🔐 Cloudflare Access now supports independent FIDO2 MFA for infrastructure apps. We’ve added to our hardware-bound key support for infrastructure MFA settings: choose from PIV or FIDO2 for flexibility. What changes for your environment: - Phishing-resistant SSH: Require FIDO2, PIV, or a combination of both when accessing a secured SSH server. - Isolated SSH identities: FIDO2 keys registered for infrastructure are separate from browser-based WebAuthn keys, keeping access boundaries clean. - Self-service enrollment: Users generate and bind their SSH identity directly through the App Launcher without needing manual admin provisioning. If you’re enforcing Zero Trust across production infrastructure, you can enable this now in your MFA settings. Huge congrats to James Walters for getting this across the line! 🥳 🔗 Full changelog and setup guide in the comments. #CloudflareOne #ZeroTrust #InfrastructureSecurity #CloudflareAccess
Self-service enrollment without admin provisioning is the part that will get flagged in review, not the FIDO2 rollout. Someone still needs to own revocation when an SSH identity outlives the laptop it was bound to
Kudos to the whole team for this wonderful Summer internship!
Thanks for shared Ann Ming Samborski
https://developers.cloudflare.com/changelog/post/2026-08-12-fido2-keys-infrastructure-ssh/