Skip to content
CoRISE

Cloudflare Zero Trust and Entra: Assigning Policy Decisions

Separate login decisions from ongoing sessions and identify the state each product observes.

1 min read
  • identity
  • security
Open table of contents

Conclusion

Separate login decisions from ongoing sessions and identify the state each product observes.

Context

An IdP and an access proxy may evaluate state at different times. Distinguish responsibility and reevaluation timing for login and ongoing sessions.

Design and verification scope

Assess the following responsibilities and boundaries when designing and verifying a configuration.

  • Identity provider
  • Device posture
  • Conditional Access
  • Session lifetime
  • Revocation
  • Logs

Decision rationale

Use the relationship between Identity provider and Logs to compare the responsibilities of the selected approach and alternatives. Separate retained constraints from what the new boundary can change.

Trade-offs

Compare the implementation, maintenance and review work introduced by Device posture with the control it provides. Include failure paths, operator effort and conditions in which the approach should not be adopted.

Limitations

Review authentication flows, policies, revocation timing and logs. Combining products alone does not guarantee continuous evaluation.

These cases provide attributed design context. They do not establish that the proposed experiments or configurations were delivered in those engagements.

Contact

Tell us about your engineering challenge.

Talk with CoRISE about the design, implementation and operation of your systems.

Start a Conversation