Enable Canvas Remoting**  
#### Limitations  
Currently supports 2D Canvas contexts only. WebGL and 3D graphics applications continue using bitmap rendering. For more information, refer to [Canvas Remoting](https://edgetunnel-b2h.pages.dev/cloudflare-one/remote-browser-isolation/canvas-remoting/).

```json
{"@context":"https://schema.org","@type":"BlogPosting","@id":"https://edgetunnel-b2h.pages.dev/changelog/product-group/cloudflare-one/3/#page","headline":"Cloudflare One Changelog | Cloudflare Docs","url":"https://edgetunnel-b2h.pages.dev/changelog/product-group/cloudflare-one/3/","inLanguage":"en","image":"https://edgetunnel-b2h.pages.dev/cf-twitter-card.png","publisher":{"@type":"Organization","name":"Cloudflare","url":"https://www.cloudflare.com/"},"isPartOf":{"@type":"WebSite","@id":"https://edgetunnel-b2h.pages.dev/#website","name":"Cloudflare Docs","url":"https://edgetunnel-b2h.pages.dev/"}}
```
